cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1805
Views
0
Helpful
4
Replies

How to restrict a VPN user with a specific anyconnect profile?

suresh.mogalapu
Level 1
Level 1

we have multiple VPN profiles - for a Specific profile,  users should not get option to select any other profile. as well as we need to use same 2FA server for all Profile users. can this be achieved ?

 

ASA5516 - 9.8(4)22  

1 Accepted Solution

Accepted Solutions
4 Replies 4

Hi,

There are many ways to do this. You can use group-alias with group-lock
feature to make sure that certain users can use certain profiles only. They
won't be able to login with other profiles (even with valid creds). But you
need to make sure that you have a unique parameter for the same group of
users such as memberOf

Another way of doing this using certificate-maps if you use cert
authentication to match parameters from the client cert and automatically
assign the designated profile. This way users don't get the option to
select a profile.

Sharing the same 2FA will not have an impact.

Here are some examples of group-lock with local auth but the same can be
applied to AD login with ldap-attribute map.

**** please remember to rate useful posts

Thank you for your reply Mohammed - you haven't posted any examples.

 

 

Sorry , forgot to paste URL.

https://www.cisco.com/c/en/us/support/docs/security/ios-easy-vpn/117634-configure-asa-00.html

***** please remember to rate useful posts

Peter Koltl
Level 7
Level 7

Do you use local authentication or RADIUS server? ISE?