Hi everybody,

 

I have a question about SSL VPN. Is it posible to create an Anyconnect for 2
different groups using local authentication but only permit the username1 to
Access the group-alias 1?

 

I mean I have 2 different profiles for the anyconnect clients, I am
authenticating them locally and I do not want a user with Access to both
groups only one. 

 

Is there any way how this can be achived by modifying the username
attributes.

 

 

 

I’m doing this in an ASA.

 

 

 

Firma ITS

 

De: [email protected]
[mailto:[email protected]] En nombre de Tyson Scott
Enviado el: Lunes, 14 de Febrero de 2011 11:08 a.m.
Para: 'Pemasiri Devanarayana'; [email protected]
Asunto: Re: [OSL | CCIE_Security] Yusuf's Flash Card - OEQ

 

1. FPM would be difficult to use.  The answer is the better option.

2. The key is " authenticate and authorize remote users with

per-user level acess control before"

 

 

 

From: [email protected]
[mailto:[email protected]] On Behalf Of Pemasiri
Devanarayana
Sent: Monday, February 14, 2011 8:14 AM
To: [email protected]
Subject: [OSL | CCIE_Security] Yusuf's Flash Card - OEQ

 

Hi, 

 

I just need some one's feedback on below two questions;

 

1) which cisco IOS feacture can prevent bad http packet from tunneling
malicious traffic

- answer was ZFW

why cant we considered FPM..?

 

) which IOS security technology can be used to authenticate and authorize
remote users with

per-user level acess control before permiting access to local/network
services or hosts/servers

 -authentication proxy

 -why cant considerd role-base CLI

 

 

<<image001.jpg>>

_______________________________________________
For more information regarding industry leading CCIE Lab training, please visit 
www.ipexpert.com

Reply via email to