Solved

Cisco ASA DCHP Reservations

Posted on 2009-04-15
3
827 Views
Last Modified: 2013-11-05
I have a Cisco ASA 5510 configured for VPN access.  I've created and assigned an IP Address pool for VPN connections on the ASA device.  One of our applications that is accessed through the VPN has a builtin security feature that only allows access from preconfigured IP addresses. Is there a way to create DHCP reservations for the VPN connections on the ASA Device?
Note: User Accounts exist in Active Directory and will authenticate via LDAP. Using Local accounts is not considered an option at this point.
0
Comment
Question by:vikashdaya
  • 2
3 Comments
 
LVL 43

Expert Comment

by:JFrederick29
ID: 24147251
Not without using local accounts.

What you can do however is create a separate VPN group (connection profile) and assign a different pool of addresses to be used for this application.  Only the users that need access to the application will use the new group and get an IP address that is allowed to access the application.
0
 

Author Comment

by:vikashdaya
ID: 24147446
I did think of that... however, the problem is the application locks down to IP address and Machine Name so the user has to get the same IP each time they connect.  Having a seperate IP Pool won't guarantee that they get the same IP each time.
I'm trying to work out if the VPN connections are able to get IP address assignments from Windows 2003 DHCP and AD User Properties (Dial-in tab has options to allocate IP to a user).  If anyone has links to how this can be done, please post them on this thread.
Thanks
0
 
LVL 43

Accepted Solution

by:
JFrederick29 earned 500 total points
ID: 24147639
Kind of a kludge but you could create a VPN group per user if you only have a handful of users that access this application.

I know you can use a RADIUS attribute to assign an IP address so that is something to look into.  Perhaps IAS can provide this functionality.

As far as DHCP is concerned, you can tell the ASA to use a DHCP server instead of a local pool and create a reservation specifying the computers MAC address.  This might be the simplest option.
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Office 365 vs. In-House 4 80
cannot connect to openvpn server 9 58
Packet Tracer Router to Router 10 56
Dedicated I.P., VPN, both, neither, or what? 12 22
I've had to do a bit of research to setup my VPN connection so that Clients can access Windows Server 2008 network shares.  I have a Cisco ASA 5510 firewall.  I found an article which was extremely useful: It had a solution if you use ASDM to config…
For a while, I have wanted to connect my HTC Incredible to my corporate network to take advantage of the phone's powerful capabilities. I searched online and came up with varied answers from "it won't work" to super complicated statements that I did…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

930 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now