<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can you have different SSL WebVPN's on Cisco ASA 5520? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050970#M419243</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What RADIUS are you using? IAS etc&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 28 Jul 2008 13:01:46 GMT</pubDate>
    <dc:creator>jamesgonzo</dc:creator>
    <dc:date>2008-07-28T13:01:46Z</dc:date>
    <item>
      <title>Can you have different SSL WebVPN's on Cisco ASA 5520?</title>
      <link>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050955#M419187</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I mean is I want to give a company access to an internal website and another company access to a different website, they can only access one website (bookmark)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 10:56:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050955#M419187</guid>
      <dc:creator>jamesgonzo</dc:creator>
      <dc:date>2020-02-21T10:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: Can you have different SSL WebVPN's on Cisco ASA 5520?</title>
      <link>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050956#M419192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the docs its loose.... me personally, the only thing I have got working in a lab is the drop down group option with all the other bells and whistles, which works quite well.  I have not been able to get back to this one in ages, no time soon either, but the below link may point you in the right direction.....unless someone else has cracked this:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/customer/products/ps6120/prod_configuration_examples_list.html" target="_blank"&gt;http://www.cisco.com/en/US/customer/products/ps6120/prod_configuration_examples_list.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jul 2008 22:18:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050956#M419192</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-07-25T22:18:38Z</dc:date>
    </item>
    <item>
      <title>Re: Can you have different SSL WebVPN's on Cisco ASA 5520?</title>
      <link>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050957#M419201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The following link will guide you to a step-by-step process to achieve this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/customer/products/ps6120/products_configuration_example09186a00808bd83d.shtml" target="_blank"&gt;http://www.cisco.com/en/US/customer/products/ps6120/products_configuration_example09186a00808bd83d.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another alternate is the group-url command, but I don't think it supports the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa-ip/sales&lt;/P&gt;&lt;P&gt;asa-ip/marketing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But it does support&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="https://sales-ssl-vpn" target="_blank"&gt;https://sales-ssl-vpn&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="https://marketing-ssl-vpn" target="_blank"&gt;https://marketing-ssl-vpn&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Jul 2008 09:21:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050957#M419201</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-07-26T09:21:48Z</dc:date>
    </item>
    <item>
      <title>Re: Can you have different SSL WebVPN's on Cisco ASA 5520?</title>
      <link>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050958#M419207</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you mean I should just create an Alias for each SSL VPN profile with only the Bookmarks each company needs then email them the URL?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I only accept connections from their external facing IP as well?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Jul 2008 19:04:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050958#M419207</guid>
      <dc:creator>whiteford</dc:creator>
      <dc:date>2008-07-27T19:04:48Z</dc:date>
    </item>
    <item>
      <title>Re: Can you have different SSL WebVPN's on Cisco ASA 5520?</title>
      <link>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050959#M419213</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you have just one IP address, go for the tunnel drop-down menu (as seen on the CCO Doc). That would be a more practical option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jul 2008 01:09:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050959#M419213</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-07-28T01:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: Can you have different SSL WebVPN's on Cisco ASA 5520?</title>
      <link>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050960#M419219</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Interesting,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.) How can I use a different Ip that the "outside" IP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.) I'm strugglinh to find this CCO doc for the tunnel drop-down menu what is this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jul 2008 06:26:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050960#M419219</guid>
      <dc:creator>jamesgonzo</dc:creator>
      <dc:date>2008-07-28T06:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: Can you have different SSL WebVPN's on Cisco ASA 5520?</title>
      <link>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050961#M419222</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1) I'm not aware of anyway, maybe NAT on a upstream device (but I doubt it)&lt;/P&gt;&lt;P&gt;2) DId you not chek this link: &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/customer/products/ps6120/products_configuration_example09186a00808bd83d.shtml" target="_blank"&gt;http://www.cisco.com/en/US/customer/products/ps6120/products_configuration_example09186a00808bd83d.shtml&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jul 2008 06:54:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050961#M419222</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-07-28T06:54:53Z</dc:date>
    </item>
    <item>
      <title>Re: Can you have different SSL WebVPN's on Cisco ASA 5520?</title>
      <link>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050962#M419226</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Strange thing is I don't have access to that site.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jul 2008 07:18:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050962#M419226</guid>
      <dc:creator>jamesgonzo</dc:creator>
      <dc:date>2008-07-28T07:18:56Z</dc:date>
    </item>
    <item>
      <title>Re: Can you have different SSL WebVPN's on Cisco ASA 5520?</title>
      <link>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050963#M419229</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All you have to do is login using your regular Cisco Account or try this link:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/application/pdf/paws/98580/enable-group-dropdown.pdf" target="_blank"&gt;http://www.cisco.com/application/pdf/paws/98580/enable-group-dropdown.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jul 2008 07:37:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050963#M419229</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-07-28T07:37:36Z</dc:date>
    </item>
    <item>
      <title>Re: Can you have different SSL WebVPN's on Cisco ASA 5520?</title>
      <link>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050964#M419230</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great, that has worked, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.) I suppose I should not call the group name something like "My Company" as anyone can get to the page on the internet, unless I can restrict this site only to their external IP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.) It seems I can get to the site either by:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="https://asa-ip/" target="_blank"&gt;https://asa-ip/&lt;/A&gt; (with drop down)&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="https://asa-ip/alias" target="_blank"&gt;https://asa-ip/alias&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this normal or more secure to somehow only use &lt;A class="jive-link-custom" href="https://asa-ip/alias," target="_blank"&gt;https://asa-ip/alias,&lt;/A&gt; but I'm not sure I can turn off the &lt;A class="jive-link-custom" href="https://asa-ip/?" target="_blank"&gt;https://asa-ip/?&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3.) I have created another alias/bookmarks for another company (have 2 profiles now) thing is they can logon to each others alias, how do I stop this?  I want company A to access group A and company B access group B only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jul 2008 09:18:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050964#M419230</guid>
      <dc:creator>jamesgonzo</dc:creator>
      <dc:date>2008-07-28T09:18:16Z</dc:date>
    </item>
    <item>
      <title>Re: Can you have different SSL WebVPN's on Cisco ASA 5520?</title>
      <link>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050965#M419231</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1) If your SSL VPN is on the internet, you need  to control access to the ASA Public IP using an ACL (lets say on your upstream router etc.)&lt;/P&gt;&lt;P&gt;2) I guess this is normal, I doubt you can turn of the ASA-ip thing. That will destroy the purpose of drop-down anyway.&lt;/P&gt;&lt;P&gt;3) You can use 'group-lock' to lock users to particular groups (both locally and via AAA AFAIK).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jul 2008 11:11:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050965#M419231</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-07-28T11:11:22Z</dc:date>
    </item>
    <item>
      <title>Re: Can you have different SSL WebVPN's on Cisco ASA 5520?</title>
      <link>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050966#M419235</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1.) Can the ASA do this?  The 'outside' interface connects to our ISP router (we don't have access), can a ACL be created only to allow external SSL connects from their public IP's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.) Group-lock sounds like just what I need, is this on ASA's ASDM?  I'm using IAS for Radius.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   2.1) I wanted to use a local user account for this (priv 0) but I found out that I could get into the CLI with the account!  Can I stop this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jul 2008 11:31:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050966#M419235</guid>
      <dc:creator>jamesgonzo</dc:creator>
      <dc:date>2008-07-28T11:31:50Z</dc:date>
    </item>
    <item>
      <title>Re: Can you have different SSL WebVPN's on Cisco ASA 5520?</title>
      <link>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050967#M419237</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1) By default I don't think, you might have to turn of sysopt. Not 100% sure about this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Yes it should be available both on the CLI/ASDM. It can also be pushed via AAA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.1) priv 0 can get into the CLI but what can he do? Also you can restrict management traffic by using ASA ACL (ssh/telnet commands)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jul 2008 12:11:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050967#M419237</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-07-28T12:11:54Z</dc:date>
    </item>
    <item>
      <title>Re: Can you have different SSL WebVPN's on Cisco ASA 5520?</title>
      <link>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050968#M419239</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suppose it can be open to the world asong as it's secure.  I just need to work out if "company A" logs on they get "bookmarks A" and if "company B" logs on they get "bookmarks B", plus company A can't access company B bookmarks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You mention group-lock, I will use a local username for each company now, but I'm really struggling to find this group-lock function on the ASDM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jul 2008 12:29:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050968#M419239</guid>
      <dc:creator>jamesgonzo</dc:creator>
      <dc:date>2008-07-28T12:29:27Z</dc:date>
    </item>
    <item>
      <title>Re: Can you have different SSL WebVPN's on Cisco ASA 5520?</title>
      <link>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050969#M419241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i use dynamic access policies to achieve this without using aliases.  im using cisco acs, and apply in the radius class field (number 25) with a setting, i use OU=groupPolicy, where groupPolicy is the name of a specific group policy i have defined in the config.  then i go to DAP and check for this RADIUS setting (not cisco setting).  after it catches it, i can define bookmarks, acl's banners, etc for everyone with this OU setting.  you must check for the entire OU=groupPolicy phrase, or whatever you throw in there.  it could be something like goPackers or something arbitrary like that. i use group policy so i can use the same DAP for ipsec vpns.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jul 2008 12:52:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050969#M419241</guid>
      <dc:creator>blawrimore1</dc:creator>
      <dc:date>2008-07-28T12:52:22Z</dc:date>
    </item>
    <item>
      <title>Re: Can you have different SSL WebVPN's on Cisco ASA 5520?</title>
      <link>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050970#M419243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What RADIUS are you using? IAS etc&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jul 2008 13:01:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050970#M419243</guid>
      <dc:creator>jamesgonzo</dc:creator>
      <dc:date>2008-07-28T13:01:46Z</dc:date>
    </item>
    <item>
      <title>Re: Can you have different SSL WebVPN's on Cisco ASA 5520?</title>
      <link>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050971#M419244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;im using cisco's ACS server, but any ietf radius will do.  im not familiar enough with IAS to tell you where to add the parameters for policy 25 (Class).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ill give you more info on how im using radius in my config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RA vpn with tunnel group name definition.  iow, the pre-shared key and tunnel group are derived from the vpn client profile and matched against RA tunnel group with same name and key.  this way i only have one pcf to give out to users.&lt;/P&gt;&lt;P&gt;aaa against radius box.  the OU=xxx in parameter 25 define for both RAvpn and WebVPN the group policy to use.  i further drill down each remote vendor gets access to which server by creating book marks for each vendor and using DAP to match both parameter 25 and 24 (State).  25 says put in remote vendor (or local user, whatever GP's i have defined already) and 24 will define the DAP with the specific URL-List for the specific vendor.  i have to create multiple DAP's: one DAP for each vendor.  one GP for all my users in a group for a base GP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have three groups:  MIS, Normal-Users, and Vendors.  I have defined one tunnel group, All-users.  i have three GP's:  MIS, Normal-users, Vendors.  I have five DAPs:  Default, MIS, Normal-Users-Dap, Vendor1-DAP, Vendor2-DAP.  MIS and Normal Users DAPs check against parameter 25 only and are assigned accordingly.  Vendor1 and 2 Daps check against 25 and 24 and are assigned accordingly.  i assign parameter 25 on the group of remote vendors in my Radius and parameter 24 on the individual user.  any remote vendor that logs in with 24 unassigned gets no bookmarks at all (Default DAP) and therefore zero access to the network. i did this just in case i neglected to assign parameter 24.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sorry for the long note, hope it makes sense.  just make sure you can assign those parameter values (24 and 25) in IAS and you should be golden with DAP's.  btw, with those parameters, i also have complete customization to RAvpn's, too, with network lists, etc.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jul 2008 17:14:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-you-have-different-ssl-webvpn-s-on-cisco-asa-5520/m-p/1050971#M419244</guid>
      <dc:creator>blawrimore1</dc:creator>
      <dc:date>2008-07-28T17:14:22Z</dc:date>
    </item>
  </channel>
</rss>

