04-19-2008 08:26 AM - edited 02-21-2020 10:20 AM
Currently I have my ASA configured to require a active directory login/password to grant remote access. I noticed in my AD tabs, that there is a dial-in tab where you can select allow/deny vpn access.
http://technet.microsoft.com/en-us/library/Bb742382.bug28143-fig3(en-us,TechNet.10).gif
Is there a way to make this work with the ASA so that all AD users aren't allowed vpn access, and so that only selected users are?
04-19-2008 10:13 AM
if yo'ure using IAS as your radius server, you can configure it so that only members of certain AD security groups are allowed to be authenticated via the vpn.
can you tell us more about how yo'ure authenticating against AD though?
04-19-2008 12:48 PM
right now I am using kerberos.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide