Are you trying to authenticate protocol nt? You could add LDAP authorization with an attribute map for group to local policy matching. If you want more details on that config, let me know. Then again, maybe I missed the question.
Sent from handheld On Jul 8, 2011, at 5:27 PM, Jeff Kell <[email protected]> wrote: > Yes, another PIX migration question ('tis the season...). > > Our legacy VPN has several groups / profiles for different access types. I > have been > able to move these to the ASA successfully (users have VPN client, and get a > matching > profile .pcf for their respective access). > > The legacy used TACACS+ authentication, but I have some vanilla access > profiles setup > now using AD authentication to reduce the overhead in setting up new users > with basic needs. > > To take this to the next level, I enabled "L2TP with IPsec" access on one of > them and > gave it a shot from Win7, taking a best guess at the L2TP setup. > > However, there appears to be no way to convey a "group" to an L2TP connection. > > Is there a reasonably transparent way to accomplish this from the Windows > side? > > Jeff > _______________________________________________ > cisco-nsp mailing list [email protected] > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ _______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
