cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1002
Views
4
Helpful
16
Replies

Can you have different SSL WebVPN's on Cisco ASA 5520?

jamesgonzo
Level 1
Level 1

Hi,

What I mean is I want to give a company access to an internal website and another company access to a different website, they can only access one website (bookmark)?

Thanks

16 Replies 16

andrew.prince
Level 10
Level 10

In the docs its loose.... me personally, the only thing I have got working in a lab is the drop down group option with all the other bells and whistles, which works quite well. I have not been able to get back to this one in ages, no time soon either, but the below link may point you in the right direction.....unless someone else has cracked this:-

http://www.cisco.com/en/US/customer/products/ps6120/prod_configuration_examples_list.html

HTH>

Farrukh Haroon
VIP Alumni
VIP Alumni

The following link will guide you to a step-by-step process to achieve this:

http://www.cisco.com/en/US/customer/products/ps6120/products_configuration_example09186a00808bd83d.shtml

Another alternate is the group-url command, but I don't think it supports the following:

asa-ip/sales

asa-ip/marketing

But it does support

https://sales-ssl-vpn

https://marketing-ssl-vpn

Regards

Farrukh

Do you mean I should just create an Alias for each SSL VPN profile with only the Bookmarks each company needs then email them the URL?

Can I only accept connections from their external facing IP as well?

Thanks

If you have just one IP address, go for the tunnel drop-down menu (as seen on the CCO Doc). That would be a more practical option.

Regards

Farrukh

Interesting,

1.) How can I use a different Ip that the "outside" IP?

2.) I'm strugglinh to find this CCO doc for the tunnel drop-down menu what is this?

Thanks

1) I'm not aware of anyway, maybe NAT on a upstream device (but I doubt it)

2) DId you not chek this link: http://www.cisco.com/en/US/customer/products/ps6120/products_configuration_example09186a00808bd83d.shtml

Regards

Farrukh

Strange thing is I don't have access to that site.

All you have to do is login using your regular Cisco Account or try this link:

http://www.cisco.com/application/pdf/paws/98580/enable-group-dropdown.pdf

Regards

Farrukh

Great, that has worked,

1.) I suppose I should not call the group name something like "My Company" as anyone can get to the page on the internet, unless I can restrict this site only to their external IP?

2.) It seems I can get to the site either by:

https://asa-ip/ (with drop down)

https://asa-ip/alias

Is this normal or more secure to somehow only use https://asa-ip/alias, but I'm not sure I can turn off the https://asa-ip/?

3.) I have created another alias/bookmarks for another company (have 2 profiles now) thing is they can logon to each others alias, how do I stop this? I want company A to access group A and company B access group B only.

Thanks

1) If your SSL VPN is on the internet, you need to control access to the ASA Public IP using an ACL (lets say on your upstream router etc.)

2) I guess this is normal, I doubt you can turn of the ASA-ip thing. That will destroy the purpose of drop-down anyway.

3) You can use 'group-lock' to lock users to particular groups (both locally and via AAA AFAIK).

Regards

Farrukh

1.) Can the ASA do this? The 'outside' interface connects to our ISP router (we don't have access), can a ACL be created only to allow external SSL connects from their public IP's.

2.) Group-lock sounds like just what I need, is this on ASA's ASDM? I'm using IAS for Radius.

2.1) I wanted to use a local user account for this (priv 0) but I found out that I could get into the CLI with the account! Can I stop this?

1) By default I don't think, you might have to turn of sysopt. Not 100% sure about this.

2) Yes it should be available both on the CLI/ASDM. It can also be pushed via AAA.

2.1) priv 0 can get into the CLI but what can he do? Also you can restrict management traffic by using ASA ACL (ssh/telnet commands)

Regards

Farrukh

Hi,

I suppose it can be open to the world asong as it's secure. I just need to work out if "company A" logs on they get "bookmarks A" and if "company B" logs on they get "bookmarks B", plus company A can't access company B bookmarks.

You mention group-lock, I will use a local username for each company now, but I'm really struggling to find this group-lock function on the ASDM.

i use dynamic access policies to achieve this without using aliases. im using cisco acs, and apply in the radius class field (number 25) with a setting, i use OU=groupPolicy, where groupPolicy is the name of a specific group policy i have defined in the config. then i go to DAP and check for this RADIUS setting (not cisco setting). after it catches it, i can define bookmarks, acl's banners, etc for everyone with this OU setting. you must check for the entire OU=groupPolicy phrase, or whatever you throw in there. it could be something like goPackers or something arbitrary like that. i use group policy so i can use the same DAP for ipsec vpns.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: