08-08-2011 12:54 PM
hello
I have Remote Access VPN users (IPsec) who are terminated on Cisco ASA 5520 (v8.2). For those users, AAA is done on the ACS. Group-policies and tunnel groups are defined on ASA. Initialy I had all VPN users defined on ASA and group policies were associated with each user. Each group policy had it’s own IP pool for users. Now, I moved users to ACS. How can I associate group policy, defined on ASA, with users group defined on ACS? Is it possible that ACS send to ASA information about IP pool for different group policy?
Users will use ONE vpn profile BUT based on the Active Directory group they belong to they obtain a different IP address for each group.
Can it be done ?
ACS version is 5.2.
Thank you
Ilie Neagu
08-10-2011 10:39 AM
answer from Cisco....
"
...
As I have understood it till now, the issue is that you need to assign IP pools based on AD group membership of the VPN users.
In ACS 5.x IP Pool management is not supported.
While RADIUS servers nearly always did this in the early dial up days, today DHCP is commonly used. For ACS 5, a decision was made to drop IP Pool management, and recommend that customers use DHCP.
So, unlike 4.x, 5.x does not have that capability.
I will check and let up know if there is any attribute which can be pushed from the ACS for pool assignment."
07-17-2013 05:48 AM
http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/vpnadd.html#wp999685
http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/vpnadd.html#wp999685
Using attribute 217 and Group mapping, pool names can be pushed from ACS.
07-17-2013 09:14 AM
Edward is correct , besides you can use framed ip address to specify ip
Sent from Cisco Technical Support iPad App
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide