VPN for computers in domain only

Hi guys,.

We just bought a Cisco ASA5516, running version 9 x and only supports Anyconnect VPN. Is it possible to configure the anyconnect VPN to support only the computers in the domain and the computers in the domain no should not be able to connect to the VPN?

Any help will be greatly appreciated.

Thank you

Lake

Hi Lakeram,

Yes, you can use the DAP functionality to filter who can and who cannot connect to the VPN... You can use multiple attributes, for example.  Address MAC, antivirus, registry keys, OS, etc.

Check the examples below.

http://www.Cisco.com/c/en/us/support/docs/security/ASA-5500-x-series-next-generation-firewalls/108000-DAP-Deploy-Guide.html

http://www.Cisco.com/c/en/us/TD/docs/security/ASA/asa84/asdm64/configuration_guide/asdm_64_config/vpn_asdm_dap.PDF

http://www.Cisco.com/c/en/us/support/docs/security/ASA-5500-x-series-next-generation-firewalls/115947-DAP-ADV-functions-00.html

It may be useful

-Randy-

Tags: Cisco Security

Similar Questions

  • Configuration remote access VPN (IPSec) using FULL domain name

    Hi friends of Cisco,

    We have the DNS (only the internal IP) within our network, right now that we have configured VPN for remote access using public IP address and connect us with the same public IP address. I need help to use the domain name FULL rather than use public IP.

    Can you please provide the configuration for this.

    Feature: ASA 5520

    Type of configuration: IPSec

    Thank you

    Estel

    Hi Philippe,.

    You can use one of the free Web of DNS dynamic sites and configure ASA to dynamic DNS.

    Reference - http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/basic_ddns.html

    HTH,

    -Dieng

  • Dns resolution for a sub.domain with some ISP DNS external in the management of the DNS (win20008 r2) service?

    Hello

    We have a domain.   www.mydomain.be.

    It is a public domain managed by our office.

    It is also the same for internal network active directory domain mydomain.be

    Of course, we have internal DNS in our active directory.

    the Registrar has created a subdomain.  www.Sub.mydomain.be

    My question is: how to solve (for my network internal only) sub.mydomain.be by the DNS of the ISP.

    --> How to work around the internal our DNS resolution for the sub.mydomain.be ONLY for the 'DNS ISP or registrar "?

    our internal DNS (r2 win20008 in active directory) must continue to resolve all applications except the sub.mydomain.be.

    Create forwarders? or another technique?

    Thank you

    Hassan,

    Hello

    Post your question in the TechNet Server Forums, as your question kindly is beyond the scope of these Forums.

    http://social.technet.Microsoft.com/forums/WindowsServer/en-us/home?category=WindowsServer

    See you soon.

  • do you need additional licenses for a remote domain on a SBS 2008 domain controller

    I have a SBS 2008 domain. We have a remote desktop through a vpn, we would like to set up a domain controller for performance reasons. It was my understanding that SBS authorized licenses for the servers to be added free of charge? Is this true for an additional domain controller?

    Hello

    You can find the Server forums on TechNet support, please create a new post at the following link:

    http://social.technet.Microsoft.com/forums/en/category/WindowsServer/

  • How to install drivers for computers connected to a network?

    Original title: install the printer driver for a network

    I am trying to download the drivers customized laptops, connected to a xerox business center.  My question is what I have to install them directly on laptops, or could I use a centralized machine and just let laptops are access pilots it or do I need to install drivers on each individual computer?

    The central machine is XP, laptops are all machines in W7.

    Hello

    The computer is connected to a domain network?

    You must install individual drivers for computers connected to the Xerox business center.

    If it's on a domain network, I suggest you to contact the TechNet Forums for any other help.

  • What means "Blacklist DNS reverse response searching for known malware domain spheral.ru - Win.Trojan.Glupteba (1:31600)"?

    I have a Cisco ASA5516x w / firepower with an IPS license installed and I'm trying to determine what means this Impact 1 alert:

    Reverse DNS BLACK list response searching for known malware domain spheral.ru - Win.Trojan.Glupteba (1:31600)

    The source looks like it's coming from DNS servers on the internet:

    208.67.220.220

    208.67.222.222

    4.2.2.6

    204.117.214.10

    The destination is our domain controllers that are configured to be our DNS servers. I'm just trying to understand what really means this alert? The classification is "a network Trojan has been detected", but this means that a user attempted to solve an to a site that has been reported as malicious DNS record, or they have malicious software on their PC that is trying to connect to a server command & control out in the wild? To be clear, the penetration of these alerts are outside interface and evacuation is our inside interface. If someone can provide a clear explanation for these alerts, it would be greatly appreciated. Thank you!

    Hello

    This does not necessarily mean that the PC or the DC are infected. This rule is for a reverse DNS lookup.

    With the source and the destination, it could just be a package that is the reverse DNS lookup query response. Now, why this request is sent in the first place is a question and a value of the investigation.

    flow: to_client; content: "|" 07. spheral | 02. ru | 00 | » ; fast_pattern: only;

    Download the capture of packages in the case of the rule, you can check and verify the IP address that is resolved to spheral.ru and then identify what PC initiated the request.

    Sometimes, it could be an AV product or security, try to reverse search DNS for an IP address of the suspect.

    Rate if helps.

    Yogesh

  • Is there really a customer Cisco VPN for Linux? _Really? _

    Hello people,

    I finally after almost a brain aneurysm trying to think too hard I have my Cisco 881 - SEC - K9 router configured properly for a multi-point my Amazon Virtual Private Cloud IPSec VPN tunnel, so that the obstacle is finally spent, and I think that it has been a very important step in my life somehow. I never thought I'd see the day, I actually got my hands on a legitimate Cisco non - stink... uh... I mean, non-linksys router. Now I can't find a "client" VPN for Linux program. I am running a Xen Hypervisor environment on openSUSE Linux because it is the only Linux distribution that fills all my laborious requirements in a Linux server environment. It is also the most mature and sure Linux on this planet, making it the most significant Linux distribution for my research needs.  Using NetworkManager is not really an option for a Linux based server environment and OpenVPN is just too complicated to understand for my little tiny head.  I've heard of some mysterious "easy VPN", but after that hours of digging online there is no information on this subject, even the Cisco download link leads to a Page not found error.  I see a Linux VPN API for the AnyConnect program, but is it a real VPN client, or just an API?  It seems to want my money to download it, but I have no money nor I really know what it is because it's all closed, the secret-like source and I can not even find a simple README file on him explaining what it is exactly.  I'm just a developer of off-work software attempts to connect to my home for personal use router and I can not really afford to more than $ 1 million for a single program I will only need to download once in my life that should have been included with the router in the first place of the fork. I have that more volunteer will probably not yet able to understand how to use the program when even because I don't know anything about VPN connections, that's why I bought this router so I can try to figure it all out as part of the open source nonprofit, research, I am currently conducting.  Is there some sort of period of evaluation or trial for personal use? Which would be really good if I could at least know if I will be able to understand or not.  I hate throwing money when it is in such a shortage these days. Is there really no alternative to a Cisco router.  It is an absolute necessity for the things I'm trying to accomplish, so try to settle for something else and past with my life isn't really an option. No, it's something that I just need to raise its head on and finish.

    I may be a little too crazy in me for my own good, but I don't see why it should take so much money just to learn to do something for personal use, it is not really a skill that I would never use otherwise.  Wouldn't be great if Cisco did their VPN client open-source and free for the public to use and modify, improve, learn and to grow and bring the whole world together in a community? Even the source code to the discontinuous old Cisco VPN client could be used as a tool for learning valuable for some poor student hungry or developer of Open Source software somewhere trying to cope with Sauce and Ramen noodles noodles Ramen on toast (don't tell me you've never thought about it).  With the ripple effect, it would significantly improve sales over time, because it would open the door to a whole new market where could those who previously could not afford to participate now. That's the real power of Open Source. It creates a more skilled workforce for the future by contributing openly and share knowledge. What happens if the next big internet technology and the solution to the global tyranny - the solution to end all wars forever - locked in the mind of a software developer to unemployment, which could not afford to upgrade their software to router from cisco or access the software they need because he was source closed and required engage in a costly to download service contract?  It would be just terrible, wouldn't it?  I guess there is no way to ever know for sure. I guess I'd be as happy if a kind soul out there could tell me an alternative easy to use for one always on the VPN connection that is running in the background that does not require NetworkManager or having to spend days days searching in and trying to figure out some really poor or extremely complex documents?  I apologize for all the sentences run on posed as a question, but just a few serious mental exhaustion of this, being unemployed is a few people from hard work. I really could use a vacation.  Maybe a camping on the coast trip is in order after I get this job, that sounds nice, isn't it? Nothing like a summer storm on the beach to the ocean--away from technology - to refresh the mind.

    I won't step in all the discussions in there, but you might want to look into is vpnc and openconnect.

    The two opensource projects that seem to work with devices Cisco, for a long time, I've been a user of vpnc.

    http://www.infradead.org/openconnect/

    http://www.UNIX-AG.uni-kl.de/~Massar/vpnc/

    Looks like some of your questions, concerns should be directed to your Cisco rep.

    There is an AC for Linux client (component the GUI and CLI). If you have problems finding - get it from 'package' (for linux) file, which is essentially a zip.

  • AnyConnect 3.0 supports IPSec VPN for remote access?

    Hello world

    I've read about Cisco AnyConnect 3.0 issues that it supports IPSec VPN for remote access:

    http://www.Cisco.com/en/us/prod/collateral/vpndevc/ps6032/ps6094/ps6120/qa_c67-622477_ns1049_Networking_Solutions_Q_and_A.html

    I downloaded and installed the Client AnyConnect Secure Mobility Client 3.0.0629, but I'm not able to get the IPSec VPN works. Also, it has no option to use the previous of Cisco IPSec VPN client PCF files.

    Can someone point me in the right direction to get IPSec VPN AnyConnect 3.0 work?

    Thank you in advance!

    Hello

    Takes AnyConnect support IPSEC from version 3.0, but only in combination with IKEv2.

    There is no option to use a CPF file with it and the config should be pushed through a profile Anyconnect.

    More information on this:

    http://www.Cisco.com/en/us/docs/security/vpn_client/AnyConnect/anyconnect30/Administration/Guide/ac02asaconfig.html#wp1325361

    You should also change the ASA config so that it accepts negotiations IKE v2:

    http://www.Cisco.com/en/us/docs/security/ASA/asa84/configuration/guide/vpn_ike.html#wp1144572

    Kind regards

    Nicolas

  • Photoshop license valid for computers - worksation and laptop computer?

    I would like to know if I can install Photoshop on my desktop and laptop with the license that cost $ 9.99 per month? Or do I have to purchase another license and double the cost? Thank you.

    You can install your subscription cc on an unlimited number of computers.

    (minor for computers connected to the internet) only limitation is that you can sign-in (and therefore start) your cc programs, at most, two computers at a time.

    couldn't be easier or better.

  • What is a good VPN for Mac and iOS client?

    I want to identify a strong product of VPN for Mac and iOS.  I want something that is easy to install and maintain, and it's effective.

    Thank you

    This depends a lot on what you're trying to accomplish. Can elaborate you on why you think you need?

  • How can I change the default zoom for the new tab only?

    The new tab in Firefox 33 zoom is too high to see all 12 of my thumb nail. I changed it using ctrl - but the next time I opened a new tab, the zoom is 100%. How can I change the default zoom for the new tab only?

    I posted a style rule to shrink the tiles, which allows several of them on the page, but naturally reduces their legibility. You can experiment with the dimensions to find a look that works for you.

    https://userstyles.org/styles/106326/shrink-new-tab-thumbnails

    I use the Stylish extension to experiment because of its preview function that allows me to see the effect quickly. You can install it from the site of modules, then after restart of Firefox while searching for his "S" icon in the toolbar to manage Styles so you can edit and experiment.

    https://addons.Mozilla.org/firefox/addon/stylish/

  • NoSquint resized correctly web pages, but the superior task bars are still too large - for example, I can only the beginning of the URL. How to fix?

    After that the last version of Firefox all amplified, I used the add-on of NoSquint (60%), which makes web pages now as they did before. However, if the two albums at the top of the screen are of normal size, the lower ones are too big. The bar that contains the URL on the left and a Google search on the right space, for example, to view only the first two letters of a URL (after the / /).

    How can I make these bars look the way they used to? Thank you.

    To adjust the font size for the user interface, you can use the extension of theme font & size changer .

    This solve your problems? Please report to us!

    Thank you.

  • When is iTunes U, be available for computers Macbook or iMac?

    When is iTunes U, be available for computers Macbook or iMac?

    I can't understand why this program wouldn't be useful on these

    computers as well... Please explain!

    As you already know, these are the user forums, you don't talk to Apple and iTunes support on here - we won't know if/when iTunes U could become available on computers until if / when Apple announce something. If you want to leave a comment for Apple on this topic: http://www.apple.com/feedback/

  • I am looking to buy a 'new' ipod classic. IPod Superstore claims get the new Apple iPod that Apple is still making them for 5 years, but only to sell them to a few suppliers for resale. Is this possible?

    I am looking to buy a 'new' ipod classic. IPod Superstore claims get the new Apple iPod that Apple is still making them for 5 years, but only to sell them to a few suppliers for resale. Is this possible?

    Probably not still making them, but Apple political is to the service of produced at least five years after they is no longer manufactured and sold

    "Owners of iPhone, iPad, iPod or Mac products can get the services and Apple parts or service providers from Apple for 5 years after that the product is longer manufactured,' which is

    Vintage and obsolete products - Apple Support

    With the iPod, 'maintenance' means often giving you a replacement to pay the off-guarantee fee, which is $ 299 for the last classic model of the iPod, according to this document

    Pricing of the Service - The Apple iPod Support

    So Apple probably has a stock that's enough to last up to five years after 2014 (when the last classic model of the iPod has been abandoned).  This provider is unlikely to be an authorized dealer, as well as the iPod has not perhaps be covered by the standard warranty of one year.  That's why it comes in a regular white box, not a retail box.  It's supposed to be a replacement of maintenance for the iPod classic (latest model) owners.  It can be 'used', but it is still old.  Parts like LCD, HDD and the age of the battery by sitting in a warehouse.

  • What is the best vpn for OS 10

    What is the best VPN for my MacBook Pro running Yosemite

    The question is really not much sense.

    A VPN is not something that you install on a computer. It's a service that you connect to, as such, there is no better for a specific type of computer.

    What exactly you need to accomplish with a VPN?

    Usually, a VPN is used to connect to a remote network and use its resources, such as printers and servers, as if you were connected locally to them.

Maybe you are looking for

  • Converts the audio signals of the mydaq in discrete values

    Hi guys! I'm currently building a project that accepts mydaq audio signals. I wanted to analog signals it have descrete peak values. Is this possible? I intend to use the discrete peak values and sum their place by using a registry change instead of

  • Problem with writing in the new file every day, error #1

    Hi, I have build a vi that writes data measured for each second of the file. This vi will be used for the acquisition of long-term data and I want to write the data to a separate file every day, else the file becomes very large. The vi is supposed to

  • erroe code 646 kb976416 I can't update happening confused

    I have a problem installing Microsoft Office InfoPath 2007 kb976416 never had this problem before I do, this update is important

  • Updated the FMS equipment

    We have improved our material found in the Foglight Management Server. We went from 6 G memory to 32 G.  We are looking for recommendations on the allocation of this memory.  Right now it works, and I think that if ain't broke don't fix it, but if we

  • BlackBerry Smartphones how do you get the pad to stay rather than return to the ABC?

    It's maybe just me, but I can't understand this... When I type a message or an e-mail to someone and you must type a number as a phone number, I hit the 123 button and rises in the keypad, but once I hit a SINGLE number, the ABC cushion back upward,