08-08-2007 02:15 AM - edited 02-21-2020 10:18 AM
Hi, all
The problem is that I want to configure a local database on the ASA in order to authenticate WebVPN users, but it looks like ASA is using the same database for authenticating users for SSH access. Is there any way to define which users are going to be authenticated only for WebVPN and not for SSH?
08-09-2007 02:32 AM
I thought it could be done under "username testuser attributes" command, but it seems there is no such an option.
08-12-2007 09:34 PM
even i had the same problem, let i had come to know that user will need to authentication via the users created locally for logging in to the device, in such case, i would advice you to login via TACACS, that would be really helpful to track the users who ever logs in via VPN.
08-13-2007 11:23 AM
Actually, I don't want to use TACACS+ for user authentication, because there's going to be only 7-10 WebVPN users, so deploying TACACS+ server doesn't make any sense. But I was really surprised when I found that there's no any possibility to determine which users are only for WebVPN access and which are only for SSH access.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide