07-25-2008 07:46 AM - edited 02-21-2020 02:56 AM
Hi,
What I mean is I want to give a company access to an internal website and another company access to a different website, they can only access one website (bookmark)?
Thanks
07-25-2008 03:18 PM
In the docs its loose.... me personally, the only thing I have got working in a lab is the drop down group option with all the other bells and whistles, which works quite well. I have not been able to get back to this one in ages, no time soon either, but the below link may point you in the right direction.....unless someone else has cracked this:-
http://www.cisco.com/en/US/customer/products/ps6120/prod_configuration_examples_list.html
HTH>
07-26-2008 02:21 AM
The following link will guide you to a step-by-step process to achieve this:
Another alternate is the group-url command, but I don't think it supports the following:
asa-ip/sales
asa-ip/marketing
But it does support
Regards
Farrukh
07-27-2008 12:04 PM
Do you mean I should just create an Alias for each SSL VPN profile with only the Bookmarks each company needs then email them the URL?
Can I only accept connections from their external facing IP as well?
Thanks
07-27-2008 06:09 PM
If you have just one IP address, go for the tunnel drop-down menu (as seen on the CCO Doc). That would be a more practical option.
Regards
Farrukh
07-27-2008 11:26 PM
Interesting,
1.) How can I use a different Ip that the "outside" IP?
2.) I'm strugglinh to find this CCO doc for the tunnel drop-down menu what is this?
Thanks
07-27-2008 11:54 PM
1) I'm not aware of anyway, maybe NAT on a upstream device (but I doubt it)
2) DId you not chek this link: http://www.cisco.com/en/US/customer/products/ps6120/products_configuration_example09186a00808bd83d.shtml
Regards
Farrukh
07-28-2008 12:18 AM
Strange thing is I don't have access to that site.
07-28-2008 12:37 AM
All you have to do is login using your regular Cisco Account or try this link:
http://www.cisco.com/application/pdf/paws/98580/enable-group-dropdown.pdf
Regards
Farrukh
07-28-2008 02:18 AM
Great, that has worked,
1.) I suppose I should not call the group name something like "My Company" as anyone can get to the page on the internet, unless I can restrict this site only to their external IP?
2.) It seems I can get to the site either by:
https://asa-ip/ (with drop down)
Is this normal or more secure to somehow only use https://asa-ip/alias, but I'm not sure I can turn off the https://asa-ip/?
3.) I have created another alias/bookmarks for another company (have 2 profiles now) thing is they can logon to each others alias, how do I stop this? I want company A to access group A and company B access group B only.
Thanks
07-28-2008 04:11 AM
1) If your SSL VPN is on the internet, you need to control access to the ASA Public IP using an ACL (lets say on your upstream router etc.)
2) I guess this is normal, I doubt you can turn of the ASA-ip thing. That will destroy the purpose of drop-down anyway.
3) You can use 'group-lock' to lock users to particular groups (both locally and via AAA AFAIK).
Regards
Farrukh
07-28-2008 04:31 AM
1.) Can the ASA do this? The 'outside' interface connects to our ISP router (we don't have access), can a ACL be created only to allow external SSL connects from their public IP's.
2.) Group-lock sounds like just what I need, is this on ASA's ASDM? I'm using IAS for Radius.
2.1) I wanted to use a local user account for this (priv 0) but I found out that I could get into the CLI with the account! Can I stop this?
07-28-2008 05:11 AM
1) By default I don't think, you might have to turn of sysopt. Not 100% sure about this.
2) Yes it should be available both on the CLI/ASDM. It can also be pushed via AAA.
2.1) priv 0 can get into the CLI but what can he do? Also you can restrict management traffic by using ASA ACL (ssh/telnet commands)
Regards
Farrukh
07-28-2008 05:29 AM
Hi,
I suppose it can be open to the world asong as it's secure. I just need to work out if "company A" logs on they get "bookmarks A" and if "company B" logs on they get "bookmarks B", plus company A can't access company B bookmarks.
You mention group-lock, I will use a local username for each company now, but I'm really struggling to find this group-lock function on the ASDM.
07-28-2008 05:52 AM
i use dynamic access policies to achieve this without using aliases. im using cisco acs, and apply in the radius class field (number 25) with a setting, i use OU=groupPolicy, where groupPolicy is the name of a specific group policy i have defined in the config. then i go to DAP and check for this RADIUS setting (not cisco setting). after it catches it, i can define bookmarks, acl's banners, etc for everyone with this OU setting. you must check for the entire OU=groupPolicy phrase, or whatever you throw in there. it could be something like goPackers or something arbitrary like that. i use group policy so i can use the same DAP for ipsec vpns.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: