Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

help to configure ACS3.3 and ASA5520 for VPN clients profiles

Hello

I have many user with need to access the network, I have a ASA5520 with version 4.0 and I configure different profiles by different users, exist many tunnel-group's and group-police's in the ASA.

I need know if is posible create the tunnel-group, group-police and other attributes in ACS 3.3. so that the ACS configure the ASA5520 when the user trying authenticating.

excuse my ingles.

2 REPLIES
Silver

Re: help to configure ACS3.3 and ASA5520 for VPN clients profile

In the Network Access Restrictions table, under Per User Defined Network Access Restrictions, select the Define IP-based access restrictions check box.

b. To specify whether the subsequent listing specifies permitted or denied IP addresses, from the Table Defines list, select one of the following:

Permitted Calling/Point of Access Locations

Denied Calling/Point of Access Locations

c. Select or enter the information in the following boxes:

AAA ClientSelect All AAA Clients, or the name of a network device group (NDG), or the name of the individual AAA client, to which to permit or deny access.

PortType the number of the port to which to permit or deny access. You can use the wildcard asterisk (*) to permit or deny access to all ports on the selected AAA client.

AddressType the IP address or addresses to use when performing access restrictions. You can use the wildcard asterisk (*).

Community Member

Re: help to configure ACS3.3 and ASA5520 for VPN clients profile

wong

I need to know if it is possible to be eliminated the configuration of diverse profiles for VPN clients in the ASA5520 (group-policy's and tunnel-group's) and to be passed them to the ACS with the purpose of making the configuration in the ASA less complex.

in case of being possible this, I require to know configure the ASA5520 and the ACS

thanks

135
Views
0
Helpful
2
Replies
CreatePlease to create content