cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1784
Views
1
Helpful
2
Replies

access restriction with CS ACS based on Radius attr 66

mmihalyfi
Level 1
Level 1

We have a VPN 3000 concentrator where users connect from the internet and extranet too.

We want to restrict some users to certain IP sources, this is in radius attribute 66 Tunnel-Client-Endpoint.

Is this restriction possible with CS ACS 3.1? Could find a way to do it.

THANKS,

Martin

2 Replies 2

b.speltz
Level 4
Level 4

In ACS it would be under the user or group setup and then Radius IETF. If you don't see it there then goto Interface configuration> Radius IETF option for 66.

Also check if you concentrator version is compatible with ACS 3.1

The question is still the same: we want to restrict some users to certain IP sources, this info is in radius attribute 66 Tunnel-Client-Endpoint.

Is this restriction possible with CS ACS 3.1?

Couldn't find a way to do it.

(I can return IP addresses in attribute 66 to the concentrator, but it doesn't seem to process them, so CSACS should deny the request if the received attribute 66 is not O.K.)

THANKS,

Martin