03-02-2011 06:10 AM - edited 02-21-2020 05:12 PM
When using certificates with the IPSEC VPN client is there a way use different polices as you would with connection profiles ?
03-16-2011 02:55 AM
Hi,
yes, when using certificates you can use the 'tunnel-group-map' feature to map certificates to tunnel groups (aka connection profiles) based on certain field(s) in the certificate. By default the ASA will map the connection to a tunnel-group with the same name as the OU field in the cert's subject, but you can customize this to use another field.
cfr.
http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/ike.html#wp1053978
hth
Herbert
03-16-2011 07:30 AM
Thanks Herbert - That may fit, I will take a look.
Thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide