cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Who Me Too'd this topic

ASA WebVPN. How do you restrict access to users in an AD group using LDAP?

jstevensunico
Level 1
Level 1

Hi All,

I am trying to configure separate WebVPN connection profiles to give different portal bookmark contents to users based on their AD group membership.  This has been very difficult, even though I beleive it should be easy.

The login page of teh ASA by default has a dropdown to allow default users to access the default portal and the SSL VPN client connection.

There are two other portals that I would like to restrict access to based on AD group membership.  I have set these up to be selected by URL.

The biggest problem is, I have no way of knowing how to go about this.  The AAA LDAP options show a group membership search, which I have configured, but I cannot say "Profile X is restricted to AD group CarpetBaggers", so that if soneone that is NOT a carpetbagger tries to log in, it fails.

I can only do an all or nothing scenario.

It would be nice to use Dynamic Access Policies to do this, and I have created a few, but they do NOT seem to work when the drop down aliases or URLs are in use.  So how do I go about using them in this scenario?  Turning off the aliases or URLs is not really an option right now.

Scenario 1 would work the best for me.  Restrict access to profiles/groups based on AD group membership using LDAP.

Scenario 2 would be an ideal longer term solution.

Any thoughts, ideas or assitance would be greatly appreciated.

Cheers

Who Me Too'd this topic