11-04-2021 03:56 AM - edited 11-04-2021 04:30 AM
Hello,
We have two Cisco 1140 in HA. Also on them are configured Anyconnect VPN with Active Directory authentication. Problem is when user is not member of any group he can connect to Cisco Anyconnect. How I can fix this issue?
Solved! Go to Solution.
11-04-2021 06:08 AM
I understand that, read the guide. The purpose of the configuration in the guide is to restrict access if the user is not a member of the group. You create a NOACCESS group policy and set the Simultaneous Login Per User to 0 - meaning they cannot login if not a member of a group.
11-04-2021 04:33 AM
11-04-2021 04:58 AM
FMC, 6.6.4
11-04-2021 05:14 AM
@sadist001 you'll have to use the link above I provided to push out the ldap settings to control the user access.
From version 6.7+ this is built into the GUI, so you could use the built in LDAP attribute maps
11-04-2021 05:36 AM
Thanks for your reply.
Problem is authentication. Filtering using AD Groups works. But if user is not member any group he still can connect to Anyconnect.
11-04-2021 06:08 AM
I understand that, read the guide. The purpose of the configuration in the guide is to restrict access if the user is not a member of the group. You create a NOACCESS group policy and set the Simultaneous Login Per User to 0 - meaning they cannot login if not a member of a group.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide