cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2166
Views
0
Helpful
1
Replies

AnyConnect VPN Local Account Password Expiration

adil.nasser3
Level 1
Level 1

Hello All,

I have configured a new vpn profile set up (new tunnel-group, group-policy, and local accounts).  I would like to set the local accounts to expire after a certain period of time and force the user to change their password periodically.  Is this possible for local accounts configured in the ASA?

Adil

1 Reply 1

rvarelac
Level 7
Level 7

Hi Adil, 

Unfortunately , using the local database this is not possible,  you can specify the VPN access-hours and Session-timeout.  However the password will never expire or force the user to change it. 

This feature is only available using RADIUS, TACACS or LDAP for authentication .

http://www.cisco.com/c/en/us/support/docs/network-management/remote-access/116757-config-asa-remote-00.html

Hope it helps

-Randy-