I worked this out from inside the ASA's ASDM software.
- Add an AAA server group for Active Directory authentication (under Configuration --> Remote Access VPN --> AAA/Local Users --> AAA Server Groups).
- Choose a name, and pick protocol: LDAP. Everything else here is fine.
- Now that you have your server group, highlight it in ASDM, and in the bottom half of the screen, add a server to the group. This is where things get tricky!
- Choose what interface the server is off of, put in the server's IP, and fill out the rest of the details as shown below. This server must be a domain controller!
- For Base DN, you should enter your AD domain name, in the format DC=DOMAIN,DC=COM (or local, or whatever)
- Scope should be set to All levels beneath the Base DN, if you want it to be able to find all of your user accounts.
- Naming attribute should be sAMAccountName
- For Login DN, enter the path to an account with the correct privliges to read the required information. I don't have specific details on this - I just used a domain admin account (I know, I know). The format should be CN=UserAccount,CN=ThisUsersOU,DC=YourDomain,DC=COM (if the user account is several OUs deep, you'll need to add a CN= entry for each OU, in the correct order - starting with the one that the user is in).
- Test the server using the Test button, after you click OK!
- Now that the group is set up, we need to configure some profiles to use this group! Inside ASDM, navigate to Configuration --> Remote Access VPN --> Network (Client) Access --> IPsec Connection Profiles.
- Edit the profile you want to change to require AD authentication.
- On the first page (Basic), change the Server Group (under the User Authentication section on the right side) to the group you just created.
- On the Advanced --> General page, Make sure nothing is checked here - everything should be unchecked and set to --None--
- Under Advanced --> IPsec --> IKE Authentication, set the Default Mode to XAUTH (Extended user authentication). This is what forces a login prompt when users connect. The checkbox here doesn't need to be checked.
- Nothing else should need to be changed (from defaults) in any other pages. Click OK, then test it using a VPN client!!!
- That's it. Let me know if you run into any issues or have any suggestions!