<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Anyconnect user static IP in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/anyconnect-user-static-ip/m-p/4270585#M564717</link>
    <description>&lt;P&gt;Guys, looking for DC-DR static IP solution for Anyconnect VPN clients.&lt;/P&gt;&lt;P&gt;Current architecture is&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Anyconnect &amp;lt;&amp;gt; DC ASA &amp;lt;&amp;gt; DC ISE &amp;lt;&amp;gt; Corp AD&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyconnect user gets a static IP. IP is binded to static IP properties of AD user in Dial-in Tab.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AD-statIP.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/101428i4F2AB6641CC74688/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AD-statIP.png" alt="AD-statIP.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;DC ISE fetches this IP (192.168.31.x range) and passes on to the user. Till now it's working perfectly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, we are setting up another ASA in DR, now the architecture becomes;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Anyconnect &amp;lt;&amp;gt; DR ASA &amp;lt;&amp;gt; DR ISE &amp;lt;&amp;gt; Corp AD&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;this time the anyconnect user should get IP in the range 172.16.x.x range.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone any idea how this can be worked out. AD user properties lets store only one IP address.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Jan 2021 06:23:44 GMT</pubDate>
    <dc:creator>manvik</dc:creator>
    <dc:date>2021-01-12T06:23:44Z</dc:date>
    <item>
      <title>Anyconnect user static IP</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-user-static-ip/m-p/4270585#M564717</link>
      <description>&lt;P&gt;Guys, looking for DC-DR static IP solution for Anyconnect VPN clients.&lt;/P&gt;&lt;P&gt;Current architecture is&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Anyconnect &amp;lt;&amp;gt; DC ASA &amp;lt;&amp;gt; DC ISE &amp;lt;&amp;gt; Corp AD&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyconnect user gets a static IP. IP is binded to static IP properties of AD user in Dial-in Tab.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AD-statIP.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/101428i4F2AB6641CC74688/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AD-statIP.png" alt="AD-statIP.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;DC ISE fetches this IP (192.168.31.x range) and passes on to the user. Till now it's working perfectly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, we are setting up another ASA in DR, now the architecture becomes;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Anyconnect &amp;lt;&amp;gt; DR ASA &amp;lt;&amp;gt; DR ISE &amp;lt;&amp;gt; Corp AD&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;this time the anyconnect user should get IP in the range 172.16.x.x range.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone any idea how this can be worked out. AD user properties lets store only one IP address.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2021 06:23:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-user-static-ip/m-p/4270585#M564717</guid>
      <dc:creator>manvik</dc:creator>
      <dc:date>2021-01-12T06:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect user static IP</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-user-static-ip/m-p/4270605#M564718</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;This is not possible using AD Dial-In option. You need to assign the static&lt;BR /&gt;IPs using ISE (Frame-IP) on a per user basis or use an external DHCP for&lt;BR /&gt;your IP Pool and bind using MAC addresses. But from AD, you can't have more&lt;BR /&gt;than one static IP.&lt;BR /&gt;&lt;BR /&gt;One solution you can try is to have two OUs in AD with duplicate users but&lt;BR /&gt;having different static IPs. Then your ISE nodes in Active/DR should point&lt;BR /&gt;to their respective OUs. This makes active ISE validate with Active OU and&lt;BR /&gt;get Active static IPs and DR ISE validate DR OU and get DR static IPs.&lt;BR /&gt;&lt;BR /&gt;I will go for ISE option of allocating IPs as this is the best option but&lt;BR /&gt;its your call.&lt;BR /&gt;&lt;BR /&gt;***** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Tue, 12 Jan 2021 07:12:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-user-static-ip/m-p/4270605#M564718</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2021-01-12T07:12:50Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect user static IP</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-user-static-ip/m-p/4270627#M564719</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/161770"&gt;@manvik&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Perhaps you could use dynamic variable substitution, example &lt;A href="https://integratingit.wordpress.com/2018/12/01/ise-dynamic-variables-from-ad/" target="_self"&gt;here&lt;/A&gt;. Add the IP address to an unused AD attribute, such as "pager" for each user. Create a new AuthZ profile, referencing the attribute. Use this AuthZ profile for sessions from the DR ASA.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2021 08:07:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-user-static-ip/m-p/4270627#M564719</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-01-12T08:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect user static IP</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-user-static-ip/m-p/4271284#M564744</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/292493"&gt;@Mohammed al Baqari&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think the feasible option is "&lt;SPAN&gt;&amp;nbsp;assign the static&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;IPs using ISE (Frame-IP) on a per user basis&lt;/SPAN&gt;". Question is how do we assign static IP in ISE for an AD user.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 05:03:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-user-static-ip/m-p/4271284#M564744</guid>
      <dc:creator>manvik</dc:creator>
      <dc:date>2021-01-13T05:03:35Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect user static IP</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-user-static-ip/m-p/4271286#M564745</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;let me test this.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 05:04:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-user-static-ip/m-p/4271286#M564745</guid>
      <dc:creator>manvik</dc:creator>
      <dc:date>2021-01-13T05:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect user static IP</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-user-static-ip/m-p/4271296#M564746</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;You match the username in the authorization policy and in the authorization&lt;BR /&gt;profile assign framed-ip attribute.&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Wed, 13 Jan 2021 05:47:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-user-static-ip/m-p/4271296#M564746</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2021-01-13T05:47:50Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect user static IP</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-user-static-ip/m-p/4271614#M564757</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/161770"&gt;@manvik&lt;/a&gt;&amp;nbsp;Out of curiousity and to confirm my thoughts, I've tested it and it works as expected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="4.PNG" style="width: 405px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/101586iF97BC637537C7633/image-size/large?v=v2&amp;amp;px=999" role="button" title="4.PNG" alt="4.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.PNG" style="width: 841px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/101587iE262AA85EE2554C7/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.PNG" alt="1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.PNG" style="width: 357px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/101588i12ACE00D96EE2074/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.PNG" alt="3.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.PNG" style="width: 860px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/101589iB71228E1A1894C75/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.PNG" alt="2.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="5.PNG" style="width: 576px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/101590iD519E7A71E567C8B/image-size/large?v=v2&amp;amp;px=999" role="button" title="5.PNG" alt="5.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;msRADIUSFramedIPAddress just relates to the attribute under the Dial-in tab in AD, it seems you can use any attribute under the users account in AD, as long as you import them into ISE. I imagine you could use custom schema attributes also.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;HTH&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 13:44:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-user-static-ip/m-p/4271614#M564757</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-01-13T13:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect user static IP</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-user-static-ip/m-p/4272412#M564783</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;It worked like a charm.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 13:58:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-user-static-ip/m-p/4272412#M564783</guid>
      <dc:creator>charles07</dc:creator>
      <dc:date>2021-01-14T13:58:58Z</dc:date>
    </item>
  </channel>
</rss>

