03-16-2004 03:46 PM - edited 02-21-2020 01:04 PM
I have a PIX 515 and I am supporting many users with the VPN Client v4.0.2. I have many different vpngroups configured for various reasons. I would like to utilize AAA for some of the groups but not others. Is this possible?
03-18-2004 06:14 AM
Yes this is possible. There are several methods of Radius/Tacacs. I use a Cisco ACS server and define my groups in the ACS server with the same as the vpn gorups. Those users on our win2k network are passed from the ACS server to windows Active Directory fjor their authentication. Those users you don't want leave as local users. My suggestion would be to set up one point of administration and that would be the ACS server. There you can define and manage all users both corporate and vendor/remote access.
04-14-2004 06:42 AM
Did you get this working? I'm trying to do exactly the same, perform XAUTH for some groups/users but not others.
Thanks
04-14-2004 11:04 AM
Yes it is working, however I send everyone desiring VPN Access through the Cisco ACS server and define access resttrictions on the network using Network Access Restriction (NAR) groups defined on the ACS server.
04-15-2004 11:58 PM
So all the VPN Clients still have to pass the XAUTH stage, but you're restricting access using downloadable ACL's.
04-16-2004 01:54 AM
No that is not correct. I simply build the vpn groups based on the acs groups and allow access to devices based on ACS. The people that belong to our enterprise are passed from ACS to Windows ADS with no problem.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide