cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
431
Views
0
Helpful
1
Replies

ASA SSLVPN configuration

reachabdulla
Level 1
Level 1

Hi.

My client requires SSL VPN to be configured at their site. I had followed the 'SSL VPN Client (SVC) on ASA Using ASDM Configuration Example' from the cisco website. The client has some more requests based on their setup. They require authentication through their ACS server. This was implemented and worked well. Now they have a new requirement. They would like to grant SSLVPN to all their users, but apply ACL filters based on groups. For example, 'accounting' people should be assigned specific IP based on their username. 'Sales' people should be assigned specific IP based on their username. On the ASA we would put ACL to restrict accounting people from accessing sales and vice versa.

I need to create groups (accounting and sales) on my ACS, and have IP address assignment based on the username. Also, I need to know what further configurations I need to perform on the ASA.

Please guide me to perform such a process. Please help in this case.

Also, please advice if there is any other better method or technique to meet the clients requirement.

My device information is as follows:

ASA 5510. ASDM 7.1(2)

ACS 3.3

Regards.

Mohammed Abdulla.

1 Reply 1

mmorris11
Level 4
Level 4

Mohammed,

You will need to upgrade to ACS 4.0 to do this. It provides all the radius hooks needed to do the kind of authorization that you are talking about in a way that is consistent with ASA group policy.

HTH pls rate!

Review Cisco Networking for a $25 gift card