Yes I read it. I will be doing a lab this afternoon.

 

Firma ITS

 

De: Bruno [mailto:[email protected]] 
Enviado el: Miércoles, 16 de Febrero de 2011 10:39 a.m.
Para: Diego Cambronero
CC: Pieter-Jan Nefkens; [email protected]
Asunto: Re: [OSL | CCIE_Security] SSL Anyconnect Question

 

Did you read the link I sent before? If it is possible, I think you will find 
it there

On Wed, Feb 16, 2011 at 1:44 PM, Diego Cambronero 
<[email protected]> wrote:

Thank you very much. Just did it and it worked perfect. Do you know if it can 
be done from a TACACS server?

 

Firma ITS

 

De: Pieter-Jan Nefkens [mailto:[email protected]] 
Enviado el: Miércoles, 16 de Febrero de 2011 09:16 a.m.
Para: Diego Cambronero
CC: Diego Cambronero; <[email protected]>


Asunto: Re: [OSL | CCIE_Security] SSL Anyconnect Question

 

That is possible, you can group-lock a user via the username attributes

 

Pj

Sent from my iPad


On 16 feb. 2011, at 15:14, "Diego Cambronero" <[email protected]> 
wrote:

Anyone know if it is posible?

 

 

 

Hi everybody,

 

I have a question about SSL VPN. Is it posible to create an Anyconnect for 2 
different groups using local authentication but only permit the username1 to 
Access the group-alias 1?

 

I mean I have 2 different profiles for the anyconnect clients, I am 
authenticating them locally and I do not want a user with Access to both groups 
only one. 

 

Is there any way how this can be achived by modifying the username attributes. 

 

 

 

I’m doing this in an ASA.

 

 

 

<image001.jpg>

 

_______________________________________________
For more information regarding industry leading CCIE Lab training, please visit 
www.ipexpert.com


_______________________________________________
For more information regarding industry leading CCIE Lab training, please visit 
www.ipexpert.com




-- 
Bruno Fagioli (by Jaunty Jackalope)
Cisco Security Professional

<<image001.jpg>>

_______________________________________________
For more information regarding industry leading CCIE Lab training, please visit 
www.ipexpert.com

Reply via email to