I am trying to develop a configuration on a VPN 3000 concentrator that will support both Cisco VPN 3000 clients and Windows 2K/XP L2TP/IPSec clients.
The catch:
- certificates are being used for IKE authentication
- the certificates are auto issued from Active Directory and not really distinquishable from each other.
It is important to be able to associate the clients with the correct GROUP so I need an alternative means for GROUP Matching besides the certificate DN.
Authorization by USERID or IP Address is not an option, there are thousands of users and administration would be a nightmare.
I look forward to any solutions that I might have missed.