06-01-2018 08:19 PM - edited 02-21-2020 07:50 AM
Created a group policy as a full tunnel and I need to configure one user with full tunnel and access only to one server IP address. is it possible in Cisco remote access VPN?
06-02-2018 04:54 AM
I have never done this, but try, setting up different tunnel groups. It does mean you need multiple vpn aliases. If you want one alias and then provide access beased on user ID, you will need a solution like cisco ISE
For IT:
access-list split-it permit 10.10.10.0 255.255.255.0
group-policy IT-pol internal
group-policy IT-pol attributes
split-tunnel-policy tunnelspecified
split-tunnel-network-list value split-it
exit
tunnel-group IT-grp type remote-access-list
tunnel-group IT-grp general-attributes
default-group-policy IT-pol
For User:
access-list split-user permit 10.10.20.0 255.255.255.0
group-policy User-pol internal
group-policy User-pol attributes
split-tunnel-policy tunnelspecified
split-tunnel-network-list value split-it
exit
tunnel-group User-grp type remote-access-list
tunnel-group User-grp general-attributes
default-group-policy User-pol
As per the above when users will connect to different tunnel-group they will different group-policy and will have different ACL specified.
l
06-05-2018 02:02 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide