AAA static IP address for RA VPN Client

Unanswered Question
Dec 12th, 2009
User Badges:


my vpn group and VPN POOL  is locally created in Cisco VPN router but users are authenticated through ACS, AAA server via TACACS. Now I want to assign the static ip address to VPN Client. Everything is fine but due to the application problem I want to give them the static Ip address from the VPN Pool. I have greated one pool in AAA server and also configure the client in AAA to get the static ip address but unable to do this. Please help me out how to do this.

My router is configured for TACACS+. I have checked the user configuration in AAA server to get the static ip address but it is not working. Please help me out how to do this. I cant change Router to Radius but this is my main router which is configured for 160 sites through ISDN and these sites also configured for TACACS+.

crypto isakmp policy 10
encr 3des
authentication pre-share
group 2 
crypto isakmp client configuration group Aviation-VPN
key egntosc
pool aviation-pool
acl avi-tunnel
crypto isakmp profile vpnclient
   match identity group Aviation-VPN
   client authentication list default
   isakmp authorization list Aviation-authorization
   client configuration address respond
crypto ipsec transform-set aviset esp-3des esp-sha-hmac
crypto dynamic-map avi 10
set transform-set aviset
set isakmp-profile vpnclient

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
cmarva Wed, 12/23/2009 - 07:33
User Badges:

Since you're using ACS, I believe the way to do this is to

go into ACS, and select the username of the user that you want

to get the static IP. Under that user's setup, there is an option to

always assign the same IP. Just select that and enter the IP you

want them to get. - chris

Federico Coto F... Sat, 06/19/2010 - 11:13
User Badges:
  • Green, 3000 points or more

The ACS can assign a static IP to the RA VPN client.

Do you have the ''IP Pools'' and ''Per-user TACACS+/RADIUS Atributes'' selected under Interface Configuration | Advanced Options from the ACS?



This Discussion