cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1494
Views
0
Helpful
2
Replies

Authentication control on different VPN concentrators

dhcchan
Level 1
Level 1

Hi there,

I have two VPN 3000 concnetrators(concentrator A and concentrator B), one ACE server and one ACS server. The customer wants that some of the users can only logon to concentrator A, but fail to concentrator B. On the other hand, some of the other users can logon to both concentrator A and B. All those users have been distributed with a Secure ID. May I ask that is it possible to achieve this? And would u give me suggestion on how to achieve it?

thanks a lot

David

2 Replies 2

kbeltz
Level 1
Level 1

Under IPSec Parameters > Authentication, select the method you use for user authentication; e.g., external. Be sure to configure the external authentication server appropriately and supply users with the appropriate entries.

lllaci
Level 1
Level 1

Separate Groups? I think you can use 2 groups. "some of the users" use the group-A (generated only in the cont-A), "some of the other users" use the group-B (generated in cont-A and cont-B, too).

I suppose the "some of the users" dont know the group-B parameters.

hi,

LL