<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: access-list for remote access vpn users in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/access-list-for-remote-access-vpn-users/m-p/1675827#M558422</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Halim&lt;/P&gt;&lt;P&gt;thanks for your reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but my freind every time the vpn user get other ip for the same pool, however i need full access to other user connected&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 07 Apr 2011 05:50:51 GMT</pubDate>
    <dc:creator>Ibrahim Jamil</dc:creator>
    <dc:date>2011-04-07T05:50:51Z</dc:date>
    <item>
      <title>access-list for remote access vpn users</title>
      <link>https://community.cisco.com/t5/network-security/access-list-for-remote-access-vpn-users/m-p/1675825#M558420</link>
      <description>&lt;P&gt;Hi Folks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How to designate access-list for the remote access vpn users in order to let them access specific subnet or host,&lt;/P&gt;&lt;P&gt;asa 5510 and acs is in the picture&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:17:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-for-remote-access-vpn-users/m-p/1675825#M558420</guid>
      <dc:creator>Ibrahim Jamil</dc:creator>
      <dc:date>2019-03-11T20:17:40Z</dc:date>
    </item>
    <item>
      <title>Re: access-list for remote access vpn users</title>
      <link>https://community.cisco.com/t5/network-security/access-list-for-remote-access-vpn-users/m-p/1675826#M558421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can configure "vpn-filter" access-list to allow them to only access specific subnets.&lt;/P&gt;&lt;P&gt;The ACL will say: from &lt;VPN-POOL-SUBNET&gt; &lt;MASK&gt; &lt;INTERNAL subnet=""&gt; &lt;MASK&gt;&lt;/MASK&gt;&lt;/INTERNAL&gt;&lt;/MASK&gt;&lt;/VPN-POOL-SUBNET&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;You can also add TCP or UDP port to the access list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ACL is then applied to "vpn-filter" then to the specific group-policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the command for your reference:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/uz.html#wp1630190"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/uz.html#wp1630190&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Apr 2011 22:27:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-for-remote-access-vpn-users/m-p/1675826#M558421</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-04-06T22:27:20Z</dc:date>
    </item>
    <item>
      <title>Re: access-list for remote access vpn users</title>
      <link>https://community.cisco.com/t5/network-security/access-list-for-remote-access-vpn-users/m-p/1675827#M558422</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Halim&lt;/P&gt;&lt;P&gt;thanks for your reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but my freind every time the vpn user get other ip for the same pool, however i need full access to other user connected&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Apr 2011 05:50:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-for-remote-access-vpn-users/m-p/1675827#M558422</guid>
      <dc:creator>Ibrahim Jamil</dc:creator>
      <dc:date>2011-04-07T05:50:51Z</dc:date>
    </item>
    <item>
      <title>Re: access-list for remote access vpn users</title>
      <link>https://community.cisco.com/t5/network-security/access-list-for-remote-access-vpn-users/m-p/1675828#M558423</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are using ASA local database as the authentication server, you can configure specific IP Address for that user.&lt;/P&gt;&lt;P&gt;Then you can create multiple vpn-filter accordingly, and assign the vpn-filter to the group-policy, and lastly, assign that group-policy to the user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can just create specific IP Address, vpn-filter, group-policy for the user that you want more restricted access, and leave the rest as what is currently configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just make sure that the ip address that you assign to the user does not overlap with the ip pool that you have created.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Apr 2011 06:38:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-for-remote-access-vpn-users/m-p/1675828#M558423</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-04-07T06:38:02Z</dc:date>
    </item>
    <item>
      <title>Re: access-list for remote access vpn users</title>
      <link>https://community.cisco.com/t5/network-security/access-list-for-remote-access-vpn-users/m-p/1675829#M558424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Halim&lt;/P&gt;&lt;P&gt;i m using ACS for authentication , now how?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for sharing the knowledge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Apr 2011 06:47:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-for-remote-access-vpn-users/m-p/1675829#M558424</guid>
      <dc:creator>Ibrahim Jamil</dc:creator>
      <dc:date>2011-04-07T06:47:09Z</dc:date>
    </item>
    <item>
      <title>Re: access-list for remote access vpn users</title>
      <link>https://community.cisco.com/t5/network-security/access-list-for-remote-access-vpn-users/m-p/1675830#M558425</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ibrahim.&lt;/P&gt;&lt;P&gt;In ACS, set the radius attribute 25 (class) to: 'OU=GROUP_POLICY_NAME;'&lt;/P&gt;&lt;P&gt;Then define a group policy called GROUP_POLICY_NAME on your asa with the correct vpn filter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alternately, you may have a vpn-filter attribute that you can configure in ACS. Check the interface configuration, and radius VPN3000/ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Apr 2011 06:56:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-for-remote-access-vpn-users/m-p/1675830#M558425</guid>
      <dc:creator>Bastien Migette</dc:creator>
      <dc:date>2011-04-07T06:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: access-list for remote access vpn users</title>
      <link>https://community.cisco.com/t5/network-security/access-list-for-remote-access-vpn-users/m-p/1675831#M558426</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,can u&amp;nbsp; please&amp;nbsp; paste a sample for the configuration based on the below input&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also my pool its like 172.16.30.100 - 172.16.30.200&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the destination address witch i want to be restricted for specific users its 172.16.50.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i forgot to mention that we are using client full vpn&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks in advance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Apr 2011 08:59:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-for-remote-access-vpn-users/m-p/1675831#M558426</guid>
      <dc:creator>Ibrahim Jamil</dc:creator>
      <dc:date>2011-04-07T08:59:52Z</dc:date>
    </item>
    <item>
      <title>Re: access-list for remote access vpn users</title>
      <link>https://community.cisco.com/t5/network-security/access-list-for-remote-access-vpn-users/m-p/1675832#M558427</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Go in Interface Configuration, Advanced Settings on ACS, and check "Per-user TACACS+/RADIUS Attributes"&lt;/P&gt;&lt;P&gt;then in Interface Configuration, Radius IETF, check "[025] Class" for User (assuming you want per user policies. If you want to make a policy for a group of users, just edit the group of the user instead of the user in ACS)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edit your user, and modify the attribute 25: (OU=MyGp;)&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/5/3/8/31835-tmp.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;and then create the group policy on the asa:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list MyGpFilter extended permit ip any host 1.2.3.4&lt;/P&gt;&lt;P&gt;group-policy MyGp internal&lt;BR /&gt;group-policy MyGp attributes&lt;BR /&gt; vpn-filter value MyGpFilter&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will indicate the ASA that the user should use the group policy MyGp, and the group policy define a VPN Filter.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Apr 2011 09:12:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-for-remote-access-vpn-users/m-p/1675832#M558427</guid>
      <dc:creator>Bastien Migette</dc:creator>
      <dc:date>2011-04-07T09:12:51Z</dc:date>
    </item>
    <item>
      <title>Re: access-list for remote access vpn users</title>
      <link>https://community.cisco.com/t5/network-security/access-list-for-remote-access-vpn-users/m-p/1675833#M558428</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks bastien&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Apr 2011 09:37:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-for-remote-access-vpn-users/m-p/1675833#M558428</guid>
      <dc:creator>Ibrahim Jamil</dc:creator>
      <dc:date>2011-04-07T09:37:32Z</dc:date>
    </item>
    <item>
      <title>Re: access-list for remote access vpn users</title>
      <link>https://community.cisco.com/t5/network-security/access-list-for-remote-access-vpn-users/m-p/1675834#M558429</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi again&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my users will be resided in active directory,so now what the config will be? my manger wont accept users in the acs , now how to do it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 Apr 2011 12:08:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-for-remote-access-vpn-users/m-p/1675834#M558429</guid>
      <dc:creator>Ibrahim Jamil</dc:creator>
      <dc:date>2011-04-09T12:08:17Z</dc:date>
    </item>
  </channel>
</rss>

