06-07-2012 04:07 AM
In our organization we are using Cisco ASA 5540 (ISO version 8.4(3)12) for allowing IPSec VPN access to employees and vendor over internet. Employees are authenticated against Active Directory (via ACS) and vendors with locally created accounts on the ACS. The user groups in ACS are mapping with ADS groups for VPN access.
Following are our observations and issue:
1. General user can login to administrator Tunnel-group and administrator can login to general user profile.
2. Also, vendor can login to employee profiles (administrators and general user).
3. User group is not restricted to VPN Tunnel-groups.
06-07-2012 05:30 AM
You can configure ACS to assign users to a specific group-policy.
Here is the sample configuration for your reference:
Hope that helps.
06-10-2012 11:29 PM
I have cheked the configuration and is perfectly fine,still i am facing the above issue...
Having users in multiple group policy have anything to do with this?
And groups created locally in ACS are able to connect through any profile...
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide