07-07-2004 03:28 AM - edited 03-10-2019 07:53 AM
Hello,
I want to connect to VPN 3000, groups are configured on ACS server and users are stored on a LDAP server. I want to assign IP to VPN client from the VPN 3000 but I want a different IP pool for each group configured on ACS.
On ACS, I don't know how to name the pool that are configured on VPN 3000.
If I try "192.168.1.50-192.168.1.60/255.255.255.0" in
Group Settings > IP Assignement > "Assigned from AAA Client pool"
it doesn't work...
Could someone help me please ?
Regards
07-07-2004 12:36 PM
I have tried to do something similar to what you are attempting, and found that it was not possible with the current versions.
The VPN3000's IP pools unfortunately have no name that can be referenced in ACS, and ACS's internal IP pool functionality is global so we're stuck with a "one-pool fits all" limitation if tryint to go that route.
Hopefully Cisco will chose to implement named IP pools on the concentrator soon. ACS does work well with IOS devices that support named pools.
07-08-2004 06:36 AM
I succeeded what I want to realize : Vpn 3000 chooses an IP in the pool that are configured on ACS and gives it to the client.
Unfortunately, I've got another trouble, my pool use 10.x.y.z addresses and VPN3000 gives to me a 255.0.0.0 netmask but I want to use 255.255.255.0
I read some posts about this but I don't find solution..
Any one could help me ?
Thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide