cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1340
Views
5
Helpful
1
Replies

Anyconnect setup with multiple connection profiles and radius

robertokippins
Level 1
Level 1

Hello I have anyconnect VPN configured with multiple connection profiles on my ASA firewall and the firewall authenticates with a Windows radius server.

 

image.jpg

I'm trying to separate the access for different users but any user account can authenticate with all the connection profiles. How can I keep this authentication separate so that non admins cannot use the Administrator profile and so on?

1 Reply 1

Hi,
You could use the radius attribute "Cisco-VPN3000:CVPN3000/ASA/PIX7x-Tunnel-Group-Name CONTAINS <TUNNEL NAME>" inconjunction with the AD group to authenticate the users to the different tunnel groups (aka connection profiles). In your example you'd create 3 rules, 1 for each tunnel-group/connection profile.

 

Here is an example, although it's for ISE, it is the same principle.

 

HTH