Re: Cisco VPN3k, locking users to client

John Ruff <[email protected]>
Newsgroups gmane.comp.security.vpn
Message-ID <[email protected]>
This may not be an exact answer but might point you in the right 
direction.  You can restrict what group user 'A' logs in under by 
placing a value in the attribute 'CLASS' equal to 'OU=GroupName;' 
(notice the semicolon).  So in other words if user 'A' was apart of 
group 'A', you would add the 'CLASS' radius attribute to the radius 
profile assigned to user 'A' having value 'OU=A;'.  This would prevent 
user 'A' from logging in under group B, C, D, etc...

Maybe this helps.  The documentation on the above is from Cisco's site, 
so maybe what you're looking for is there too.

Good Luck!

_________________
John Ruff
[email protected]

"No one can see past a decision they don't understand." --The Oracle




Dale Shaw wrote:

>Hi,
>
>Can anyone think of a way to ensure that 'user A' can only establish a
>VPN tunnel if they are connecting from 'VPN client A'?
>
>Setup: VPN3030, RADIUS authentication (to Cisco ACS 3.2 on Windoze), no
>certificates, no hardware tokens.
>
>Unless I'm missing something really obvious, I can't see an easy way to
>do this.
>
>cheers,
>Dale
>
>_______________________________________________
>VPN mailing list
>[email protected]
>http://lists.shmoo.com/mailman/listinfo/vpn
>  
>

_______________________________________________
VPN mailing list
[email protected]
http://lists.shmoo.com/mailman/listinfo/vpn
john.vcf (text/x-vcard, 149 B)
begin:vcard
fn:John Ruff
n:Ruff;John
email;internet:[email protected]
tel;cell:[email protected]
x-mozilla-html:FALSE
version:2.1
end:vcard
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.