cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
637
Views
0
Helpful
4
Replies

FTD Anyconnect - Internet AD User based policy

er.ankitsharma
Level 1
Level 1

Hello,

 

After deploying Anyconnect VPN and successfully allowing the Anyconect IP Pool to access the internal network resource, now I am facing challenges to deploy a internet policy for these Anyconnect VPN user.

 

I want to restrict the Anyconnect users going out on the internet using a AD username based policy.

 

When I create a outside to outside policy keeping the source as the Anyconnect VPN pool and destination as any with defined AD users and applications like outlook then this policy doesn't hit.

 

It seems that the FTD is not able to check the AD users added to the policy.

 

The rest of the inside to outside policies based on AD username, are working perfectly fine !

 

Please let me know your views on this.

1 Accepted Solution

Accepted Solutions

 

I think we cannot use tunnel policy for this issue. And now I have resolved this issue using Identity policies.

 

 

Thanks!

View solution in original post

4 Replies 4

Have you tried applying these rules using tunnel policies?

--
Please remember to select a correct answer and rate helpful posts

Hi Marius,

 

I haven't tried applying these using tunnel policies.

 

Can we use tunnel policies for Anyconnect VPN and also can we restrict traffic based on usernames using tunnel policies ?

 

Also I noticed connection events where the 'initiator user' column  says 'no authentication required' for the Anyconnect traffic.

Can we use tunnel policies for Anyconnect VPN and also can we restrict traffic based on usernames using tunnel policies ?

As far as I know, it is not possible to restrict traffic based on usernames using tunnel policies.

--
Please remember to select a correct answer and rate helpful posts

 

I think we cannot use tunnel policy for this issue. And now I have resolved this issue using Identity policies.

 

 

Thanks!

Review Cisco Networking products for a $25 gift card