cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
417
Views
1
Helpful
4
Replies

Using Radius to assign Anyconnect static IP's in ASA 9.1x

tryingtofixit
Level 1
Level 1

Anyone have this working in production?

I have it working in a limited lab. Seems the only statement I needed to do was go from:

no vpn-addr-assign aaa

To

vpn-addr-assign aaa

My Anyconnect client gets the IP assigned to them in AD. And my other clients continue to pully dhcp from the asa vpn pool. Tested this several times works with no issues.

Is it really this simple?

I don't need to create tunnel-groups, policies, separate anyconnect profiles?

My limited testing shows that vpn-addr-assign aaa isn't overriding  dhcp being given out via my vpndhcp pool.

thanks 

4 Replies 4

Ruben Cocheno
Spotlight
Spotlight

@tryingtofixit 

Yes, it is

Tag me to follow up.
Please mark it as Helpful and/or Solution Accepted if that is the case. Thanks for making Engineering easy again.
Connect with me for more on Linkedin https://www.linkedin.com/in/rubencocheno/

balaji.bandi
Hall of Fame
Hall of Fame

not sure what radius using you need to configure Framed-IP-Address for that to work.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

using Microsoft NPS for radius. did zero config on the NPS. 

Just user NPS for 802.1X for my testing not used for VPN authentication.

check below example : (using ISE) - should get an idea on NPS.

https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/220438-configure-a-static-ip-address-on-an-anyc.html

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Review Cisco Networking for a $25 gift card