10-25-2015 06:08 PM
10-25-2015 08:04 PM
Remote access VPN users are assigned addresses (mapping to internal VLANs) according to the tunnel-group or connection profile that they connect on.
You could make multiple connection profiles and lock each user to a specific one.
10-25-2015 08:39 PM
Thanks for the reply Marvin and I'm glad to hear that it is possible.
I cannot try this out for now as we haven't bought this unit yet.
This will certainly help with the decision making.
I do however got a ASA 5505 which I am going to test the method you have suggested.
I believe both 5505 and 5506-X are somewhat similar (except that 5506-X got routed ports with UTM capabilities)
10-26-2015 09:45 AM
I would suggest going another direction with this. Instead of having several connection profiles, I suggest having one connection profile that everyone connects to and then create several group-policy and lock the users to their specific group-policy. You can also assign a VLAN in the group policy that the VPN client will be assigned to aswell as VPN-filters to restrict other access, etc.
MYASA(config-group-policy)# ?
group_policy configuration commands:
vlan
vpn-filter
--
Please remember to select a correct answer and rate helpful posts
10-26-2015 10:02 AM
Hi Marius,
I agree - your method is probably a better one. It's less confusion as the end users do not have to choose anything special.
10-26-2015 03:38 PM
Thanks Marius.
Great stuff - thanks both for helping out.
I will get back after trying this on a 5505 - which may actually take a while.
10-08-2018 07:51 AM
Greeting,
I need expertise in similar VLAN related configuration for anyconnect on FTD.
In our setup, IP assignment to RAS users is done by Radius server. Radius server also assign different VLAN IDs to different region users. I want to understand how I need to configure those VLANs on FTD? Do I need to configure subinterfaces and assign vlans to them?
All users will be using same applications, so how should I configure routing on FTD so specific subinterface will be preferred?
Thanks for your help in advance.
---
Regards,
Sagar Phadatare.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide