10-23-2009 11:08 AM - edited 02-21-2020 03:45 AM
Is there a way to allow access to Clientless (webvpn) for some users but not to AnyConnect? We want powerusers to use AnyConnect and normal users to use the Clientless. Right now all users can access either one. We're using IAS RADIUS for authentication. Thanks.
10-23-2009 11:27 AM
terryfojas- Sorry to jump in on your posting but was wondering if you could help me. How do you have IAS RADIUS setup? We are trying to do that in our office but it fails. Thank you.
Jim
10-23-2009 11:43 AM
On IAS:
- Create a client that points to your ASA's IP
- Client-vendor is RADIUS Standard
-Check that shared secret matches your ASA's
-Create a Remote Access Policy with "Grant remote access permission" checked.
On ASA:
Enter your IAS' IP on ASDM-Config, Device Management,Users/AAA,AAA Server Groups
10-27-2009 06:16 AM
I have it setup but when I test it to authenticate a user I get this error message- ERROR: Authentication Rejected:AAA failure.
Our network admin says the IAS is setup to use MS-CHAPv2, but the ASA is sending it via PAP. Can we force MS-CHAP or are we stuck with PAP?
10-30-2009 01:45 PM
tunnel-group yourvpngroup ppp-attributes
no authentication chap
no authentication ms-chap-v1
authentication ms-chap-v2
11-03-2009 12:56 PM
Thank you for responding and for your help.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide