<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Tunnel-Group | Client Address Pool in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-tunnel-group-client-address-pool/m-p/4540301#M1086816</link>
    <description>&lt;P&gt;Thanks for the info. This is really helpful. I was wondering if there was a command to disconnect all the VPN active users without resorting to reloading the ASA. Is there such a command?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best, ~ zK&lt;/P&gt;</description>
    <pubDate>Thu, 27 Jan 2022 13:34:08 GMT</pubDate>
    <dc:creator>skhirbash</dc:creator>
    <dc:date>2022-01-27T13:34:08Z</dc:date>
    <item>
      <title>ASA Tunnel-Group | Client Address Pool</title>
      <link>https://community.cisco.com/t5/network-security/asa-tunnel-group-client-address-pool/m-p/4538781#M1086761</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created two ip local pools (ip_pool_CorpUsr and ip_pool_GuestUsr) and specified the IP range for each pool. Secondly, I assigned ip_pool_CorpUsr to tunnel-group CorpUsers and ip_pool_GuestUsr to tunnel-group Guests. This configuration is working just fine in the production environment.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;tunnel-groups:&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - CorpUsers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Guests&lt;/P&gt;&lt;P&gt;ip pools:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp; ip_pool_CorpUsr&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp; ip_pool_GuestUsr&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was trying to modify the ip pool ranges, so I tired to test in the lab by assigning different ip pools between the tunnel-groups and encountered an issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is what I was trying to do:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - I added&amp;nbsp; ip_pool_CorpUsr to the tunnel-group Guests&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - I tried to remove this ip pool (ip_pool_CorpUsr) from the Guests tunnel-group, but, then, I received the following error message:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"ERROR: Address pool ip_pool_CorpUsr is in use.&lt;BR /&gt;&amp;nbsp;ERROR: Some addresses in the pool are still in use by VPN,can't remove it."&lt;/P&gt;&lt;P&gt;I don't understand why I am receiving this error message if I was simply trying to remove an ip pool that is used by a different tunnel-group (CorpUsers) rom a tunnel-group (Guests) that's using a different ip pool (ip_pool_GuestUsr).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best, ~zK&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 23:22:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-tunnel-group-client-address-pool/m-p/4538781#M1086761</guid>
      <dc:creator>zekebash</dc:creator>
      <dc:date>2022-01-25T23:22:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Tunnel-Group | Client Address Pool</title>
      <link>https://community.cisco.com/t5/network-security/asa-tunnel-group-client-address-pool/m-p/4538902#M1086763</link>
      <description>&lt;P&gt;This is an expected behaviour if there are users utilising IP address from this pool even though its not the same tunnel group/group policy.&lt;/P&gt;
&lt;P&gt;Only way is to force log off all the users and remove the configuration. This is documented on bug -&amp;nbsp;CSCvn69188&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 04:12:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-tunnel-group-client-address-pool/m-p/4538902#M1086763</guid>
      <dc:creator>Udupi Krishna.</dc:creator>
      <dc:date>2022-01-26T04:12:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Tunnel-Group | Client Address Pool</title>
      <link>https://community.cisco.com/t5/network-security/asa-tunnel-group-client-address-pool/m-p/4540301#M1086816</link>
      <description>&lt;P&gt;Thanks for the info. This is really helpful. I was wondering if there was a command to disconnect all the VPN active users without resorting to reloading the ASA. Is there such a command?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best, ~ zK&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 13:34:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-tunnel-group-client-address-pool/m-p/4540301#M1086816</guid>
      <dc:creator>skhirbash</dc:creator>
      <dc:date>2022-01-27T13:34:08Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Tunnel-Group | Client Address Pool</title>
      <link>https://community.cisco.com/t5/network-security/asa-tunnel-group-client-address-pool/m-p/4540306#M1086819</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/53788"&gt;@skhirbash&lt;/a&gt; you can use the "vpn-sessiondb logoff" command, just append any of the options below&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; vpn-sessiondb logoff&lt;BR /&gt;all&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; All sessions&lt;BR /&gt;anyconnect&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AnyConnect sessions&lt;BR /&gt;index&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Index specific session&lt;BR /&gt;ipaddress &amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP Address specific sessions&lt;BR /&gt;l2l IPsec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LAN-to-LAN sessions&lt;BR /&gt;name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; Username specific sessions&lt;BR /&gt;protocol&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Protocol specific sessions&lt;BR /&gt;ra-ikev1-ipsec&amp;nbsp;&amp;nbsp; IKEv1 IPsec Remote Access sessions&lt;BR /&gt;ra-ikev2-ipsec&amp;nbsp;&amp;nbsp; Generic IKEv2 IPsec Remote Access sessions&lt;BR /&gt;tunnel-group&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Tunnel-group sessions&lt;BR /&gt;vpn-lb VPN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Load Balancing Mgmt sessions&lt;BR /&gt;webvpn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WebVPN sessions&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to logoff all users use the command "&lt;STRONG&gt;vpn-sessiondb logoff all&lt;/STRONG&gt;"&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2022 13:38:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-tunnel-group-client-address-pool/m-p/4540306#M1086819</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-01-27T13:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Tunnel-Group | Client Address Pool</title>
      <link>https://community.cisco.com/t5/network-security/asa-tunnel-group-client-address-pool/m-p/4541276#M1086841</link>
      <description>&lt;P&gt;You also have the ability to log off VPN users in ASDM: Monitoring-&amp;gt;VPN-&amp;gt;VPN Statistics-&amp;gt;Sessions: from here you have similar options&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jan 2022 12:52:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-tunnel-group-client-address-pool/m-p/4541276#M1086841</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2022-01-28T12:52:35Z</dc:date>
    </item>
  </channel>
</rss>

