Solved

Multiple vpn group on a cisco pix

Posted on 2004-04-28
3
418 Views
Last Modified: 2013-11-16
To create multiple group in VPN so that each group acces different network resources.
I am trying to create 2 different groups using vpngroup command. and give different set of access to these groups.
I am using PIX 506 firewall. ios ver 6.3.3

i  need the vpngroup sysdev to use the second access-list statement so that users using that group only access 10.160.170 network.

Please see the config below.

access-list vpnlist permit ip object-group gfnet-full 10.170.30.0 255.255.255.0
access-list vpnlist permit ip 10.160.170.0 255.255.255.0 10.170.30.0 255.255.0

crypto ipsec transform-set gfedsset esp-des esp-md5-hmac
crypto dynamic-map dmap 10 set transform-set gfedsset
crypto map smap 10 ipsec-isakmp dynamic dmap
crypto map smap client authentication TACACS+
crypto map smap interface outside
isakmp enable outside
isakmp policy 20 authentication pre-share
isakmp policy 20 encryption des
isakmp policy 20 hash md5
isakmp policy 20 group 2
isakmp policy 20 lifetime 4800
vpngroup full-net address-pool ippool
vpngroup full-net dns-server xxxxx
vpngroup full-net wins-server xxxxx
vpngroup full-net default-domain xxx.com
vpngroup full-net idle-time 1800
vpngroup full-net password ********

vpngroup sysdev address-pool ippool
vpngroup sysdev dns-server xxxx
vpngroup sysdev wins-server xxxxx
vpngroup sysdev default-domain xxx.com
vpngroup sysdev idle-time 1800
vpngroup sysdev password ********

0
Comment
Question by:jessriju
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 23

Accepted Solution

by:
Tim Holman earned 125 total points
ID: 10938128
Give each vpngroup a different IP pool (can be a single address), terminate this pool on the DMZ, and use the PIX to firewall requests.  Alternatively, lookup 'downloadable ACLs' or 'downloadable access lists' which can be used with RADIUS servers (eg Cisco Secure ACS, Microsoft IAS etc).
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Stuck in INIT/DROTHER 2 76
ip igmp join-group 8 72
Cisco ASA 5505 firewall open port 4 22
Objects in Cisco ASA 2 3
For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
Many of the companies I’ve worked with have embraced cloud solutions due to their desire to “get out of the datacenter business.” The ability to achieve better security and availability, and the speed with which they are able to deploy, is far grea…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question