Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

ASA SSLVPN configuration


My client requires SSL VPN to be configured at their site. I had followed the 'SSL VPN Client (SVC) on ASA Using ASDM Configuration Example' from the cisco website. The client has some more requests based on their setup. They require authentication through their ACS server. This was implemented and worked well. Now they have a new requirement. They would like to grant SSLVPN to all their users, but apply ACL filters based on groups. For example, 'accounting' people should be assigned specific IP based on their username. 'Sales' people should be assigned specific IP based on their username. On the ASA we would put ACL to restrict accounting people from accessing sales and vice versa.

I need to create groups (accounting and sales) on my ACS, and have IP address assignment based on the username. Also, I need to know what further configurations I need to perform on the ASA.

Please guide me to perform such a process. Please help in this case.

Also, please advice if there is any other better method or technique to meet the clients requirement.

My device information is as follows:

ASA 5510. ASDM 7.1(2)

ACS 3.3


Mohammed Abdulla.


Re: ASA SSLVPN configuration


You will need to upgrade to ACS 4.0 to do this. It provides all the radius hooks needed to do the kind of authorization that you are talking about in a way that is consistent with ASA group policy.

HTH pls rate!