My client requires SSL VPN to be configured at their site. I had followed the 'SSL VPN Client (SVC) on ASA Using ASDM Configuration Example' from the cisco website. The client has some more requests based on their setup. They require authentication through their ACS server. This was implemented and worked well. Now they have a new requirement. They would like to grant SSLVPN to all their users, but apply ACL filters based on groups. For example, 'accounting' people should be assigned specific IP based on their username. 'Sales' people should be assigned specific IP based on their username. On the ASA we would put ACL to restrict accounting people from accessing sales and vice versa.
I need to create groups (accounting and sales) on my ACS, and have IP address assignment based on the username. Also, I need to know what further configurations I need to perform on the ASA.
Please guide me to perform such a process. Please help in this case.
Also, please advice if there is any other better method or technique to meet the clients requirement.
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...