cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
766
Views
10
Helpful
3
Replies

how I can Specific just 1 External IP to to connect by AnyConnect

W-ALI
Level 1
Level 1

Hi All,
My F.W Device type: ASA 5516

ASA version: 9.12

ASDM Version:7.13

 

Already I created Many connection profiles to connect by AnyConnect from any External IP,

now I want to create another new Connection Profile and specific for him to connect just from 1 Specific External source IP ,

 

if that possible or there's any solution?

 

Thanks in Advance 

 

 

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

You can use hostscan with a dynamic access policy to check attributes on an endpoint as a condition of allowing remote access VPN. Note using hostscan requires AnyConnect Apex licensing. However, endpoint IP address is not among the attributes you can add. You can use MAC address if that helps. If you have Cisco ISE, you could build an Authorization policy there checking for the endpoint IP address.

https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/200191-AnyConnect-Licensing-Frequently-Asked-Qu.html#anc16

https://packetswitch.co.uk/cisco-asa-dap/

 

 

View solution in original post

3 Replies 3

Marvin Rhoads
Hall of Fame
Hall of Fame

You can use hostscan with a dynamic access policy to check attributes on an endpoint as a condition of allowing remote access VPN. Note using hostscan requires AnyConnect Apex licensing. However, endpoint IP address is not among the attributes you can add. You can use MAC address if that helps. If you have Cisco ISE, you could build an Authorization policy there checking for the endpoint IP address.

https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/200191-AnyConnect-Licensing-Frequently-Asked-Qu.html#anc16

https://packetswitch.co.uk/cisco-asa-dap/

 

 

Thanks Marvin for your fast response , really appreciated 

 I want to create another new Connection Profile and specific for him to connect just from 1 Specific External source IP ,