01-26-2013 06:04 AM - edited 02-21-2020 06:39 PM
Hi,
I have Cisco ASA 5520 / ASA Ver: 8.0(4) / ASDM Ver: 6.1(3).
I have configured Remote Access VPN and everything seems to be fine. Like i have created Extended ACL and allowed for singe host with particlar port to be allowed.
After login with the Anyconnect client, i am restricted to access the single host configured, but not based on ports. i.e. i do not want user to RDP the server allowed, but only access the application based on the port that is allowed. But somehow it is not working.
Can someone guide, how can i allow user to access a server with defined port only and not any other service/port access for the server.
Thanks in advance.
K
01-26-2013 01:00 PM
Hi,
I guess there are several ways to do this depending on your setup
I guess at this point you have configured Split-Tunneling or?
You could try for example
OPTION 1
OPTION 2
The above are the options you could use with the ASA alone. There are other options too. If you have the username/password configured on an AAA server you might be able to build the rules there. Sadly I am not too familiar with that kind of setup.
- Jouni
01-26-2013 01:44 PM
Hi,
vpn-filter access-list under group-policy would satisfy your requirment.
Mashal
01-27-2013 12:59 AM
Hello Jouni,
Thanks for reply.
I have done the changes as per option2. After connection, when i see the details of the user session in the asa, i can see that the acl is applied as per the selection, but on the user's computer i am not able to access anything.
In the asa realtime logviewer, there are errors like below for the vpnuser
"Authorization denied (acl=SSPVPN-ACL) for user '123456' from 192.168.25.10/137 to 192.168.25.255/137 on interface outside using UDP"
Can you please guide what could be the issue ?
Thanks again.
K
01-27-2013 02:57 AM
Hi Jouni,
I tried the Option1 and it is working fine as required.
Is there anyway to allow access only on particular computer and not from multiple computers ? Can one user login with more than single session ?
Thanks,
K
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide