cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
320
Views
0
Helpful
1
Replies

Restrict 4.6 VPN users from being able to connect based on IP

jkerk
Level 1
Level 1

I would like to restrict certain ACS 3.3 groups\VPN Clients to only be able to connect from a specific IP subnet or address range.

Is this possible? How would it be configured?

1 Reply 1

smalkeric
Level 6
Level 6

Which version of VPN concentrator you are using?.Because, I have had the most sucess doing this using

Cisco vendor-specific RADIUS attribute AV-PAIR (26/9/1). Notice this requires 4.0 and later code on the concentrator. This is per the following page

http://www.cisco.com/univercd/cc/td/doc/product/vpn/vpn3000/4_0/admon/dynfilt.htm#wp2006777