I have been trying to configure the anyconnect client to use a drop down menu to pick the group policy that they want to use. The problem is that I get the drop down menu to pick the two different groups that I setup on the ASA using the group-alias, however, they do not take on the attributes of the group and it shows up in the logs as using the same group policy even when I pick a different one. I setup individual usernames attached to the two different group policies and when I do that, they take on the correct attributes, so it looks to me that I have a radius attribute I have to change in ACS. Does anyone know which attribute I have to change to get it to work? Thank you very much for all of your help.
I can get it to work if I set the "Class attribute" in radius, but I would still like the users to choose which profile they want, instead of being lock into one. The problem is that some users need LAN access where they are at. So, we created a full tunnel and a split-tunnel group policy. I want them to be able to choose either one of these policies. If there is anyway that I can do this without seperating users into separate groups within ACS and using the "Class Attribute" that would be great, because there are around 800 users for the split tunnel and a few thousand that need the full tunnel, so it would be a nightmare trying to track down all the users that need the LAN access. Do you happen to know if there is an attribute that will allow me this flexibility? Thanks.
DocumentationCode download linksGoalRequirementLimitationsSupported ISR
and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and
UCS-E Blades:Step by Step ConfigurationConfigure one of the connectivity
options to access the Cisco IMC from the n...
Firepower Threat Defense (NGFWv) on UCS E-series - Transparent Mode in
HA DocumentationCode download linksGoalRequirementLimitationsSupported
ISR and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and
UCS-E Blades:Step by Step ConfigurationCo...
Question I am currently unable to specify "crypto keyring" command when
configuring VPN connection on my cisco 2901 router. The following
licenses have been activated on my router :