<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Client Authentication VPN3000 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/client-authentication-vpn3000/m-p/280383#M6003</link>
    <description>&lt;P&gt;I have a VPN concentrator that is configured for client authentication using an NT domain. I dont want every account in Active Directory to have  VPN access, so i was wondering if it was possible to limit the scope of where the vpn 3000 looks for accounts to authenticate. Can it be limited to a particular organiztional Unit in Active Directory? &lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 18:09:44 GMT</pubDate>
    <dc:creator>henrysacco</dc:creator>
    <dc:date>2020-02-21T18:09:44Z</dc:date>
    <item>
      <title>Client Authentication VPN3000</title>
      <link>https://community.cisco.com/t5/network-access-control/client-authentication-vpn3000/m-p/280383#M6003</link>
      <description>&lt;P&gt;I have a VPN concentrator that is configured for client authentication using an NT domain. I dont want every account in Active Directory to have  VPN access, so i was wondering if it was possible to limit the scope of where the vpn 3000 looks for accounts to authenticate. Can it be limited to a particular organiztional Unit in Active Directory? &lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:09:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-authentication-vpn3000/m-p/280383#M6003</guid>
      <dc:creator>henrysacco</dc:creator>
      <dc:date>2020-02-21T18:09:44Z</dc:date>
    </item>
    <item>
      <title>Re: Client Authentication VPN3000</title>
      <link>https://community.cisco.com/t5/network-access-control/client-authentication-vpn3000/m-p/280384#M6005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You may have to use ACS.   It can check the windows groups and dial-in settings.  then replay to the VPN server correctly. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Mar 2004 01:38:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-authentication-vpn3000/m-p/280384#M6005</guid>
      <dc:creator>kerry.whittaker</dc:creator>
      <dc:date>2004-03-18T01:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: Client Authentication VPN3000</title>
      <link>https://community.cisco.com/t5/network-access-control/client-authentication-vpn3000/m-p/280385#M6006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You would have to use Radius.  Microsoft's built in IAS would do the trick.  It can allow you to specify a group that can access the VPN.  I'm not sure if it can match on an OU though...  Maybe.  You might also have to be in Native mode for some of that to work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Apr 2004 15:05:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/client-authentication-vpn3000/m-p/280385#M6006</guid>
      <dc:creator>jjkruege</dc:creator>
      <dc:date>2004-04-05T15:05:33Z</dc:date>
    </item>
  </channel>
</rss>

