<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question: how to assign VPN IP to VPN client user using ACS  in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/question-how-to-assign-vpn-ip-to-vpn-client-user-using-acs-5-4/m-p/2227148#M126414</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ACS 5 doesn't have ability to provide IP addresses from IP address pools defined in ACS. &lt;/P&gt;&lt;P&gt;You need to assign static user on per user basis on ACS 5. You may also create a pool on the ASA and push the pool name from ACS 5&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.3/release/notes/acs_53_rn.html#wp216411"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.3/release/notes/acs_53_rn.html#wp216411&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; - Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 06 Jun 2013 20:12:27 GMT</pubDate>
    <dc:creator>Jatin Katyal</dc:creator>
    <dc:date>2013-06-06T20:12:27Z</dc:date>
    <item>
      <title>Question: how to assign VPN IP to VPN client user using ACS 5.4?</title>
      <link>https://community.cisco.com/t5/network-access-control/question-how-to-assign-vpn-ip-to-vpn-client-user-using-acs-5-4/m-p/2227147#M126372</link>
      <description>&lt;P&gt;I'm new to ACS5.4.&amp;nbsp; What I'm trying to achieve is to let ACS5.4 assign IP's to users who connect to our ASA using Cisco VPN client.&amp;nbsp; ASA is running as Radius client of ACS5.4, and we've tested successfully for Radius authentication.&amp;nbsp; But users are still getting "unknown error" in VPN client, after authenticating successfully.&amp;nbsp; I suspect I probably used incorrect RADIUS attributes in authorization policy.&amp;nbsp; Here's what I did:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. In policy elements -&amp;gt; authorization and permissions -&amp;gt; network access -&amp;gt; authorization profiles, I created a new profile, and that profile calls the Radius attribute CVPN3000/ASA/PIX7.x-DHCP-Network-Scope.&amp;nbsp; An IP address is entered under that attribute as a static value.&lt;/P&gt;&lt;P&gt;2. Then, in access policies -&amp;gt; access services -&amp;gt; IPSec VPN client with Radius (this is the policy I created) -&amp;gt; authorization, I created an authorization policy that allow the RADIUS profile created earlier to be used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did I miss anything?&amp;nbsp; Maybe I picked the wrong RADIUS attribute?&amp;nbsp; Thanks in advance for any help!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:31:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/question-how-to-assign-vpn-ip-to-vpn-client-user-using-acs-5-4/m-p/2227147#M126372</guid>
      <dc:creator>josephqiu</dc:creator>
      <dc:date>2019-03-11T03:31:07Z</dc:date>
    </item>
    <item>
      <title>Re: Question: how to assign VPN IP to VPN client user using ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/question-how-to-assign-vpn-ip-to-vpn-client-user-using-acs-5-4/m-p/2227148#M126414</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ACS 5 doesn't have ability to provide IP addresses from IP address pools defined in ACS. &lt;/P&gt;&lt;P&gt;You need to assign static user on per user basis on ACS 5. You may also create a pool on the ASA and push the pool name from ACS 5&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.3/release/notes/acs_53_rn.html#wp216411"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.3/release/notes/acs_53_rn.html#wp216411&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; - Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jun 2013 20:12:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/question-how-to-assign-vpn-ip-to-vpn-client-user-using-acs-5-4/m-p/2227148#M126414</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-06-06T20:12:27Z</dc:date>
    </item>
    <item>
      <title>Question: how to assign VPN IP to VPN client user using ACS 5.4?</title>
      <link>https://community.cisco.com/t5/network-access-control/question-how-to-assign-vpn-ip-to-vpn-client-user-using-acs-5-4/m-p/2227149#M126462</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are absolutely right!!&amp;nbsp; I was doing research online after posting the above.&amp;nbsp; The correct RADIUS attribute to use is actually CVPN3000/ASA/PIX7.x-Group-Based-Address-Pools.&amp;nbsp; Then create the pool in ASA, and call that pool's name in ACS under that RADIUS attribute.&amp;nbsp; Someone explained this perfectly in this community before.&amp;nbsp; Much appreciate your answer!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's from another post last year:&lt;/P&gt;&lt;P&gt;ACS&amp;nbsp; 5 does not have the feature of IP pools. Logically its always good to&amp;nbsp; setup pools locally on vpn server and if you want user to pick ip from&amp;nbsp; specific local pool you can configure acs to push that attribute.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;On ACS Go to &amp;gt; Policy Elements&amp;nbsp; -&amp;gt; Network Access -&amp;gt;&amp;nbsp;&amp;nbsp; Authorization Profiles -&amp;gt; Create -&amp;gt;&lt;BR /&gt;Name of the Policy -&amp;gt;Dictionary Type: Radius-Cisco VPN 3000/ASA/PIX7.x&lt;BR /&gt;&lt;BR /&gt;Attribute Type : CVPN3000/ASA/PIX7.x-Group-Based-Address-Pools &lt;BR /&gt;Attribute Type: String&lt;BR /&gt;Attribute Value : Static MYPOOL (Name of the Pool which is defined on the ASA)&lt;BR /&gt;&lt;BR /&gt;Access Policies -&amp;gt;Default Network Access -&amp;gt; Authorization -&amp;gt;&amp;nbsp; Create -&amp;gt; Under result section call the Authorization p&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jun 2013 20:17:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/question-how-to-assign-vpn-ip-to-vpn-client-user-using-acs-5-4/m-p/2227149#M126462</guid>
      <dc:creator>josephqiu</dc:creator>
      <dc:date>2013-06-06T20:17:07Z</dc:date>
    </item>
    <item>
      <title>Question: how to assign VPN IP to VPN client user using ACS 5.4?</title>
      <link>https://community.cisco.com/t5/network-access-control/question-how-to-assign-vpn-ip-to-vpn-client-user-using-acs-5-4/m-p/2227150#M126504</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your welcome! Well, this is from the begining since ACS 5.x launched. With the above steps, could say that you're on the right path.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; - Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jun 2013 23:30:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/question-how-to-assign-vpn-ip-to-vpn-client-user-using-acs-5-4/m-p/2227150#M126504</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-06-06T23:30:06Z</dc:date>
    </item>
    <item>
      <title>Question: how to assign VPN IP to VPN client user using ACS 5.4?</title>
      <link>https://community.cisco.com/t5/network-access-control/question-how-to-assign-vpn-ip-to-vpn-client-user-using-acs-5-4/m-p/2227151#M126571</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I'd really like to see the rest of that text. It seems to have been cut off&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Dec 2013 16:02:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/question-how-to-assign-vpn-ip-to-vpn-client-user-using-acs-5-4/m-p/2227151#M126571</guid>
      <dc:creator>codewize</dc:creator>
      <dc:date>2013-12-12T16:02:35Z</dc:date>
    </item>
    <item>
      <title>Question: how to assign VPN IP to VPN client user using ACS 5.4?</title>
      <link>https://community.cisco.com/t5/network-access-control/question-how-to-assign-vpn-ip-to-vpn-client-user-using-acs-5-4/m-p/2227152#M126618</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Codewize,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;Access Policies -&amp;gt;Default Network Access -&amp;gt; Authorization -&amp;gt;&amp;nbsp; Create -&amp;gt; &lt;BR /&gt;Under result section call the Authorization policy that you created before.&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**Share your knowledge. It’s a way to achieve immortality. &lt;BR /&gt;--Dalai Lama** &lt;BR /&gt; &lt;BR /&gt;Please Rate if helpful. &lt;BR /&gt;Regards &lt;BR /&gt;Ed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Dec 2013 20:47:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/question-how-to-assign-vpn-ip-to-vpn-client-user-using-acs-5-4/m-p/2227152#M126618</guid>
      <dc:creator>edwjames</dc:creator>
      <dc:date>2013-12-12T20:47:39Z</dc:date>
    </item>
  </channel>
</rss>

