• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 424
  • Last Modified:

Multiple vpn group on a cisco pix

To create multiple group in VPN so that each group acces different network resources.
I am trying to create 2 different groups using vpngroup command. and give different set of access to these groups.
I am using PIX 506 firewall. ios ver 6.3.3

i  need the vpngroup sysdev to use the second access-list statement so that users using that group only access 10.160.170 network.

Please see the config below.

access-list vpnlist permit ip object-group gfnet-full
access-list vpnlist permit ip 255.255.0

crypto ipsec transform-set gfedsset esp-des esp-md5-hmac
crypto dynamic-map dmap 10 set transform-set gfedsset
crypto map smap 10 ipsec-isakmp dynamic dmap
crypto map smap client authentication TACACS+
crypto map smap interface outside
isakmp enable outside
isakmp policy 20 authentication pre-share
isakmp policy 20 encryption des
isakmp policy 20 hash md5
isakmp policy 20 group 2
isakmp policy 20 lifetime 4800
vpngroup full-net address-pool ippool
vpngroup full-net dns-server xxxxx
vpngroup full-net wins-server xxxxx
vpngroup full-net default-domain xxx.com
vpngroup full-net idle-time 1800
vpngroup full-net password ********

vpngroup sysdev address-pool ippool
vpngroup sysdev dns-server xxxx
vpngroup sysdev wins-server xxxxx
vpngroup sysdev default-domain xxx.com
vpngroup sysdev idle-time 1800
vpngroup sysdev password ********

1 Solution
Tim HolmanCommented:
Give each vpngroup a different IP pool (can be a single address), terminate this pool on the DMZ, and use the PIX to firewall requests.  Alternatively, lookup 'downloadable ACLs' or 'downloadable access lists' which can be used with RADIUS servers (eg Cisco Secure ACS, Microsoft IAS etc).
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Keep up with what's happening at Experts Exchange!

Sign up to receive Decoded, a new monthly digest with product updates, feature release info, continuing education opportunities, and more.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now