05-30-2024 06:27 AM
Is it possible for the DHCP Pool assigned to the user to be based on their Active Directory Group? Like to maybe have a default Pool, but for users in a specific Active Directory Group to get assigned an IP from a different local DHCP Pool?
05-30-2024 06:33 AM
@wmoody329 if you use RADIUS for authentication/authorisation you can authorise the user based on their AD group membership and return a DHCP scope. You'd just create multiple rules based on the number of different AD groups, and return a different DHCP scope as required.
The RADIUS attribute to send to the user is "CVPN3000/ASA/PIX7x-DHCP-Network-Scope", example using ISE:-
05-30-2024 09:40 AM
Rob we are actually using MFA with Azure. I'm not sure if that simplifies the issue or not.
05-30-2024 09:50 AM
@wmoody329 in this scenario before, I have used MFA for authentication and authorisation via RADIUS (ISE), which performs the lookup of the AD group membership and assigns the DHCP scope (as per above).
05-30-2024 06:51 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide