<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WebVPN Group authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/webvpn-group-authentication/m-p/440883#M5863</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Take a group "webvpn" internally configured .&lt;/P&gt;&lt;P&gt;Create locally a user called "local" that you assign to this group and on the radius server a user called "external".&lt;/P&gt;&lt;P&gt;If you choose the option "strip group" on global authentication parameters on your vpn3000 , you will be able to log on using either "local" or "external@webvpn".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you don't use "strip group" , you have to create a user "external@webvpn" on the radius server(this can be interesting if you want to put the same acccount in differents groups).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Morgan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 27 Mar 2006 15:19:26 GMT</pubDate>
    <dc:creator>morgsizun</dc:creator>
    <dc:date>2006-03-27T15:19:26Z</dc:date>
    <item>
      <title>WebVPN Group authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/webvpn-group-authentication/m-p/440875#M5855</link>
      <description>&lt;P&gt;I am trying to create a seperate group called "WebVPNuser" and enable Webvpn permission only for that group and use Local authentication for users in WebVPnuser group. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What i observe is users (under webvpnuser group) do not authenticate using WebVPNusers group but are authenticated using basegroup which is Radius server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure where i am going wrong. We have other users conencting using IPsec clinet without any problem. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:13:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/webvpn-group-authentication/m-p/440875#M5855</guid>
      <dc:creator>ittiadmin</dc:creator>
      <dc:date>2020-02-21T18:13:02Z</dc:date>
    </item>
    <item>
      <title>Re: WebVPN Group authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/webvpn-group-authentication/m-p/440876#M5856</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is explained in Appendix B of the config manual.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/vpn/vpn3000/4_1/config/webvpnap.htm#1008861" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/vpn/vpn3000/4_1/config/webvpnap.htm#1008861&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Web VPN uses global authentication and authorization settings, not the settings configured for the group. The first active server, independent of type, is used for authentication and authorization of WebVPN sessions. "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You'll need to make Internal the first global auth method.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Catriona&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jul 2005 13:46:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/webvpn-group-authentication/m-p/440876#M5856</guid>
      <dc:creator>ciscocsoc</dc:creator>
      <dc:date>2005-07-07T13:46:10Z</dc:date>
    </item>
    <item>
      <title>Re: WebVPN Group authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/webvpn-group-authentication/m-p/440877#M5857</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your info. I had tried this suggestion before and it had worked, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But i wanted to enable WebVPN only on "WebVPnuser" group instead of enabling  webvpn in Base Group and use internal database for authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have changed internal the first auth method.  Hope Changing Internal the first global auth method wont effect other VPN users authentication. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate your Help. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jul 2005 12:37:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/webvpn-group-authentication/m-p/440877#M5857</guid>
      <dc:creator>ittiadmin</dc:creator>
      <dc:date>2005-07-08T12:37:47Z</dc:date>
    </item>
    <item>
      <title>Re: WebVPN Group authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/webvpn-group-authentication/m-p/440878#M5858</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was looking for the same thing...were you able to find sort of solution to this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Feb 2006 19:42:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/webvpn-group-authentication/m-p/440878#M5858</guid>
      <dc:creator>cplatt01</dc:creator>
      <dc:date>2006-02-13T19:42:22Z</dc:date>
    </item>
    <item>
      <title>Re: WebVPN Group authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/webvpn-group-authentication/m-p/440879#M5859</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Under Configuration | General | Authentication , you can enble group lookup and choose a delimiter (for example @).&lt;/P&gt;&lt;P&gt;After that you can log in with user@yourgroup .&lt;/P&gt;&lt;P&gt;yourgroup can be the only one able to do webvpn .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this help you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Morgan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Mar 2006 13:56:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/webvpn-group-authentication/m-p/440879#M5859</guid>
      <dc:creator>morgsizun</dc:creator>
      <dc:date>2006-03-01T13:56:05Z</dc:date>
    </item>
    <item>
      <title>Re: WebVPN Group authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/webvpn-group-authentication/m-p/440880#M5860</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If this is the only way, it means I cannot separate my&lt;/P&gt;&lt;P&gt;WebVPN users in distinct groups, isn't it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to find a way of assigning WebVPN users to different groups in a secure way; because even if I configure the Radius server to return the right Class Attribute (Class="OU=&lt;GROUPNAME&gt;;"), it seems to be ignored (at least for WebVPN connections): users logging in as user@anygroup get the attributes of that group, if the group authorizes WebVPN!&lt;/GROUPNAME&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Mar 2006 14:19:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/webvpn-group-authentication/m-p/440880#M5860</guid>
      <dc:creator>abdus_salam_ictp</dc:creator>
      <dc:date>2006-03-23T14:19:26Z</dc:date>
    </item>
    <item>
      <title>Re: WebVPN Group authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/webvpn-group-authentication/m-p/440881#M5861</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can create different internally configured groups and put users in these groups(for example to have differents ACL):&lt;/P&gt;&lt;P&gt;user1@group1&lt;/P&gt;&lt;P&gt;user2@group2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These groups have to be internally configured because i don't think you can assign WebVPN attributes by Radius server(so your radius attribute will be ignored).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Mar 2006 16:14:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/webvpn-group-authentication/m-p/440881#M5861</guid>
      <dc:creator>morgsizun</dc:creator>
      <dc:date>2006-03-24T16:14:03Z</dc:date>
    </item>
    <item>
      <title>Re: WebVPN Group authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/webvpn-group-authentication/m-p/440882#M5862</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was able to partially resolve this issue.  To assign users to a different group(using webvpn) we will need to pass group information during RADIUS authentication. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, What i was not able to resolves was using some Webvpn users to authenticate using Local database and some on Radius server.  I tried different ways like using "@" during login. Each time i tried to login,  By defaultVPN concentator passes info to Radius server, Which rejectes as there are no users defined in radius server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Mar 2006 19:28:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/webvpn-group-authentication/m-p/440882#M5862</guid>
      <dc:creator>ittiadmin</dc:creator>
      <dc:date>2006-03-24T19:28:07Z</dc:date>
    </item>
    <item>
      <title>Re: WebVPN Group authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/webvpn-group-authentication/m-p/440883#M5863</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Take a group "webvpn" internally configured .&lt;/P&gt;&lt;P&gt;Create locally a user called "local" that you assign to this group and on the radius server a user called "external".&lt;/P&gt;&lt;P&gt;If you choose the option "strip group" on global authentication parameters on your vpn3000 , you will be able to log on using either "local" or "external@webvpn".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you don't use "strip group" , you have to create a user "external@webvpn" on the radius server(this can be interesting if you want to put the same acccount in differents groups).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Morgan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Mar 2006 15:19:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/webvpn-group-authentication/m-p/440883#M5863</guid>
      <dc:creator>morgsizun</dc:creator>
      <dc:date>2006-03-27T15:19:26Z</dc:date>
    </item>
  </channel>
</rss>

