<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Remote VPN multiple Profile in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-remote-vpn-multiple-profile/m-p/4169267#M1074939</link>
    <description>&lt;P&gt;You don't force them to select, you tell the ASA to lock them to a single selection. As &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/292493"&gt;@Mohammed al Baqari&lt;/a&gt; mentioned, we do that with group-lock.&lt;/P&gt;
&lt;P&gt;The specifics of how you do that are covered in several free online videos and articles. Just google "cisco anyconnect group lock ad authentication" (for example).&lt;/P&gt;</description>
    <pubDate>Mon, 19 Oct 2020 08:52:42 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2020-10-19T08:52:42Z</dc:date>
    <item>
      <title>ASA Remote VPN multiple Profile</title>
      <link>https://community.cisco.com/t5/network-security/asa-remote-vpn-multiple-profile/m-p/4169172#M1074935</link>
      <description>&lt;P&gt;ASA Remote VPN (Ipsec) users connecting from home. ASA is authenticated to AAA servers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway to achieve the below.&lt;/P&gt;&lt;P&gt;If user1 connects via anyconnect ASA should send authentication request too AAA server 1&lt;/P&gt;&lt;P&gt;If user2 connects via anyconnect ASA should send authentication request too AAA server 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's ok if custom anyconnect profile needs to be added at user-end.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 06:22:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-remote-vpn-multiple-profile/m-p/4169172#M1074935</guid>
      <dc:creator>manvik</dc:creator>
      <dc:date>2020-10-19T06:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Remote VPN multiple Profile</title>
      <link>https://community.cisco.com/t5/network-security/asa-remote-vpn-multiple-profile/m-p/4169204#M1074936</link>
      <description>Hi, you can create two group policies with 2 aaa servers, one for each&lt;BR /&gt;user. If you enable group alias the users will get a drop down to select&lt;BR /&gt;their relevant group when connecting to vpn. Then the user will&lt;BR /&gt;authenticate against his aaa server depending on his group selection from&lt;BR /&gt;the drop down.  You use group lock feature to avoid users mixing groups.&lt;BR /&gt;&lt;BR /&gt;***** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Mon, 19 Oct 2020 07:21:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-remote-vpn-multiple-profile/m-p/4169204#M1074936</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2020-10-19T07:21:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Remote VPN multiple Profile</title>
      <link>https://community.cisco.com/t5/network-security/asa-remote-vpn-multiple-profile/m-p/4169236#M1074938</link>
      <description>&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Issue is users are already connected and working via RVPN. We want few of those users to authenticate against AAA server 2.&lt;/P&gt;&lt;P&gt;In this case, how can we force the users to select their group.&lt;/P&gt;&lt;P&gt;They are already using anyconnect with single group/profile in it.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 08:23:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-remote-vpn-multiple-profile/m-p/4169236#M1074938</guid>
      <dc:creator>manvik</dc:creator>
      <dc:date>2020-10-19T08:23:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Remote VPN multiple Profile</title>
      <link>https://community.cisco.com/t5/network-security/asa-remote-vpn-multiple-profile/m-p/4169267#M1074939</link>
      <description>&lt;P&gt;You don't force them to select, you tell the ASA to lock them to a single selection. As &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/292493"&gt;@Mohammed al Baqari&lt;/a&gt; mentioned, we do that with group-lock.&lt;/P&gt;
&lt;P&gt;The specifics of how you do that are covered in several free online videos and articles. Just google "cisco anyconnect group lock ad authentication" (for example).&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 08:52:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-remote-vpn-multiple-profile/m-p/4169267#M1074939</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-10-19T08:52:42Z</dc:date>
    </item>
    <item>
      <title>ASA Remote VPN multiple Profile</title>
      <link>https://community.cisco.com/t5/network-security/asa-remote-vpn-multiple-profile/m-p/4171019#M1075013</link>
      <description>&lt;P&gt;They use different profile! So each profile have it auth/authorz aaa.&lt;/P&gt;&lt;P&gt;If both profile use same group key&lt;/P&gt;&lt;P&gt;then group-lock need config with max-users&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what happened when we use both&lt;/P&gt;&lt;P&gt;for example&lt;/P&gt;&lt;P&gt;user1 will use profile 1 with aaa1 and max-users=1, with group-lock this user will always use this group&lt;/P&gt;&lt;P&gt;user2 will use profile 2 with aaa2 and max-users=1, with group-lock this user will always use this group&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;without max-users&lt;/P&gt;&lt;P&gt;both user1 and user2 will use profile1 and group-lock make then always use this profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please correct me if I wrong.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2020 13:37:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-remote-vpn-multiple-profile/m-p/4171019#M1075013</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2020-10-21T13:37:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Remote VPN multiple Profile</title>
      <link>https://community.cisco.com/t5/network-security/asa-remote-vpn-multiple-profile/m-p/4178352#M1075456</link>
      <description>&lt;P&gt;Can someone give steps on configuring&amp;nbsp;&lt;SPAN&gt;group alias in IPSEC RVPN.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It would be helpful with step-by-step methods. Req is - &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When end-user selects Profile 1 in anyconnect, they would be authenticating to AAA server1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When end-user selects Profile 2 in anyconnect, they would be authenticating to AAA server2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can someone help with steps to achieve the above.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2020 05:20:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-remote-vpn-multiple-profile/m-p/4178352#M1075456</guid>
      <dc:creator>manvik</dc:creator>
      <dc:date>2020-11-04T05:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Remote VPN multiple Profile</title>
      <link>https://community.cisco.com/t5/network-security/asa-remote-vpn-multiple-profile/m-p/4178365#M1075457</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Here you go:&lt;BR /&gt;&lt;BR /&gt;ciscoasa(config)# *tunnel-group remote-1 type ipsec-ra*&lt;BR /&gt;ciscoasa(config)# *tunnel-group remote-1 general-attributes*&lt;BR /&gt;ciscoasa(config-general)# *authentication-server-group aaa_1*&lt;BR /&gt;&lt;BR /&gt;ciscoasa(config)# *tunnel-group remote-2 type ipsec-ra*&lt;BR /&gt;ciscoasa(config)# *tunnel-group remote-2 general-attributes*&lt;BR /&gt;ciscoasa(config-general)# *authentication-server-group aaa_2*&lt;BR /&gt;&lt;BR /&gt;This is where you assign different aaa groups to different profiles. Rest&lt;BR /&gt;is normal anyconnect configuration. Follow this configuration guide.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa95/configuration/vpn/asa-95-vpn-config/vpn-extserver.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa95/configuration/vpn/asa-95-vpn-config/vpn-extserver.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;***** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Wed, 04 Nov 2020 06:40:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-remote-vpn-multiple-profile/m-p/4178365#M1075457</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2020-11-04T06:40:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Remote VPN multiple Profile</title>
      <link>https://community.cisco.com/t5/network-security/asa-remote-vpn-multiple-profile/m-p/4178369#M1075458</link>
      <description>&lt;P&gt;Thank You&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/292493"&gt;@Mohammed al Baqari&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can the remote users select "tunnel-group remote-2" from anyconnect.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2020 06:46:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-remote-vpn-multiple-profile/m-p/4178369#M1075458</guid>
      <dc:creator>manvik</dc:creator>
      <dc:date>2020-11-04T06:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Remote VPN multiple Profile</title>
      <link>https://community.cisco.com/t5/network-security/asa-remote-vpn-multiple-profile/m-p/4178392#M1075463</link>
      <description>Just enable group-alaias under webvpn config. Then a dropdown will be&lt;BR /&gt;presented on the client when they sign in.&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Wed, 04 Nov 2020 07:37:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-remote-vpn-multiple-profile/m-p/4178392#M1075463</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2020-11-04T07:37:13Z</dc:date>
    </item>
  </channel>
</rss>

