cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
985
Views
0
Helpful
2
Replies

Assigned IP pool from ACS to VPN 3000

gauthraj
Level 1
Level 1

Hello,

I want to connect to VPN 3000, groups are configured on ACS server and users are stored on a LDAP server. I want to assign IP to VPN client from the VPN 3000 but I want a different IP pool for each group configured on ACS.

On ACS, I don't know how to name the pool that are configured on VPN 3000.

If I try "192.168.1.50-192.168.1.60/255.255.255.0" in

Group Settings > IP Assignement > "Assigned from AAA Client pool"

it doesn't work...

Could someone help me please ?

Regards

2 Replies 2

d.parks
Level 1
Level 1

I have tried to do something similar to what you are attempting, and found that it was not possible with the current versions.

The VPN3000's IP pools unfortunately have no name that can be referenced in ACS, and ACS's internal IP pool functionality is global so we're stuck with a "one-pool fits all" limitation if tryint to go that route.

Hopefully Cisco will chose to implement named IP pools on the concentrator soon. ACS does work well with IOS devices that support named pools.

I succeeded what I want to realize : Vpn 3000 chooses an IP in the pool that are configured on ACS and gives it to the client.

Unfortunately, I've got another trouble, my pool use 10.x.y.z addresses and VPN3000 gives to me a 255.0.0.0 netmask but I want to use 255.255.255.0

I read some posts about this but I don't find solution..

Any one could help me ?

Thanks