12-12-2005 11:51 PM - edited 02-21-2020 02:09 PM
Hi,
Need to know whether is it possible to define an ACL per group/user basis for IPSec client??
Anyone can provide me some sample or URL??
Thanks.
12-13-2005 01:38 PM
Can you redefine your question, what do you want the ACL to do?
12-13-2005 04:16 PM
sorry for the confusion.
everytime when user logs in using cisco vpn client, they are able to connect to all the server/devices. But i need to restrict them only to connect to one or two servers only.
which mean i need an acl per user/group based on the IPSec connection, but i can't find any of these setting in the box.
hope you understand.
12-15-2005 02:51 PM
with pix v6.x, the way is to disable the command "sysopt connection permit-ipsec'.
with this command disabled, the crypto traffic will be verified with the inbound acl. in other words, inbound acl for crypto is required.
e.g.
access-list inbound permit tcp
access-list inbound permit tcp
one thing needs to be noticed is that once the remote user has full access to a server, he/she may hop onto other resources on the lan from that particular server.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide