GANYMEDE + for the unified management of ASA and VPN auth

Hello, I have ASA 5540 and 4.2 ACS (AD backend), I want authentic unified management and vpn access.

For example, I have two groups in ACS (mapping AD): Admins, VPN access.

I wish that Admins have full access (shell, VPN) and "Access VPN" only vpn, without shell of any kind.

I understand how to do with RADIUS - use 'Service-type' and network access profile, but how to do it with GANYMEDE +?

There is something

I explained to him almost the same scenario in the post of 2008

https://Cisco-support.hosted.Jivesoftware.com/message/853751#853751

To achieve this, you should have even ASA added to GANYMEDE and RADIUS AAA cleint.

Since you want to group admin must have FULL access so don't change anything on this group.

Now vpnaccess Group on ACS must have only access to the VPN, then here you need to implement IP-based NAR

Go into the setup of the Group > ip based NAR

I hope this helps.

Rgds, jousset

Note the useful posts ~

Tags: Cisco Security

Similar Questions

Maybe you are looking for