08-28-2021 02:43 PM
Hi All,
My F.W Device type: ASA 5516
ASA version: 9.12
ASDM Version:7.13
Already I created Many connection profiles to connect by AnyConnect from any External IP,
now I want to create another new Connection Profile and specific for him to connect just from 1 Specific External source IP ,
if that possible or there's any solution?
Thanks in Advance
Solved! Go to Solution.
08-28-2021 09:55 PM
You can use hostscan with a dynamic access policy to check attributes on an endpoint as a condition of allowing remote access VPN. Note using hostscan requires AnyConnect Apex licensing. However, endpoint IP address is not among the attributes you can add. You can use MAC address if that helps. If you have Cisco ISE, you could build an Authorization policy there checking for the endpoint IP address.
https://packetswitch.co.uk/cisco-asa-dap/
08-28-2021 09:55 PM
You can use hostscan with a dynamic access policy to check attributes on an endpoint as a condition of allowing remote access VPN. Note using hostscan requires AnyConnect Apex licensing. However, endpoint IP address is not among the attributes you can add. You can use MAC address if that helps. If you have Cisco ISE, you could build an Authorization policy there checking for the endpoint IP address.
https://packetswitch.co.uk/cisco-asa-dap/
08-29-2021 05:40 AM
Thanks Marvin for your fast response , really appreciated
08-29-2021 07:45 AM
I want to create another new Connection Profile and specific for him to connect just from 1 Specific External source IP ,
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide