<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AAA local user management VPN. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-local-user-management-vpn/m-p/2027420#M158072</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm a bit new to Cisco and i find this AAA a bit confusing...&lt;/P&gt;&lt;P&gt;I've turend on AAA by:&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and it created me:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login default local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I use this "&lt;SPAN style="font-family: courier new,courier;"&gt;default&lt;/SPAN&gt;" list for WebVPN ? And what would be a different if i create new "&lt;SPAN style="font-family: courier new,courier;"&gt;sslvpn&lt;/SPAN&gt;" list...&lt;/P&gt;&lt;P&gt;Also when I'll be creating user for VPN remote access.. that user will also exist in local database and have access to router via SSH?&lt;/P&gt;&lt;P&gt;Because the research I've done it doesn't seem you can group users in different "aaa groups" e.g. user admin belongs under "&lt;SPAN style="font-family: courier new,courier;"&gt;admin&lt;/SPAN&gt;" aaa group which can do ssh to router, users for VPN can only do remote VPN access and not SSH and login into router...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i saw ASA has some attribute for users called remote-user&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;&lt;STRONG&gt;admin&lt;/STRONG&gt;, in which users are allowed access to the configuration mode. This option also allows a user to connect via remote access. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;A name="wp1162031" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;&lt;STRONG&gt;nas-prompt&lt;/STRONG&gt;, in which users are allowed access to the EXEC mode. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;A name="wp1162032" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;&lt;STRONG&gt;remote-access&lt;/STRONG&gt;, in which users are allowed access to the network. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But i can't find this option in IOS on my 1900 Series ISR router.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 02:38:23 GMT</pubDate>
    <dc:creator>ilukeberry</dc:creator>
    <dc:date>2019-03-11T02:38:23Z</dc:date>
    <item>
      <title>AAA local user management VPN.</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-local-user-management-vpn/m-p/2027420#M158072</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm a bit new to Cisco and i find this AAA a bit confusing...&lt;/P&gt;&lt;P&gt;I've turend on AAA by:&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and it created me:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login default local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I use this "&lt;SPAN style="font-family: courier new,courier;"&gt;default&lt;/SPAN&gt;" list for WebVPN ? And what would be a different if i create new "&lt;SPAN style="font-family: courier new,courier;"&gt;sslvpn&lt;/SPAN&gt;" list...&lt;/P&gt;&lt;P&gt;Also when I'll be creating user for VPN remote access.. that user will also exist in local database and have access to router via SSH?&lt;/P&gt;&lt;P&gt;Because the research I've done it doesn't seem you can group users in different "aaa groups" e.g. user admin belongs under "&lt;SPAN style="font-family: courier new,courier;"&gt;admin&lt;/SPAN&gt;" aaa group which can do ssh to router, users for VPN can only do remote VPN access and not SSH and login into router...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i saw ASA has some attribute for users called remote-user&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;&lt;STRONG&gt;admin&lt;/STRONG&gt;, in which users are allowed access to the configuration mode. This option also allows a user to connect via remote access. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;A name="wp1162031" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;&lt;STRONG&gt;nas-prompt&lt;/STRONG&gt;, in which users are allowed access to the EXEC mode. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;A name="wp1162032" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;&lt;STRONG&gt;remote-access&lt;/STRONG&gt;, in which users are allowed access to the network. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But i can't find this option in IOS on my 1900 Series ISR router.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:38:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-local-user-management-vpn/m-p/2027420#M158072</guid>
      <dc:creator>ilukeberry</dc:creator>
      <dc:date>2019-03-11T02:38:23Z</dc:date>
    </item>
    <item>
      <title>AAA local user management VPN.</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-local-user-management-vpn/m-p/2027421#M158103</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Luka,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA and the IOS webvpn is a little different here is a guide that will point you in the right direction:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/ios-xml/ios/sec_conn_sslvpn/configuration/15-2mt/sec-conn-sslvpn-ssl-vpn.html#GUID-8A423FE8-F5CD-438D-9FE5-DE6E2E05F813"&gt;http://www.cisco.com/en/US/docs/ios-xml/ios/sec_conn_sslvpn/configuration/15-2mt/sec-conn-sslvpn-ssl-vpn.html#GUID-8A423FE8-F5CD-438D-9FE5-DE6E2E05F813&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 06 Oct 2012 05:55:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-local-user-management-vpn/m-p/2027421#M158103</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-10-06T05:55:37Z</dc:date>
    </item>
  </channel>
</rss>

