cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2464
Views
50
Helpful
19
Replies

ASA anyconnect LDAP/BAse DN and client profiles

AyoubC
Level 1
Level 1

Hello Sec GURUs, 

I have two different questions please: 

1- Im using Anyconnect with LDAP server (AD) to feetch the user ad creds, everything work fine as long as i'm point think LDAP server DC=companyname, DC=domaine, DC=com. Once I adjust the BASE DN to narrow down the OU group(CN=engineering, OU=remoteusers, DC=companyname, DC=domaine, DC=com) the and anyconnect users failed to connect, I'm I missing another parameter, Please guide me on how I can do that, 

 

2- Is there a way to use ClientProfile to control the following,  make the Anyconnect "disconnect"Button grayed out after a user connect, also I want to restrict the user machine to access to internet before until the user connect his VPN AnyConnect. 

 

THANKS!!!

19 Replies 19

AyoubC
Level 1
Level 1

@Rob Ingram that was the last piece of the puzzle, you're right it seems that after mapping the correct group policy, it inherits along with that vpn-simultaneous-logins  "0" from the default policy-group (NO ACCESS)

Attribute mapping works like a charm now, I'll create now more groups and perform more tests.

 

Glad your issue is solve
and you are so so welcome,
@Rob Ingram  thanks again for clarifying the default group-policy. 

AyoubC
Level 1
Level 1

Thank you @MHM Cisco World , 

One more question, I'm a fun of ASDM, and I m wondering where I can find "vpn-simultaneous-logins  " or it's a CLI command only. ?

@AyoubC it's a setting defined under the group-policy and is configurable via ASDM. Here is an example:

300-735-Part-04-Q03-026.jpg

AyoubC
Level 1
Level 1

Sounds great ! 

Review Cisco Networking for a $25 gift card