cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
602
Views
0
Helpful
0
Replies

ASA 5515 for VPN, using RADIUS and VLANs from our network

quacktacular
Level 1
Level 1

I have an ASA 5515x and I'm looking to setup a VPN solution like this:

  1. We already have an existing Meraki Security Appliance (this is our router / DHCP server etc).
  2. The ASA will provide VPN service only
  3. Want it to use existing RADIUS server for authentication
  4. Uses filter-id / group from RADIUS to apply Group Policy 
  5. Uses the Group Policy to dump clients into the correct VLAN on our network (will setup multiple interfaces for VLANS on the LAN port).
  6. The Meraki MX will then take care of firewall rules / DHCP etc.

This thread looked helpful, and made it seem like its possible: https://supportforums.cisco.com/t5/vpn/asa-vlan-mapping-feature-limited-to-local-network-only/td-p/1452295

 

It has proven to be a bit challenging! So far I have gotten the ASA to talk to our RADIUS server. It authenticates alright within our management network.

 

I'm having trouble getting the basic VPN going, though. Ran through the Wizards but can't get Clientless VPN or AnyConnect to connect from the outside. I am a new to ASA, and have tried following the guides but I'm not sure where to look next? :)

0 Replies 0