cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
472
Views
0
Helpful
6
Replies

Access control on VPN

saluko
Level 1
Level 1

Hi,

We currently have remote access vpn in place and working fine. What I now what to do is to restrict access for a particular external client to a single host within our network, while still allowing full access to everyone else. Is this achieveable?? The particular client is using Win2000 pro.

Thanks

6 Replies 6

k.poplitz
Level 3
Level 3

You’ll have to use AAA (XAUTH) to authorize what that user can and cannot access. Cisco Secure ACS is a good AAA server.

pdentico
Level 1
Level 1

As another alternative on a pix you can setup multiple ip pools and assign them to different "vpngroups". Then you can create access-lists based on the ip pools.

Hope this helps.

If you setup multiple ip pools, would you need to add them both to the isakmp client ip config??

No the 3.x client does not need that command. It gets the ip address from the vpngroup command.

Thank you very much for your help guys:-)

HEATH FREEL
Level 1
Level 1

You can also use the same IP pool but assign a different Split Tunnel to the group.