cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
432
Views
0
Helpful
5
Replies

local vpn accounts

esossamon
Level 1
Level 1

Is their a way on the ASA running 8.0 code to set a local account to expire on a certain date?

5 Replies 5

JORGE RODRIGUEZ
Level 10
Level 10

I do not believe there is such feature on any ASA code as to time based local account expiration, you would have to use 3rd party like Cisco Secure Access Control Server (ACS) where you can have that feature / manage all accounts expiration dates etc..

have a look here

http://www.cisco.com/en/US/products/sw/secursw/ps2086/index.html

Rgds

Jorge

Jorge Rodriguez

Hi,

I am running an ASA with version 7.0 and I have a user account that is set to expire. Example code:

1. First create a new Time Range, eg:

time-range {time range name}

absolute end 18:00 29 November 2008

2. Assign the Time range to the VPN user, eg:

username {vpn username} attributes

vpn-access-hours value {time range name (as above)}

This works for me! Hope it helps!

Phillip, your post is upsolutely correct applicable to RA vpn, perhaps if original poster could specify whether he meant RA vpn client local account access expiration date or local account expiration as a whole meaning no access to asa from the inside for management as I have understood. If RA vpn your answer is correct.

Rgds

Jorge

Jorge Rodriguez

yes I did mean RA vpn client local accounts. I've tested this and it works great. Thanks Phillip!!!

glad to have helped!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: