03-14-2008 11:13 AM - edited 03-09-2019 08:18 PM
Good afternoon,
We need to provide a vendor access to a server located on the inside of the network (MS SQL Server). I have a couple questions along these lines:
1. We currently allow vpn access to IT staff on our ASA 5510 (which is privately managed). We currently have one authentication group for our IT staff. Is there a way to have two authentication groups? We're using a MS radius server to authenticate before access is approved.
2. Once the vendor is connected, what would be the best way to restrict them to only the one box?
Our concern is that they would be able to launch telnet, file share, etc...I realize this may be best handled by MS group, but was thinking about access lists..
Any thoughts would be appreciated.
03-14-2008 11:41 AM
The easiest way would be to create a second remote access tunnel group. Create a new ip pool for that group and apply it to a new policy for that group. You could then limit the access by being very specific with your nat exemption acl.
03-14-2008 12:13 PM
Thanks for the quick response!
03-14-2008 12:22 PM
Better yet, create a vpn-filter for the new group.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide