<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, You can have fall-back to in VPN</title>
    <link>https://community.cisco.com/t5/vpn/asa-remote-access-vpn-query-multiple-group-policies-to-single/m-p/2697608#M102403</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can have fall-back to primary method as LOCAL only.&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa90/configuration/guide/asa_90_cli_config/aaa_servers.html#pgfId-1053533&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Abaji.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 27 May 2015 16:14:30 GMT</pubDate>
    <dc:creator>Abaji Rawool</dc:creator>
    <dc:date>2015-05-27T16:14:30Z</dc:date>
    <item>
      <title>ASA Remote Access VPN Query - multiple group policies to single connection profile</title>
      <link>https://community.cisco.com/t5/vpn/asa-remote-access-vpn-query-multiple-group-policies-to-single/m-p/2697605#M102400</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Two quick questions here that i need help with.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. In an ASA 5525, is it possible to have multiple group-policies to a single Connection profile?&lt;/P&gt;&lt;P&gt;Scenario: One of our clients is running F5 Firepass for&amp;nbsp;their VPN solution and that device can is used by them to have multiple group-policies per Connection Profile. We are planning to migrate them to ASA (5525) and i'm not sure if the ASA can support that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. In an ASA 5525 for Clientless Remote Access VPN,&amp;nbsp;can we forward the login page to an external server? For example, if i have a connection profile setup with a URL:&amp;nbsp;"&lt;A href="https://wyz.vpn.com/%22" target="_blank"&gt;https://wyz.vpn.com/"&lt;/A&gt;;&amp;nbsp;for LDAP/Radius authentication, but for&amp;nbsp;&lt;A href="https://wyz.vpn.com/data" target="_blank"&gt;https://wyz.vpn.com/data&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A href="https://wyz.vpn.com/test" target="_blank"&gt;https://wyz.vpn.com/test&lt;/A&gt;&amp;nbsp;i want HTTP form based authentication and this&amp;nbsp;page needs to be sent to an external server i.e ASA will not handle that page but rather the front page for this will be served by the external server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Scenario:&amp;nbsp;One of our clients is running F5 Firepass for&amp;nbsp;their VPN solution. On the F5&amp;nbsp;they have setup pages such as&amp;nbsp;&lt;A href="https://wyz.vpn.com/%22" style="outline-width: 0px; color: rgb(0, 85, 128); text-decoration: underline;" target="_blank"&gt;https://wyz.vpn.com/&lt;/A&gt;&amp;nbsp;which the F5 shows to the user when they connect via clientless VPN; however if the user types in&amp;nbsp;&lt;A href="https://wyz.vpn.com/data" target="_blank"&gt;https://wyz.vpn.com/data&lt;/A&gt;&amp;nbsp;into the browser, the traffic comes to the F5, but the F5 redirects this traffic to an external server (with an external url as well). It is then this external server that forwards the front page to the user requesting authentication credentials for HTTP form based authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance all!!&lt;/P&gt;</description>
      <pubDate>Sat, 22 Feb 2020 04:14:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/asa-remote-access-vpn-query-multiple-group-policies-to-single/m-p/2697605#M102400</guid>
      <dc:creator>ramesh.8901</dc:creator>
      <dc:date>2020-02-22T04:14:46Z</dc:date>
    </item>
    <item>
      <title>Hi, I am not sure what are</title>
      <link>https://community.cisco.com/t5/vpn/asa-remote-access-vpn-query-multiple-group-policies-to-single/m-p/2697606#M102401</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not sure what are you trying to achieve with point 1 and for point 2 ASA can do limited stuff but complete redirection is not possible at this time&amp;nbsp;&lt;/P&gt;&lt;P&gt;What ASA can do :http://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise/design-zone-security/portal.pdf&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Abaji.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2015 06:56:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/asa-remote-access-vpn-query-multiple-group-policies-to-single/m-p/2697606#M102401</guid>
      <dc:creator>Abaji Rawool</dc:creator>
      <dc:date>2015-05-26T06:56:37Z</dc:date>
    </item>
    <item>
      <title>Hi, Thanks for that. Also</title>
      <link>https://community.cisco.com/t5/vpn/asa-remote-access-vpn-query-multiple-group-policies-to-single/m-p/2697607#M102402</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for that. Also would you happen to know if a connection profile can have more than one authentication method? The client wants the primary authentication method to be HTTP form based authentication and if the user fails to input those credentials he can use RSA. I know that for a connection profile i can have the local user as a fallback authentication mechanism but can we have RSA as a fallback?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2015 14:53:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/asa-remote-access-vpn-query-multiple-group-policies-to-single/m-p/2697607#M102402</guid>
      <dc:creator>ramesh.8901</dc:creator>
      <dc:date>2015-05-27T14:53:15Z</dc:date>
    </item>
    <item>
      <title>Hi, You can have fall-back to</title>
      <link>https://community.cisco.com/t5/vpn/asa-remote-access-vpn-query-multiple-group-policies-to-single/m-p/2697608#M102403</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can have fall-back to primary method as LOCAL only.&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa90/configuration/guide/asa_90_cli_config/aaa_servers.html#pgfId-1053533&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Abaji.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2015 16:14:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/asa-remote-access-vpn-query-multiple-group-policies-to-single/m-p/2697608#M102403</guid>
      <dc:creator>Abaji Rawool</dc:creator>
      <dc:date>2015-05-27T16:14:30Z</dc:date>
    </item>
    <item>
      <title>Hi, Thank you very much for</title>
      <link>https://community.cisco.com/t5/vpn/asa-remote-access-vpn-query-multiple-group-policies-to-single/m-p/2697609#M102404</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much for the help.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2015 07:25:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/asa-remote-access-vpn-query-multiple-group-policies-to-single/m-p/2697609#M102404</guid>
      <dc:creator>ramesh.8901</dc:creator>
      <dc:date>2015-05-29T07:25:58Z</dc:date>
    </item>
  </channel>
</rss>

