If you have checked the allow user to select then you need to configure the Alias for the connection profile and next time the user will connect he would see that alias configured there. If there are multiple connection with the group-alias configured than you will see a drop down list and the user can select the group he want to connect to.
If you do not select this option than no matter how many connection profile you will configure the connect will always land on the DefaultWebVPNGroup profile.
If you do not wan to use the group alias you also have the option to configure a group-url. If you configure a group-url then you don't check "allow user to select connection profile". you can configure a url and use that url to connect in that user will not know how many other profiles are there.
to configure the group-url you need to do the following:
Have you got FQDN for your VPN SERVER IP address , if yes you can specific your Group URL for each group ,where other group will be unknown to end user .
One advantage of using group-url over group-alias (group drop-down) is that you do not expose the group names as the latter method does.
How do you configure the group-url if the ASA VPN gateway is behind a NAT device?
The host/URL that the user enters will be used for the group mapping. Therefore, you have to use the NAT'd address, not the actual address on the ASA's outside interface. The best alternative is to use FQDN instead of IP address for group-url mapping.
All mapping is implemented on HTTP protocol level (based on information the browser sends) and a URL is composed to map from information in incoming HTTP headers. The host name or IP is taken from the host header and the rest of the URL from the HTTP request line. This means that the host/URL the user enters will be used for the group mapping.
ASA 8.x: Allow Users to Select a Group at WebVPN Login via Group-Alias and Group-URL Method
Community Live Event Video
Are you ready to level up your security? Learn more about how Cisco SecureX can help you simplify your security and maximize operational efficiency.
This event talks about Cisco SecureX, its benefits, features, and usage. Th...
Hi all,I cannot understand why is something working very well they create a way to complicate things in Cisco ASA OS. I have a rule :object network LOCAL_ADRESS1 host 192.168.20.12 nat (VLAN20,outside) source static LOCAL_ADRESS1 interface&...
It is our pleasure to officially announce the finalists in the 2021 IT Blog Awards. We are now looking to our amazing tech community to check out the amazing line up of bloggers, vloggers and podcasters. Make sure to vote for your favorites...
Community Live Event Slides
This event talks about Cisco SecureX, its benefits, features, and usage. The session includes sample use cases and live demonstrations.
Cisco expert Luis Silva talks about how this solution can integrate Cisco technology and ...
Hello All, Recently I got an opportunity to perform POC with Cisco ISE (2.7 Patch 4) and Aruba Wireless AP (IAP) to perform 802.1x EAP-FAST (machine + user) authentication followed by Posture Assessment on Windows 10 Machines (installed with AnyConnect 4....