Hello Kishore,
If you set the VPN-filter properly you can prevent the users from talking to each other.
You can check the following document that explains how the VPN filters work and how you set them:
http://www.cisco.com/c/en/us/support/docs/secur...
Hello lupingyao,
Yes, that is possible.
You have to configure secondary authentication in your ASA and the Active Directory part will depend on which protocol you are using.
You can refer to this link for the double-authentication:
http://www.cisco....
Hello Kishore,
If you want to use tunnelall and make the users not to be able to talk to each other you have several options:
- Have the command same-security permit intra-interface disabled
- Use a VPN filter in the group-policy allowing the conne...
Hello ereinoehl1,
I think that you are only missing the following nat:
nat (wifi,outside) source static Remote2-Wireless Remote2-Wireless destination static Main1-All Main1-All no-proxy-arp route-lookup
Please let me know if that works.
Regards,
-...
houstonrob,
If you don't care about the configuration then you can jump to 9.1, you should only check if your device has enough RAM and enough space in the flash.
Regards,
-Javier-