<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX remote access - two groups in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956449#M494055</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;is there any way to do it on PIX 6.3(5)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 21 Apr 2008 11:54:52 GMT</pubDate>
    <dc:creator>camila9898</dc:creator>
    <dc:date>2008-04-21T11:54:52Z</dc:date>
    <item>
      <title>PIX remote access - two groups</title>
      <link>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956437#M494040</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please is it possible to distinguish two remote access groups on radius server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example i have two groups. One for employes and second for externalist.&lt;/P&gt;&lt;P&gt;I authentificate them on one radius server.&lt;/P&gt;&lt;P&gt;It is possible to distinguish between these two groups on radius server?&lt;/P&gt;&lt;P&gt;How can i do this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Because when i create two tunnel groups and two policy groups, i am still able to access both groups with user from employe or externalist group. And when i look to log on IAS server, i wasnt able to distinguish between log entry when i login as employe and when i login as externalist &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance&lt;/P&gt;&lt;P&gt;Tomas&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:57:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956437#M494040</guid>
      <dc:creator>tomas.backo</dc:creator>
      <dc:date>2020-02-21T09:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: PIX remote access - two groups</title>
      <link>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956438#M494042</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tomas,&lt;/P&gt;&lt;P&gt;  Please explain what exactly you want to achieve.&lt;/P&gt;&lt;P&gt;  You have two tunnel-groups now, and you dont want the user of tunnel-group externalist to access tunnel-group employee or what?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Mar 2008 14:58:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956438#M494042</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-03-31T14:58:01Z</dc:date>
    </item>
    <item>
      <title>Re: PIX remote access - two groups</title>
      <link>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956439#M494043</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Husycisco,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;firstly sorry for not very clearly written question, i was in a hurry &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So what i need to do:&lt;/P&gt;&lt;P&gt;i have to different type of users: employers and externalist.&lt;/P&gt;&lt;P&gt;I am using radius server for authentification of users.&lt;/P&gt;&lt;P&gt;I am using pre-shared keys for both tunnel-groups. (I can't suppose, that user's from one group don't know pre-shared key from second)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I can connect as employer to employer's tunnel-group and as externalist to externalist's tunnel-group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But because I am using the same radius server for both groups (so users for both groups are defined on radius - there are two windows groups exactly), I can also connect as employer to externalist's tunnel and vice-versa as externalist to employer's tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand this behaviour: radius isn't able to distinguish now, if employer is authenticating to employer's or externalist's tunnel. Radius only know, that this user is defined and permited to login to VPN. So access is granted to user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is: is it possible to distinguish on radius which tunnel-group is user trying to log in? ( Maybe send accessed group as attribute from PIX to radius )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And is it possible to setup microsoft IAS policy to distinguish between request from employer's and externalist's group?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much for you help.&lt;/P&gt;&lt;P&gt;Hope that now it is much more clear, and sorry my for my english &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Tomas&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Mar 2008 20:06:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956439#M494043</guid>
      <dc:creator>tomas.backo</dc:creator>
      <dc:date>2008-03-31T20:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: PIX remote access - two groups</title>
      <link>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956440#M494045</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I also have this need.  I have an ASA and would like to present two different WebVPN customizations to each group.  I think we may be looking at aaa authorization here, as opposed to authentication but not sure.  Any help would be appreciated.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Apr 2008 21:34:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956440#M494045</guid>
      <dc:creator>reachonenetadm</dc:creator>
      <dc:date>2008-04-08T21:34:28Z</dc:date>
    </item>
    <item>
      <title>Re: PIX remote access - two groups</title>
      <link>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956441#M494046</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oh, totally forgot that question, let me check the attribute and respond....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Apr 2008 22:53:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956441#M494046</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-04-08T22:53:43Z</dc:date>
    </item>
    <item>
      <title>Re: PIX remote access - two groups</title>
      <link>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956442#M494048</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tomas, if you are still interested, let me know and I will write a step by step&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Apr 2008 01:28:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956442#M494048</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-04-09T01:28:50Z</dc:date>
    </item>
    <item>
      <title>Re: PIX remote access - two groups</title>
      <link>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956443#M494049</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;reachonenetadm,&lt;/P&gt;&lt;P&gt;  Are you using Windows IAS?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Apr 2008 02:16:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956443#M494049</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-04-09T02:16:20Z</dc:date>
    </item>
    <item>
      <title>Re: PIX remote access - two groups</title>
      <link>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956444#M494050</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Husycisco,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am still very interested in &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; and i will be very thankfull if you can help me with this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank in advance&lt;/P&gt;&lt;P&gt;Tomas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Apr 2008 05:57:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956444#M494050</guid>
      <dc:creator>tomas.backo</dc:creator>
      <dc:date>2008-04-09T05:57:47Z</dc:date>
    </item>
    <item>
      <title>Re: PIX remote access - two groups</title>
      <link>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956445#M494051</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tomas,&lt;/P&gt;&lt;P&gt;  Ok then, we have 2 tunnel-groups and 2 group-policies for tunnel-groups, here is what you have to do.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;  *First, we should lock the group-policies to tunnel groups so that one policy would not use the other tunnel-group. For achieving this, following is the sample CLI commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tunnel-group test1 general-attributes&lt;/P&gt;&lt;P&gt;default-group-policy policy1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tunnel-group test2 general-attributes&lt;/P&gt;&lt;P&gt;default-group-policy policy2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;group-policy policy1 attributes&lt;/P&gt;&lt;P&gt;group-lock value test1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;group-policy policy2 attributes&lt;/P&gt;&lt;P&gt;group-lock value test2&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;  *Now lets do the config on IAS. You should have 2 seperate Remote access policies created for your 2 different windows groups in IAS, for example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remote access policy x&lt;/P&gt;&lt;P&gt;If Windows Group matches "yourdomain\externalist"&lt;/P&gt;&lt;P&gt;Grant access&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remote access policy y&lt;/P&gt;&lt;P&gt;If Windows Group matches "yourdomain\employees"&lt;/P&gt;&lt;P&gt;Grant access&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   Now in Remote access policy x, click edit profile&amp;gt;click advanced&amp;gt;click add.  Choose "Class" attribute. This RA policy is for externalists, and lets say that we want to lock that windows group to test1 tunnel group. So enter  OU=policy1   value in Class attribute. This is the group-policy name that we locked to tunnel-group test1&lt;/P&gt;&lt;P&gt;  Follow the same path and enter  OU=policy2  for Remote access policy y, the employees windows group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Apr 2008 11:19:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956445#M494051</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-04-09T11:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: PIX remote access - two groups</title>
      <link>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956446#M494052</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am using Windows IAS, yes.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Apr 2008 14:00:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956446#M494052</guid>
      <dc:creator>reachonenetadm</dc:creator>
      <dc:date>2008-04-09T14:00:45Z</dc:date>
    </item>
    <item>
      <title>Re: PIX remote access - two groups</title>
      <link>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956447#M494053</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That worked brilliantly for me.  Thanks VERY much for posting this.  &lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Apr 2008 15:44:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956447#M494053</guid>
      <dc:creator>reachonenetadm</dc:creator>
      <dc:date>2008-04-09T15:44:44Z</dc:date>
    </item>
    <item>
      <title>Re: PIX remote access - two groups</title>
      <link>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956448#M494054</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are welcome reachonenetadm, and thanks for rating. I hope it works for Tomas too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Apr 2008 16:23:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956448#M494054</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-04-09T16:23:43Z</dc:date>
    </item>
    <item>
      <title>Re: PIX remote access - two groups</title>
      <link>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956449#M494055</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;is there any way to do it on PIX 6.3(5)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Apr 2008 11:54:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956449#M494055</guid>
      <dc:creator>camila9898</dc:creator>
      <dc:date>2008-04-21T11:54:52Z</dc:date>
    </item>
    <item>
      <title>Re: PIX remote access - two groups</title>
      <link>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956450#M494056</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Husycisco,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it is working for me also.&lt;/P&gt;&lt;P&gt;I answer before 2 weeks .. respectively i think that i answer &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; ... but in fact i only rate this conversation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So one more time, thank you very much. You help me a lot with this problem!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tomas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Apr 2008 12:08:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956450#M494056</guid>
      <dc:creator>tomas.backo</dc:creator>
      <dc:date>2008-04-21T12:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: PIX remote access - two groups</title>
      <link>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956451#M494057</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tomas,&lt;/P&gt;&lt;P&gt;  Nice to hear that it worked for you, and thanks for rating.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Apr 2008 13:36:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-remote-access-two-groups/m-p/956451#M494057</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-04-21T13:36:24Z</dc:date>
    </item>
  </channel>
</rss>

