03-28-2006 03:21 AM
Hello,
Design question: I have multiple customers that will be VPNing (RA) into a single ASA. I would like to restrict their network access to a single vlan (subnet) on the ASA. Is this possible? I know it can be done w/ downloadable ACLs w/ ACS, but this is not an option right now.
Thanks!!
-Lee
03-28-2006 12:43 PM
Hey Lee,
Instead of using dnld ACL's, I think you could use different ip-local-pool on the ASA for each group defined. Then you'll need to apply the according access-list's to the config.
HTH
Mike
03-28-2006 04:12 PM
a group policy with a vpn filter may be configured on asa in order to restrict the access.
further, a vpn filter can be applied on individual user.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide