06-29-2009 03:23 PM - edited 03-10-2019 04:34 PM
Hi there,
I'm using Microsoft Network Policy server (formerly known as IAS server) for Radius Authentication. Is there a way to configure NPS so it will assign a VPN Group Policy on the ASA? Basically, I'd like to create multiple VPN group policies for different types of users and assign them via AD groups so when the user logs in to the VPN they get the Policy designed for them.
Thanks in advance,
--Brandon
06-30-2009 01:00 AM
See the below config example:-
http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00808d1a7c.shtml
HTH>
07-14-2010 07:58 PM
Yes, this works just fine with Microsoft NPS. In a nutshell, you tell NPS to return the radius attribute 25 (It's called "Class") and assign it the value of ou=MyVPNGroupPolicy where MyVPNGroupPolicy is the name of your group policy in the ASA.
I want to say this option is under the standard radius attributes on one of the last configuration screens of the wizard. You do NOT need to configure this using an LDAP setup, you can continue to use NPS, just like you did IAS.
07-16-2020 05:19 AM
I did like you said with multiple group policy name in an ASA 5512. But my problem is that any user from AD can log in any group even if they are not in the group in AD. Please help
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide