cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
866
Views
0
Helpful
1
Replies

Block windows Shared Folder over anyconnect

najarian
Level 1
Level 1

Hello everyone, we noticed that in the client VPN group "XXXX" access to internal resources without AD group membership (ATTRIBUTE_MAP) is possible!!. E.g. Open the $ shared folders of internal systems (tested with \\ 10.10.8.10 \c$\ if the user does not have any VPN AD groups; it shouldn't be like that. Can you please tell me why!!??

 

Regard

Ashkan

Mohammad najarian
CCIE #65604
1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

AnyConnect simply allows or denies access to IP addresses. What, if any, access a connected endpoint or users has to a reachable network resource is controlled by the OS on that resource - not AnyConnect or the ASA (or whatever AnyConnect comes in through).

View solution in original post

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

AnyConnect simply allows or denies access to IP addresses. What, if any, access a connected endpoint or users has to a reachable network resource is controlled by the OS on that resource - not AnyConnect or the ASA (or whatever AnyConnect comes in through).