I have a Cisco ASA 5520 Firewall. I'm using it as a Firewall and VPN Endpoint. There are at the moment 3 Site-to-Site VPN connections and 4 VPN Client connection profiles. Now they all work with no problem. My Question is it possible to limit one VPN client connection profile to accept connections only from one or two public IP's and of course how can I do it, but all other vpn client connection profiles must be accessible from anywhere?
It seems to me, that you didn't quite understand my question...
This article describes how to limit access to internal host behind the VPN endpoint/Firewall. I have to limit the users FROM WHERE they connect to the VPN endpoint. Their public IP's... Here is the qoute from the article. " This document provides a sample configuration using the Cisco Adaptive Security Device Manager (ASDM) for restricting what internal networks remote access VPN users can access behind the PIX Security Appliance or Adaptive Security Appliance (ASA). You can limit remote access VPN users to only the areas of the network that you want them to access when you:
Create access lists.
Associate them with group policies.
Associate those group policies with tunnel groups. "