[c-nsp] per-user access-lists with IOS SSL VPN

Randy randy_94108 at yahoo.com
Wed Sep 5 20:28:55 EDT 2012



--- On Wed, 9/5/12, Jason Lixfeld <jason at lixfeld.ca> wrote:

> From: Jason Lixfeld <jason at lixfeld.ca>
> Subject: [c-nsp] per-user access-lists with IOS SSL VPN
> To: "cisco-nsp at puck.nether.net" <cisco-nsp at puck.nether.net>
> Date: Wednesday, September 5, 2012, 4:05 PM
> I've got a third party that need
> access to my network over my VPN.  Instead of giving
> them carte blanche, I'd like to wrap an ACL around their
> session so they only have access to what's permitted by the
> ACL.  I can configure these users in tac_plus as users,
> or as members of a group, or locally on the VPN box, if
> needed.
> 
> My google-fu hasn't turned up anything remotely appropriate
> to what it is I'm looking for - hoping someone out here
> might know.
> 
> My kit consists of a 2901 running 15.2(1)GC1.
> 
> Thanks in advance.


If my tired old brain-cells still recall correctly, I used to use extended-acls (for secure-routes) to accomplish something similar with ASAs
./Randy
 



More information about the cisco-nsp mailing list