12-02-2022 12:58 PM
We are running FTD firewalls connected to FMC and have AnyConnect fully configured and setup. We are using Active Directory to authenticate users for VPN login.
Our office network consists of multiple VLANs that are restricted with ACL rules. All the VLANs of interest are included in the AnyConnect setup. I need to find a way to restrict access per user. For example, when I as the IT admin login to VPN, I should have full non-restricted access to all the subnets, but when one of our contractors logs in, I want to lock it down to only one specific subnet or even only one or a few IP addresses. Is there any way to do this?
Solved! Go to Solution.
12-02-2022 01:09 PM
@Edrissa If using AD change the server to use LDAP you can then use the LDAP attribute map to assign different policy settings to members of different AD groups. For example give IT admin a different IP address pool, the Access Control rule give the users from that IP address pool full unrestricted access. Where a contractor is a member of a different AD group, which is assigned a different IP address pool, the Access Control rules for the Contractors IP pool restricts access.
Example of LDAP attribute map - https://www.cisco.com/c/en/us/support/docs/network-management/remote-access/216313-configure-ra-vpn-using-ldap-authenticati.html
12-02-2022 01:09 PM
@Edrissa If using AD change the server to use LDAP you can then use the LDAP attribute map to assign different policy settings to members of different AD groups. For example give IT admin a different IP address pool, the Access Control rule give the users from that IP address pool full unrestricted access. Where a contractor is a member of a different AD group, which is assigned a different IP address pool, the Access Control rules for the Contractors IP pool restricts access.
Example of LDAP attribute map - https://www.cisco.com/c/en/us/support/docs/network-management/remote-access/216313-configure-ra-vpn-using-ldap-authenticati.html
12-02-2022 02:45 PM
Awesome! This worked perfectly. Thank you very much!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide