I have a vpn set up on my PIX with two vpngroups - one for my wireless employees and one for my wireless visitors. I have a visitor account set up in my radius server that is used for authentication to the visitor group. Both groups are set for authentication via radius. My problem is that I do not want a visitor to be able to use that account to authenticate using the wireless employee profile. Is there a way that if I can configure my radius server to put the visitor account in a group - that I can restrict access on the pix when someone tries to log on from this group? Help - any suggestions on how to handle this issue will be greatly appreciated!