Hi again.

Looks like I'm running into a lot of issues on this lab :)

Task 4.4 asks that we only allow the user to be authorized against a group
if they are assigned to the group. This must be restricted locally on ASA2.

I've configured group-lock on the group-policy, but for some reason it's not
working as expected because the user created in the previous task named
remote-...@r5-ezvpn can login. Any idea what I'm missing? I think I've
matched the solution guide answer...

I could configure the Tunnel-Group-Lock radius attribute on the ACS, but I
think that breaks the requirements of the task and it is not mentioned in
the solutions?

group-policy EZVPN_GP internal
group-policy EZVPN_GP attributes
 banner value Welcome to IPexpert
 group-lock value EZVPN
 split-tunnel-policy tunnelspecified
 split-tunnel-network-list value SPLIT_TUNNEL01
 default-domain value ipexpert.com
 user-authentication enable

ASA2# show run tunnel-g
tunnel-group EZVPN type remote-access
tunnel-group EZVPN general-attributes
 address-pool EZVPN_POOL01
 authentication-server-group RADIUS01
 default-group-policy EZVPN_GP
 authorization-required
tunnel-group EZVPN ipsec-attributes
 pre-shared-key *
ASA2#
_______________________________________________
For more information regarding industry leading CCIE Lab training, please visit 
www.ipexpert.com

Reply via email to