09-13-2011 08:09 AM
Hi
I have configured cisco router as easy vpn server.
everything working fine.
but i can;t find how to assign static ip to specified vpn client. (assign by MAC or by name)
i tryed to create dhcp binding:
ip dhcp pool vpnclient
host 192.168.111.50 255.255.255.0
hardware-address 0005.9a3c.00a9
client-name vpnclient
but this do not affect on ezvpn client ip address ..
Solved! Go to Solution.
09-13-2011 09:35 PM
Hey Andrii good trick, noted down
You would need to include the IP Pool of group A on the Split tunneling ACL of group B and viceversa.
I hope it makes sense
If it doesnt let me know
Raga
09-13-2011 08:12 AM
Hi Adrii,
This is not supported on routers only on the ASA and the address assigment gets done based on user id not on MAC address.
HTH.
Raga
09-13-2011 10:28 AM
thank you Luis for your reply.
okay another questions:
1) is it possible to change local pool lease parameters ?
2) is it possible to get ezvpn clients by name in any way?
thank you in advance
09-13-2011 12:12 PM
Andrii:
1) No, the IP address will remain assigned to a given client as long as the VPN client remains connected. You cant change that.
2) You can only do this on the ASA, not on a router. On the ASA you can statically assign an IP address to a given user for example:
username cisco123 password ffIRPGpDSOJh9YLq username cisco123 attributes vpn-framed-ip-address 192.168.5.1 255.255.255.0
Unfortunately, the router's capabilities in regards to VPN are a little limited
compared to the ASA's.
I hope this clarifies your questions.
Raga
09-13-2011 03:37 PM
Luis, thank you again for clarification.
But i found the trick I can do :
-create second vpn group and "second ezvpn server". assign group to srv
-create separate local pool with only one ip address in it
-use this connection to connect my "unusuall ezvpn client"
profit
09-13-2011 03:38 PM
but only one thing i can;'t do for now - it's make the clients of these groups "visible" to each other.
09-13-2011 09:35 PM
Hey Andrii good trick, noted down
You would need to include the IP Pool of group A on the Split tunneling ACL of group B and viceversa.
I hope it makes sense
If it doesnt let me know
Raga
09-14-2011 10:55 AM
Hi Diego,
thank you for your help! now everyhting works fine.
09-14-2011 10:58 AM
Sweet!
Glad to hear that I was able to help
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide