cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
623
Views
0
Helpful
2
Replies

ASA5520 vpn authentication tie-in with active directory

ksuchewie
Level 1
Level 1

Currently I have my ASA configured to require a active directory login/password to grant remote access. I noticed in my AD tabs, that there is a dial-in tab where you can select allow/deny vpn access.

http://technet.microsoft.com/en-us/library/Bb742382.bug28143-fig3(en-us,TechNet.10).gif

Is there a way to make this work with the ASA so that all AD users aren't allowed vpn access, and so that only selected users are?

2 Replies 2

srue
Level 7
Level 7

if yo'ure using IAS as your radius server, you can configure it so that only members of certain AD security groups are allowed to be authenticated via the vpn.

can you tell us more about how yo'ure authenticating against AD though?

right now I am using kerberos.