09-24-2003 06:18 PM - edited 02-20-2020 11:00 PM
We are validating our sw vpn users on our 3030 via nt domain. Therefore there are no individual userids.
How can we selectively disable certain users? e.g. A few office workers not allowed to come in from home.
If this were Windows / RAS we could uncheck the dialin box on their user profile - is there some similar setting within Windows for sw VPN users?
Or even better, are these domain authenticated users authenticated against any particular nt group, from which we could then remove them?
09-30-2003 12:01 PM
With NT Domain Authentication, what you are trying is not possible. What you need to do is to configure the concentrator to use Radius. You could refer to http://www.cisco.com/warp/public/471/cisco_vpn_msradius.html and http://www.cisco.com/warp/public/471/vpn3k_ias.html for more configuration information.
09-30-2003 02:58 PM
Thanks kindly for your note. I'll have to check into this further.
If you are able to, this issue should be submitted as a bug / feature enhancement.
If you can query nt for whether or not they're a valid user, you should also be able to query whether or not they are members of the defined group. e.g. admins vs. guests.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide