cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
411
Views
5
Helpful
1
Replies

Cisco anyconnect profile connectrion configuration

nor61k
Level 1
Level 1

good day! our task is to configure anyconnect as follows: for user to get attribute 25 from radius server and grant privileges based on it. Hence several questions arose:
1)As i noticed only one group policy(it's name should be equal to attr 25) can be bound to connection profile so how can i make 1 connect profile so users could connect via it and be granted with different rights?
2) how to create policy for every group police? should I create separate acl for every group policy and that's it?
3) how can i provide access to internet for users not through internet but via local internet during anyconnect session

1 Reply 1

Francesco Molino
VIP Alumni
VIP Alumni

Hi

 

You can assign only 1 group power user. 

You have 2 choices:

- you create as many groups as needed and push these groups through radius and then filter accesses using standard policies

- you have 1 group for all users and push them a vpn filter acl using filter-id attribute or dACL which is passed using cisco av-pair attribute.

 

Your radius is Cisco ISE or something else?

 

Your last question is to provide internet access to anyconnect using their local internet (so split tunnel should be used) or through central internet (full tunnel should be configured).

 

Thanks


Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: