Advertisement

07.03.2008 at 03:06AM PDT, ID: 23536289 | Points: 500
[x]
Attachment Details

Differentiate authentication type between Cisco Cut-Through Proxy and Cisco IPSec Remote Access VPN using IAS

Asked by chekfu in Cisco PIX Firewall, Virtual Private Networking (VPN)

Hi Expert

I have a Cisco ASA box. I've configured Cisco Remote Access VPN using IAS (Windows Server 2003 R2). It has been working very well for a year. For long, the domain user account being assigned in Security Group of "VPN Authentication", users just install Cisco VPN Client and import my PCF, they can connect to VPN.

Recently, I've configured Cisco Cut-Through Proxy in this Cisco ASA box using IAS. Create a security group of "Internet Authentication", assign some users to this group. Users get prompt for authentication box when they go 1st website (e.g www.google.com). Users type their own domain username and password, it was authenticated successfully and go to the web.

However, those users who have only security group of "Internet Authentication", they are able to connect to Cisco VPN, because I purposely install Cisco VPN Client and import the pcf file.

I wonder that what I should add in Remote Access Policy of IAS, so that, a user with "Internet Authentication" without "VPN Authentication" assigned, he only allow access Internet but no VPN. Similarly, a remote user only assigned with "VPN Authentication" without "Internet Authentication", he can only access VPN without Internet access.

Your help is very much appreciated.

Start Free Trial
[+][-]07.05.2008 at 08:57PM PDT, ID: 21939234

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.08.2008 at 11:18PM PDT, ID: 21960968

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]08.16.2008 at 09:22PM PDT, ID: 22246089

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08.17.2008 at 06:30AM PDT, ID: 22246857

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628