cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1792
Views
1
Helpful
2
Replies

ASA - ISE GEO location integration for VPN users

Amit Dhanawade
Level 1
Level 1

I have a scenario wherein the customer wants to block traffic coming from international locations. Currently he is terminating any connect users ( VPN ) on ASA 5585 - SSP10

Three types of users typically connect to Vodafone network.

  • Partners
  • Vodafone Employees
  • Off-roll employees


Scenario expected


  • If and only if the Vodafone employee is connecting to the network from international location ( outside india ) they that connection should be allowed , All other connections from outside India should be blocked
  • If the user is within India then it should be allowed no matter

Is there a solution around this ?

1 Accepted Solution

Accepted Solutions

Jason Kunst
Cisco Employee
Cisco Employee

Perhaps with an mdm provider providing the location context and mdm integration

Please keep in mind this is public forum would recommend removing customer name

View solution in original post

2 Replies 2

Jason Kunst
Cisco Employee
Cisco Employee

Perhaps with an mdm provider providing the location context and mdm integration

Please keep in mind this is public forum would recommend removing customer name

Timothy Abbott
Cisco Employee
Cisco Employee

To add to Jason's reponse, geo location functionality is something not native in ISE currently.  I know that Meraki Systems Manager has the ability to flag a device compliant or not based on location so you could be a solution like that to meet the customer's needs.

Regards,

-Tim