11-19-2022 01:33 AM
Hello Sec GURUs,
I have two different questions please:
1- Im using Anyconnect with LDAP server (AD) to feetch the user ad creds, everything work fine as long as i'm point think LDAP server DC=companyname, DC=domaine, DC=com. Once I adjust the BASE DN to narrow down the OU group(CN=engineering, OU=remoteusers, DC=companyname, DC=domaine, DC=com) the and anyconnect users failed to connect, I'm I missing another parameter, Please guide me on how I can do that,
2- Is there a way to use ClientProfile to control the following, make the Anyconnect "disconnect"Button grayed out after a user connect, also I want to restrict the user machine to access to internet before until the user connect his VPN AnyConnect.
THANKS!!!
Solved! Go to Solution.
11-23-2022 05:01 AM
@Rob Ingram that was the last piece of the puzzle, you're right it seems that after mapping the correct group policy, it inherits along with that vpn-simultaneous-logins "0" from the default policy-group (NO ACCESS)
Attribute mapping works like a charm now, I'll create now more groups and perform more tests.
11-23-2022 05:45 AM
Glad your issue is solve
and you are so so welcome,
@Rob Ingram thanks again for clarifying the default group-policy.
11-23-2022 06:01 AM
Thank you @MHM Cisco World ,
One more question, I'm a fun of ASDM, and I m wondering where I can find "vpn-simultaneous-logins " or it's a CLI command only. ?
11-23-2022 06:10 AM
@AyoubC it's a setting defined under the group-policy and is configurable via ASDM. Here is an example:
11-23-2022 08:15 AM
Sounds great !
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide