cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
537
Views
5
Helpful
1
Replies

Anyconnect Group Selection

Steven Williams
Level 4
Level 4

I have created two groups for my Anyconnect clients. I am using NT Domain authentication, but I want to know if it is possible to force an Anyconnect group to a user thats part of a certain OU in AD? For instance the IT group would get a group called IT and have more access than others for the other group called Public. All my IT users are in an OU, so when they authticate with their creds Anyconnect would know they belong to the IT group.                  

1 Reply 1

Jennifer Halim
Cisco Employee
Cisco Employee

Yes, you can configure LDAP attribute map to map user to a specific group-policy.

Here is the configuration guide for your reference:

http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00808d1a7c.shtml

Hope that helps.