Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

Access control on VPN

I have setup VPN client 1.1 connecting to PIX-525 with extended authentication by Cisco ACS 3.0 (TACACS+).

My customer want to have access control by user group for some of the server.

Could I assign IP address by TACACS+ and then filter it by ACL?

Or there is another way to achive that?

1 REPLY
Community Member

Re: Access control on VPN

1st. Turn off Sysopt Permit-IPsec

2nd. Change your Client to the VPN 3000 3.5

3rd. Create Groups using different IP pools

4th. Create Conduits/Access-list to allow/deny access based on IP Pool.

At least that is how I would do it.

91
Views
0
Helpful
1
Replies
CreatePlease to create content