cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
288
Views
2
Helpful
1
Replies

ASA/FTD RADIUS Class 25 precedence

I'm trying to work out how to achieve different Group Policies for different users.  I know how to send Attribute 25 Class to select the group policy, however would this override the group policy that was previously selected by using a specific URL?

This is a working FTD setup with FMC that I didn't build.  It looks like the Connection Profile is being selected though the URL the client connects to and there is group policy attached that has a split tunnel ACL.  I need to override this group policy for selected users so that the split tunnel is different.  I can update the Radius rules so that it checks for Windows Group Membership and then send Attribute 25 with the name of a different group policy that has a different split tunnel ACL, but will this override what the FTD already sent to the Radius server?

1 Reply 1

tvotna
Spotlight
Spotlight

Yes, it will.