Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Community Member

Specify IP address to a VPN Vlient

Hi,

I am configuring a PIX firewall as VPN server... I am using IOS

6.3(1). Some of my users will use PPTP but some them will use L2PT

over IPSec. Now I am assigning IP addresses from the PIX.

Now I want to assign user Specific IP address. For example

user1----->192.168.1.10

user2----->192.168.1.11

user3----->192.168.1.12

How can I do it?? I don't want user to assign his own ip address..I want to assign it from my pix..

~M$

2 REPLIES
Community Member

Re: Specify IP address to a VPN Vlient

i am not sure if you can assign a specific user a specific IP using the Pix as you can on the Concentrator, but you could create 2 groups (one for PPTP and one for L2TP/IPSec) and have the groups reference 2 different local address pools. at least that have differentiate them and have separate addresses

ip local-pool L2TP-USERS 10.1.5.10-10.1.5.20

ip local-pool PPTP-USERS 10.1.5.21-10.1.5.30

vpdn group L2TP-VPN client configuration address local L2TP-USERS

vpdn group L2TP-VPN client accept dialin l2tp

vpdn group PPTP-VPN client configuration address local PPTP-USERS

vpdn group PPTP-VPN client accept dialin pptp

unless a user from the L2TP group has the initiative to configure a PPTP connection on their own, you should not have a problem.

http://www.geocities.com/dgarnett2002/pptp-pix-xpclient.pdf

Community Member

Re: Specify IP address to a VPN Vlient

I know this can be done with a radius server. Look into the documentation on using a PIX with radius

438
Views
0
Helpful
2
Replies
CreatePlease to create content