02-12-2003 01:19 AM - edited 02-21-2020 10:06 AM
Hi there,
I have two VPN 3000 concnetrators(concentrator A and concentrator B), one ACE server and one ACS server. The customer wants that some of the users can only logon to concentrator A, but fail to concentrator B. On the other hand, some of the other users can logon to both concentrator A and B. All those users have been distributed with a Secure ID. May I ask that is it possible to achieve this? And would u give me suggestion on how to achieve it?
thanks a lot
David
02-18-2003 10:06 AM
Under IPSec Parameters > Authentication, select the method you use for user authentication; e.g., external. Be sure to configure the external authentication server appropriately and supply users with the appropriate entries.
02-19-2003 07:23 AM
Separate Groups? I think you can use 2 groups. "some of the users" use the group-A (generated only in the cont-A), "some of the other users" use the group-B (generated in cont-A and cont-B, too).
I suppose the "some of the users" dont know the group-B parameters.
hi,
LL
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide