Re: Cisco VPN3k, locking users to client
John Ruff <[email protected]>
| Newsgroups | gmane.comp.security.vpn |
|---|---|
| Message-ID | <[email protected]> |
This may not be an exact answer but might point you in the right direction. You can restrict what group user 'A' logs in under by placing a value in the attribute 'CLASS' equal to 'OU=GroupName;' (notice the semicolon). So in other words if user 'A' was apart of group 'A', you would add the 'CLASS' radius attribute to the radius profile assigned to user 'A' having value 'OU=A;'. This would prevent user 'A' from logging in under group B, C, D, etc... Maybe this helps. The documentation on the above is from Cisco's site, so maybe what you're looking for is there too. Good Luck! _________________ John Ruff [email protected] "No one can see past a decision they don't understand." --The Oracle Dale Shaw wrote: >Hi, > >Can anyone think of a way to ensure that 'user A' can only establish a >VPN tunnel if they are connecting from 'VPN client A'? > >Setup: VPN3030, RADIUS authentication (to Cisco ACS 3.2 on Windoze), no >certificates, no hardware tokens. > >Unless I'm missing something really obvious, I can't see an easy way to >do this. > >cheers, >Dale > >_______________________________________________ >VPN mailing list >[email protected] >http://lists.shmoo.com/mailman/listinfo/vpn > > _______________________________________________ VPN mailing list [email protected] http://lists.shmoo.com/mailman/listinfo/vpn
john.vcf
(text/x-vcard, 149 B)
begin:vcard fn:John Ruff n:Ruff;John email;internet:[email protected] tel;cell:[email protected] x-mozilla-html:FALSE version:2.1 end:vcard