11-06-2008 11:19 AM - edited 03-11-2019 07:09 AM
Hello,
I managed an ASA 5510 for a client, and they have roughly 100 remote access VPN users. They want to be able to monitor who is logged onto the remote access VPN at any time, but I do not want to give them access to the firewall to do show vpn-sessiondb, or access to ASDM, unless there is a limited view login where they can only see the current VPN connections or something.
Has anyone accomplished this or found a way to do this?
Thanks.
11-07-2008 06:21 AM
If your client has AAA, you can use AAA authorization (that's how we do it).
Hope that helps.
11-07-2008 12:54 PM
You can also set up local authorization.
http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/mgaccess.html#wp1072168
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide