Advertisement

10.17.2007 at 03:33PM PDT, ID: 22900504
[x]
Attachment Details

Using MS IAS For VPN AAA .. Works .. But Not Controlling Network Access

Asked by LBSources in IPSec Security Protocol, Virtual Private Networking (VPN), Cisco PIX Firewall

Tags: ias, found, server

Hello All .. First post.. I have lurked here for years and have found sooo many answers, fixes and assistance for many of my problems and decided its time to give back and get some help at the same time =-)

Moving on..

I have an ASA 5520 working just fine doing AAA with MS IAS. I have 2 groups and I can log in as any user from those groups with no problems. Based on the split-tunnel-acl I have network access also with no problems.

What I'm trying to do though is figure out 2 things.

1. How can I use MS IAS to control network access.

What I would like is to have the GROUP_SplitTunnelAcl say something like:

- permit 10.10.1.0 255.255.255.0

But using MS IAS block access to 10.10.1.5

I understand that you can control the ACL of the VPN group by specifying an ACL in the filter-id.

I found this out here: http://support.microsoft.com/kb/283829 .. But I have still yet been able to make even that work out. I think it has to do with something on the IAS server.

- What i have added / tried already is:
* Service-Type: Login

- I have added Cisco av-pair in the following format and none work:
- ip:inacl#=deny icmp any host 10.10.1.5
- ip:inacl#99=deny icmp any host 10.10.1.5
- ip:access-list GROUP_splitTunnelAcl deny icmp any 10.10.1.5

I have also tried adding these statements in the Vendor specific attribute settings identifying the following

- Vendor-Specific Attribute: Cisco
- Vendor-assigned attribute number: 1
- ip:inacl#=deny icmp any host 10.10.1.5
- ip:inacl#99=deny icmp any host 10.10.1.5
- ip:access-list GROUP_splitTunnelAcl deny icmp any 10.10.1.5
2. How can ASA ACLs be written, applied and used (that might be 3 things as one!)

- Must they be standard format?
------ If so, this means you cant write them to block protocol (ICMP, TCP, WWW)0 access right?
------ If no then how come I cant get my DENY ACLs above the PERMIT statements to work?

What I found funny is that even trying to set a DENY using protocol (ICMP) in the GROUP_SplitTunnelAcl didnt even work and is not respected when connected VIA VPN. This is what makes me believe you cant write STANDARD ACLs to block protocol (ICMP, TCP, WWW) access.

So in short.. this thing works fine, but I'd like to do this per group/user network access control. I'd like to have the split-tunnel-acl say allow access to the 10.10.1.0/24 of a subnet, but for Group A deny IP access for 10.10.1.5 and for Group B deny tcp to 10.10.1.8 eq www.

Hope I'm painting a clear picture, If not.. I will provide was is needed to help you help me :-)

Thanks in advance and I'm really excited to be a person in need here at EE!

LBSStart Free Trial
[+][-]10.17.2007 at 04:43PM PDT, ID: 20097872

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]10.17.2007 at 05:38PM PDT, ID: 20098063

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10.18.2007 at 04:45AM PDT, ID: 20099958

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]10.18.2007 at 04:49AM PDT, ID: 20099972

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10.18.2007 at 04:53AM PDT, ID: 20099985

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]10.18.2007 at 05:19AM PDT, ID: 20100102

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10.18.2007 at 06:01AM PDT, ID: 20100496

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10.19.2007 at 03:45AM PDT, ID: 20107735

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10.19.2007 at 12:03PM PDT, ID: 20111388

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]10.19.2007 at 07:13PM PDT, ID: 20113499

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10.20.2007 at 07:18AM PDT, ID: 20114842

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]10.20.2007 at 08:13AM PDT, ID: 20115042

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10.20.2007 at 08:43AM PDT, ID: 20115169

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10.20.2007 at 09:04AM PDT, ID: 20115218

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10.20.2007 at 09:06AM PDT, ID: 20115221

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]10.20.2007 at 10:24AM PDT, ID: 20115464

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10.20.2007 at 10:55AM PDT, ID: 20115548

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]10.20.2007 at 12:45PM PDT, ID: 20115858

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10.20.2007 at 01:14PM PDT, ID: 20115935

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]10.20.2007 at 01:18PM PDT, ID: 20115946

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10.20.2007 at 01:26PM PDT, ID: 20115963

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: IPSec Security Protocol, Virtual Private Networking (VPN), Cisco PIX Firewall
Tags: ias, found, server
Sign Up Now!
Solution Provided By: Darkstriker69
Participating Experts: 2
Solution Grade: A
 
 
[+][-]10.20.2007 at 01:32PM PDT, ID: 20115981

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_1_20070628