cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2188
Views
0
Helpful
3
Replies

ASA 8.2 - ACS 5.2 with dynamic VPN IP pool assignment

ineagu
Level 1
Level 1

hello

I have Remote Access VPN users (IPsec) who  are terminated on Cisco ASA 5520 (v8.2). For those users, AAA is done on the ACS.  Group-policies and tunnel groups are defined on ASA. Initialy I had all  VPN users defined on ASA and group policies were associated with each  user. Each group policy had it’s own IP pool for users. Now, I moved  users to ACS. How can I associate group policy, defined on ASA, with  users group defined on ACS? Is it possible that ACS send to ASA  information about IP pool for different group policy?

Users will use ONE vpn profile BUT based on the Active Directory group they belong to they obtain a different IP address for each group.

Can it be done ?

ACS version is 5.2.

Thank you

Ilie Neagu

3 Replies 3

ineagu
Level 1
Level 1

answer from Cisco....

"

...

As I have understood it till now, the issue is that you need to assign IP pools based on AD group membership of the VPN users.

In ACS 5.x IP Pool management is not supported. 
 
While RADIUS servers nearly always did this in the early dial up days, today DHCP is commonly used. For ACS 5, a decision was made to drop IP Pool management, and recommend that customers use DHCP.
So, unlike 4.x, 5.x does not have that capability. 
I will check and let up know if there is any attribute which can be pushed from the ACS for pool assignment."

Shaoqin Li
Level 3
Level 3

Edward is correct , besides you can use framed ip address to specify ip

Sent from Cisco Technical Support iPad App

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: