I am trying to what seemes to be an simple issue, but !!!
group lock works with attribute 25, but if a user is sent for example to the default group on the ACS or any group where option 25 is not configured ( or configured to some value not avalable on the ASA ) the group lock policy is not enforced, I.E. the users gets in fine no matter what VPN group he is in
is that normal behavior ??