<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD - AnyConnect Local User migration from ASA. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-anyconnect-local-user-migration-from-asa/m-p/5274773#M1120264</link>
    <description>&lt;P&gt;Hey Marvin, thanks for this idea (its been a while since I used DAPs!).&lt;/P&gt;
&lt;P&gt;I looked into it, I could set a user message, network ACL and "custom attribute" in a DAP. The network ACL ticks my first requirement, but the custom attribute only appears to support 3 other attributes with no option to set the address pool or group policy on a per user basis &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="darrenj_1-1742881659958.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/242328iE33D27B7FD7378D9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="darrenj_1-1742881659958.png" alt="darrenj_1-1742881659958.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="darrenj_0-1742881621861.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/242327iAA93B4ED65442B1D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="darrenj_0-1742881621861.png" alt="darrenj_0-1742881621861.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;So, I'm back into a position of looking for an option without using a AAA server or some other external server (before someone mentions that as a solution).&lt;/P&gt;
&lt;P&gt;Darren&lt;/P&gt;</description>
    <pubDate>Tue, 25 Mar 2025 05:51:13 GMT</pubDate>
    <dc:creator>darrenj</dc:creator>
    <dc:date>2025-03-25T05:51:13Z</dc:date>
    <item>
      <title>FTD - AnyConnect Local User migration from ASA.</title>
      <link>https://community.cisco.com/t5/network-security/ftd-anyconnect-local-user-migration-from-asa/m-p/5274761#M1120262</link>
      <description>&lt;P&gt;Hey all, I'm migrating from an ASA to FTD (managed by FMC). In the current ASA deployment, we have lots of VPN users that connect to a single tunnel-group and authenticate using local user credentials configured on the ASA.&lt;/P&gt;
&lt;P&gt;Now for the magic....based on the username that logs in, the ASA will assign a group-policy (contains stuff like IP pool to use, split-tunneling, etc) and a VPN filter (which restricts access to specific resources). This works great and gives me complete flexibility. Example user;&lt;/P&gt;
&lt;P&gt;username darrentest password &amp;lt;password&amp;gt; encrypted&lt;BR /&gt;username darrentest attributes&lt;BR /&gt;vpn-group-policy GP_TEST&lt;BR /&gt;vpn-filter value ACL_TEST&lt;/P&gt;
&lt;P&gt;Now I try and set up the same thing in v7.4 of FMC and its a big fail. When I create a username/password there is no option to configure attributes like group-policy, VPN filter, etc.&lt;/P&gt;
&lt;P&gt;Spoiler Alert! I know this can be achieved with AAA servers (RADIUS attributes) but I don't have this and I simply want to migrate my existing solution.&lt;/P&gt;
&lt;P&gt;Has anyone come across this before and is my understanding of this big limitation correct? I can't even see it working with FlexConfigs &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Darren&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Mar 2025 04:42:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-anyconnect-local-user-migration-from-asa/m-p/5274761#M1120262</guid>
      <dc:creator>darrenj</dc:creator>
      <dc:date>2025-03-25T04:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: FTD - AnyConnect Local User migration from ASA.</title>
      <link>https://community.cisco.com/t5/network-security/ftd-anyconnect-local-user-migration-from-asa/m-p/5274765#M1120263</link>
      <description>&lt;P&gt;You can use dynamic access policy with condition being username. It can then assign a VPN filter or static IP (but not a group policy AFAIK).&lt;/P&gt;</description>
      <pubDate>Tue, 25 Mar 2025 05:23:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-anyconnect-local-user-migration-from-asa/m-p/5274765#M1120263</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-03-25T05:23:02Z</dc:date>
    </item>
    <item>
      <title>Re: FTD - AnyConnect Local User migration from ASA.</title>
      <link>https://community.cisco.com/t5/network-security/ftd-anyconnect-local-user-migration-from-asa/m-p/5274773#M1120264</link>
      <description>&lt;P&gt;Hey Marvin, thanks for this idea (its been a while since I used DAPs!).&lt;/P&gt;
&lt;P&gt;I looked into it, I could set a user message, network ACL and "custom attribute" in a DAP. The network ACL ticks my first requirement, but the custom attribute only appears to support 3 other attributes with no option to set the address pool or group policy on a per user basis &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="darrenj_1-1742881659958.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/242328iE33D27B7FD7378D9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="darrenj_1-1742881659958.png" alt="darrenj_1-1742881659958.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="darrenj_0-1742881621861.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/242327iAA93B4ED65442B1D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="darrenj_0-1742881621861.png" alt="darrenj_0-1742881621861.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;So, I'm back into a position of looking for an option without using a AAA server or some other external server (before someone mentions that as a solution).&lt;/P&gt;
&lt;P&gt;Darren&lt;/P&gt;</description>
      <pubDate>Tue, 25 Mar 2025 05:51:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-anyconnect-local-user-migration-from-asa/m-p/5274773#M1120264</guid>
      <dc:creator>darrenj</dc:creator>
      <dc:date>2025-03-25T05:51:13Z</dc:date>
    </item>
    <item>
      <title>Re: FTD - AnyConnect Local User migration from ASA.</title>
      <link>https://community.cisco.com/t5/network-security/ftd-anyconnect-local-user-migration-from-asa/m-p/5274931#M1120272</link>
      <description>&lt;P&gt;You're right. I though I recalled being able to assign a static IP in there but I just checked on my side and it's not an option.&lt;/P&gt;
&lt;P&gt;Unfortunately you may have to use the option that you mentioned not wanting. There are some free ones that will serve, but it does require setting up an external server.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Mar 2025 13:39:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-anyconnect-local-user-migration-from-asa/m-p/5274931#M1120272</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-03-25T13:39:16Z</dc:date>
    </item>
    <item>
      <title>Re: FTD - AnyConnect Local User migration from ASA.</title>
      <link>https://community.cisco.com/t5/network-security/ftd-anyconnect-local-user-migration-from-asa/m-p/5275118#M1120288</link>
      <description>&lt;P&gt;Thanks for checking my sanity your side too mate. It is quite lame I must say, its been close to 10 years now and still so much functionality has been lost in the move from ASA to FTD/Firepower. I've worked on Cisco firewalls for about 20 years now (back to PIXs!) and its not surprising to see them lose so much ground in the firewall space when you compare them to other vendors. Ah well.....&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 01:22:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-anyconnect-local-user-migration-from-asa/m-p/5275118#M1120288</guid>
      <dc:creator>darrenj</dc:creator>
      <dc:date>2025-03-26T01:22:35Z</dc:date>
    </item>
  </channel>
</rss>

