cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
689
Views
12
Helpful
14
Replies

Forcing authentication only on a predefined interface

Hi,

Is there a way to set up a tunnel IPSEC for a certain group only on a predefined interface? And how?

The isamkp must be enabled on all interface, because I have tunnel on all interface..

Thank you.

Massimiliano.

1 Accepted Solution

Accepted Solutions

Well you can remove the systop connection permit-vpn command and allow VPNs through ACL only. This command bypasses ACL check for firewall-terminated crypto traffic; its enabled by default. Disable this, and allow each SPECIFIC IP access to specific crypto interface. Or Deny some and allow others (this would specially be true on the outside).

ASA 8.1 added support for netflow but only on the higher end models (5580-XX). Maybe we see it in the future on other models as well.

Regards

Farrukh

View solution in original post

14 Replies 14

Farrukh Haroon
VIP Alumni
VIP Alumni

For digital certificate based VPNs you can do it like this:

http://www.cisco.com/en/US/docs/ios/12_2t/12_2t4/feature/guide/ftdnacl.html

Regards

Farrukh

Hi Farrukh.

Thank for your reply.

I've no VPN based on digital certificate...how can i obtain the same result?

Thank you.

Massimiliano.

Two questions, which platform and the VPN type (L2L,RA IPSEC, etc?)

Regards

Farrukh

Hi,

The platform is a PIX 525 with OS 7.2

The type of VPN is IPSEC, client-to-gateway....the software is Cisco VPN Client for Linux.

Thank you.

Massimiliano.

For the PIX you don't need to even control this! The host can only 'hit' the crypto map to which it is 'coming from'.

e.g Source IP for VPN client is 4.4.4.4. If this s reachable via the Outside interface (via default route), this host can ONLY access the 'outside' crypto map' It wont be able to access any crypto map applied on other interfaces like DMZ1 , WAN etc.

Regards

Farrukh

Hi Farrukh,

Another way to say what I need.

Say we have a firewall with two interfaces:outside and inside. I've credential (VPN Group and username and password)...we have isakmp enabled on outside and inside...i want that the user using the credential can access in VPN only on one interface (say inside); i don't want control the IP address..

Thank you.

Massimiliano.

P.S.: Another question...PIX or ASA support NetFlow?

Well you can remove the systop connection permit-vpn command and allow VPNs through ACL only. This command bypasses ACL check for firewall-terminated crypto traffic; its enabled by default. Disable this, and allow each SPECIFIC IP access to specific crypto interface. Or Deny some and allow others (this would specially be true on the outside).

ASA 8.1 added support for netflow but only on the higher end models (5580-XX). Maybe we see it in the future on other models as well.

Regards

Farrukh

Hi Farrukh.

Can I made the distinction on which interface to use based on on group and username and password?

Massimiliano.

P.S.: Rating for your response regarding the Netflow and another question:)) How can I collect data (like Netflow) on a PIX/ASA?

Thank you for the rating :).

As I said you need an ASA 5580 for that:

http://www.cisco.com/en/US/docs/security/asa/asa81/netflow/netflow.html

No I don't think you can make it based on groups or usernames. You have to use IPs.

Regards

Farrukh

Thanks.

Massimiliano.

Marwan ALshawi
VIP Alumni
VIP Alumni

by the way if u use ACS for AAA authentication

there is otion called tunnel-group-lock

u can lock a user or group to a spesific vpn tunnel-group on the PIX/ASA

this will be group based on tunnel-group vpn

if helpful Rate

How does that achieve the requirement? I'm sorry I must be missing something here.

Regards

Farrukh

Hi,

But I want lock a group to a particular interface...

Massimiliano.