cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
879
Views
0
Helpful
1
Replies

Restricting access by group

krisarowland
Community Member

I have a vpn set up on my PIX with two vpngroups - one for my wireless employees and one for my wireless visitors. I have a visitor account set up in my radius server that is used for authentication to the visitor group. Both groups are set for authentication via radius. My problem is that I do not want a visitor to be able to use that account to authenticate using the wireless employee profile. Is there a way that if I can configure my radius server to put the visitor account in a group - that I can restrict access on the pix when someone tries to log on from this group? Help - any suggestions on how to handle this issue will be greatly appreciated!

1 Reply 1

irisrios
Level 11
Level 11

This is possible I guess. Heres are a couple of white paper which could have some info.

Network Access Restrictions White Paper

http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_white_paper09186a00801a8fd0.shtml

Securing ACS Running on Microsoft Windows Platforms

http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_white_paper09186a00800887d8.shtml

Review Cisco Networking for a $25 gift card