Showing posts with label Active Directory. Show all posts
Showing posts with label Active Directory. Show all posts

Wednesday, November 23, 2011

Cisco ASA 5500 Active Directory Integration

Today I needed to enable an extra layer of security for a Cisco ASA VPN (ASA 5500 series appliance - should work on 5505, 5510, 5520, 5540, 5550, etc...).  I needed to require the user to enter their Active Directory domain credentials to connect to a Cisco IPsec VPN, for better security.

I worked this out from inside the ASA's ASDM software.


  1. Add an AAA server group for Active Directory authentication (under Configuration --> Remote Access VPN --> AAA/Local Users --> AAA Server Groups).
  2. Choose a name, and pick protocol: LDAP. Everything else here is fine.
  3. Now that you have your server group, highlight it in ASDM, and in the bottom half of the screen, add a server to the group.  This is where things get tricky!
    • Choose what interface the server is off of, put in the server's IP, and fill out the rest of the details as shown below.  This server must be a domain controller!
    • For Base DN, you should enter your AD domain name, in the format DC=DOMAIN,DC=COM (or local, or whatever)
    • Scope should be set to All levels beneath the Base DN, if you want it to be able to find all of your user accounts.
    • Naming attribute should be sAMAccountName
    • For Login DN, enter the path to an account with the correct privliges to read the required information.  I don't have specific details on this - I just used a domain admin account (I know, I know).  The format should be CN=UserAccount,CN=ThisUsersOU,DC=YourDomain,DC=COM (if the user account is several OUs deep, you'll need to add a CN= entry for each OU, in the correct order - starting with the one that the user is in).
    • Test the server using the Test button, after you click OK!
  4. Now that the group is set up, we need to configure some profiles to use this group!  Inside ASDM, navigate to Configuration --> Remote Access VPN --> Network (Client) Access --> IPsec Connection Profiles.
  5. Edit the profile you want to change to require AD authentication.
    • On the first page (Basic), change the Server Group (under the User Authentication section on the right side) to the group you just created.
    • On the Advanced --> General page, Make sure nothing is checked here - everything should be unchecked and set to --None--
    • Under Advanced --> IPsec --> IKE Authentication, set the Default Mode to XAUTH (Extended user authentication).  This is what forces a login prompt when users connect.  The checkbox here doesn't need to be checked.
    • Nothing else should need to be changed (from defaults) in any other pages.  Click OK, then test it using a VPN client!!!
  6. That's it.  Let me know if you run into any issues or have any suggestions!


Friday, September 30, 2011

PowerShell for Creating Secure User Folders via AD

Today I needed to create a user folder structure for every non-disabled user in a specific Active Directory OU (and sub-OUs).  The folders needed to match the username exactly, and have security so that the user has modify permissions, and Domain Admins have full control - no other permissions!  Sounds simple, until you consider that there are hundreds of users.

I found a few PowerShell examples online, but nothing that I found could do everything I needed, so I tweaked and modified until I came up with these two simple scripts.

To start with, I manually created a base folder (in my example, named PSTs, sigh..).  I gave Domain Users read-only permission and Domain Admins full control of this folder.  No other permissions were present on this folder - if there are other permissions on your base folder, the permissions portion of this script will not work properly for you.

The first script just prints a list of usernames found in Active Directory (under the OU you specify) to the screen:


$strFilter = "(&(objectCategory=User)(!userAccountControl:1.2.840.113556.1.4.803:=2))"


$objDomain = New-Object System.DirectoryServices.DirectoryEntry("LDAP://OU=YourOU,dc=YourDomain,dc=local")


$objSearcher = New-Object System.DirectoryServices.DirectorySearcher
$objSearcher.SearchRoot = $objDomain
$objSearcher.PageSize = 1000
$objSearcher.Filter = $strFilter
$objSearcher.SearchScope = "Subtree"


$colProplist = "samaccountname"
foreach ($i in $colPropList){$objSearcher.PropertiesToLoad.Add($i)}


$colResults = $objSearcher.FindAll()


foreach ($objResult in $colResults)
    {$objItem = $objResult.Properties; $objItem.samaccountname}

This first script searches all OUs underneath the OU specified by the LDAP:// line for user accounts that are not disabled (the userAccountControl:1.2.840.113556.1.4.803:=2 identifier specifies disabled users), then pulls the sAMAccountName attribute and prints it to the screen.  This gives us a list of all the non-disabled usernames we need.


Copy this list and paste it into a text file, so that there is one username per line (just a simple copy paste).


Run the following script against the text file, and your directories will be created with the permissions discussed above:



$users = Get-Content "C:\userlist.txt"
ForEach ($user in $users)
{
$newPath = Join-Path "C:\PSTs" -childpath $user
New-Item $newPath -type directory


$acl = Get-Acl $newpath
$acl.SetAccessRuleProtection($true,$true)
$acl | Set-Acl $newpath


$acl = Get-Acl $newPath
# This removes all access for the group in question
$group = "YourDomain\Domain Users"
$acl.Access |where {$_.IdentityReference -eq $group} |%{$acl.RemoveAccessRule($_)}


$account="POMONACH.LOCAL\$user"
$rights=[System.Security.AccessControl.FileSystemRights]::Modify
$inheritance=[System.Security.AccessControl.InheritanceFlags]"ContainerInherit,ObjectInherit"
$propagation=[System.Security.AccessControl.PropagationFlags]::None
$allowdeny=[System.Security.AccessControl.AccessControlType]::Allow

$accessRule=New-Object System.Security.AccessControl.FileSystemAccessRule ($account,$rights,$inheritance,$propagation,$allowdeny)


$acl.SetAccessRule($accessRule)
$acl | Set-Acl $newpath
}

This will set create the user folders, remove security inheritance, and remove Domain Users from the security tab.  It will also add the user to the security tab with modify permissions.  I'm not a PowerShell expert, so there are some parts here that I don't quite "get", even though I wrote some of it, but I get the general idea and it worked for me!