10-18-2020 11:22 PM
ASA Remote VPN (Ipsec) users connecting from home. ASA is authenticated to AAA servers.
Anyway to achieve the below.
If user1 connects via anyconnect ASA should send authentication request too AAA server 1
If user2 connects via anyconnect ASA should send authentication request too AAA server 2
It's ok if custom anyconnect profile needs to be added at user-end.
10-19-2020 12:21 AM
10-19-2020 01:23 AM
Thank you,
Issue is users are already connected and working via RVPN. We want few of those users to authenticate against AAA server 2.
In this case, how can we force the users to select their group.
They are already using anyconnect with single group/profile in it.
10-19-2020 01:52 AM
You don't force them to select, you tell the ASA to lock them to a single selection. As @Mohammed al Baqari mentioned, we do that with group-lock.
The specifics of how you do that are covered in several free online videos and articles. Just google "cisco anyconnect group lock ad authentication" (for example).
11-03-2020 09:20 PM
Can someone give steps on configuring group alias in IPSEC RVPN.
It would be helpful with step-by-step methods. Req is -
When end-user selects Profile 1 in anyconnect, they would be authenticating to AAA server1
When end-user selects Profile 2 in anyconnect, they would be authenticating to AAA server2
Can someone help with steps to achieve the above.
11-03-2020 10:40 PM
11-03-2020 10:46 PM
Thank You @Mohammed al Baqari
How can the remote users select "tunnel-group remote-2" from anyconnect.
11-03-2020 11:37 PM
10-21-2020 06:37 AM
They use different profile! So each profile have it auth/authorz aaa.
If both profile use same group key
then group-lock need config with max-users
what happened when we use both
for example
user1 will use profile 1 with aaa1 and max-users=1, with group-lock this user will always use this group
user2 will use profile 2 with aaa2 and max-users=1, with group-lock this user will always use this group
without max-users
both user1 and user2 will use profile1 and group-lock make then always use this profile.
please correct me if I wrong.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide