12-18-2012 05:03 AM
Hello Community.
I like to restrict VPN access to our ASA only from a specified IP Adresss. The problem is the customer can install the VPN client on every machine, but i want to restrict that to one machine (one IP Address).
Any ideas. Cheers Patrick
Solved! Go to Solution.
12-18-2012 05:19 AM
If you are using ACS for vpn user authentication, then you can do this with calling-station-id. You have to add the remote ip address on calling-station-id attributes of ACS.
With Regards,
Safwan
Don't forget to rate helpful posts
12-19-2012 02:49 PM
Another solution is to have a router before the ASA and apply the ACL on wan interface of the router.
ISP-->Router--->ASA--->LAN
With Regards,
Safwan
Don't forget to rate helpful posts
12-18-2012 05:19 AM
If you are using ACS for vpn user authentication, then you can do this with calling-station-id. You have to add the remote ip address on calling-station-id attributes of ACS.
With Regards,
Safwan
Don't forget to rate helpful posts
12-19-2012 07:51 AM
Thanks for the answer. Isn't there a cheaper solution, the price for ACS is around $7000.
12-19-2012 02:49 PM
Another solution is to have a router before the ASA and apply the ACL on wan interface of the router.
ISP-->Router--->ASA--->LAN
With Regards,
Safwan
Don't forget to rate helpful posts
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide