cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
962
Views
0
Helpful
5
Replies

Anyconnect FTD

sadist001
Level 1
Level 1

Hello,

 

We have two Cisco 1140 in HA. Also on them are configured Anyconnect VPN with Active Directory authentication. Problem is when user is not member of any group he can connect to Cisco Anyconnect. How I can fix this issue?   

1 Accepted Solution

Accepted Solutions

I understand that, read the guide. The purpose of the configuration in the guide is to restrict access if the user is not a member of the group. You create a NOACCESS group policy and set the Simultaneous Login Per User to 0 - meaning they cannot login if not a member of a group.

View solution in original post

5 Replies 5

FMC, 6.6.4

@sadist001 you'll have to use the link above I provided to push out the ldap settings to control the user access.

 

From version 6.7+ this is built into the GUI, so you could use the built in LDAP attribute maps

https://www.cisco.com/c/en/us/support/docs/network-management/remote-access/216313-configure-ra-vpn-using-ldap-authenticati.pdf

 

 

Thanks for your reply.

 

Problem is authentication. Filtering using AD Groups works. But if user is not member any group he still can connect to Anyconnect. 

I understand that, read the guide. The purpose of the configuration in the guide is to restrict access if the user is not a member of the group. You create a NOACCESS group policy and set the Simultaneous Login Per User to 0 - meaning they cannot login if not a member of a group.