cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
368
Views
0
Helpful
2
Replies

How to assign an ACL to a VPN Client using Cisco 3005 and Radius

karel.stadler
Level 1
Level 1

On the Cisco 3005 you can assign a locally defined filter to an local user. Since i'm using Radius for authentication and authorization, i would like to assign the filter from there.

Unfortunately i couldn't find a corresponding CVPN-3000 attribute for this. Is this really not supported or did we miss something ?

best rgds

Karel

2 Replies 2

hadbou
Level 5
Level 5

On the cisco VPN concentrators, using the Radius server you can restrict only URL's and you cannot administer the traffic thats flowing through.

Okay, i found the solution. It can be done with the Cisco-AVPair attribute oder the Filter-Id. If you use Filter-Id you have to define the ACL on the Concentrator. If you use Cisco-AVPair "ip:inacl#1=permit ...." you can assign the ACL from the Radius, which scales a bit more if you have several concentrators. Thanks anyway

best rgds

Karel