cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1281
Views
0
Helpful
2
Replies

Restrict local VPN users to a specific tunnel group in Firepower FTD

Chess Norris
Level 4
Level 4

Hi,

A customer have configured his FTD 7.0 with local users and wants to restricts a user to a specific tunnel group.

He dont have the possiblility to set up an ISE or NPS server right now, so he need a solution with local users.

In the ASA we could use the group-lock function for this, but I cannot find any option for this in either FDM or in FMC.

Is it possible to use FlexConfig to configure this or is the group-lock function not supported at all in FTD?

 

Thanks

/Chess

 

 

 

2 Replies 2

Hi,

In ASA this was possible using group-lock feature under username
attributes. See below

https://www.cisco.com/c/en/us/support/docs/security/ios-easy-vpn/117634-configure-asa-00.html

Up to version 7.0 on FTD, its not possible using local accounts out of the
box. But use the example above and try it with flexconfig to see if it
works.

***** please remember to rate useful posts

Chess Norris
Level 4
Level 4

I am getting some errors when trying FlexConfig (See picture). I guess it's not supported then or maybe  I do something wrong? 

 

FlexConfig.JPG

 

Thanks

/Chess

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: