Any connect-vpn

Roni
Comes here often

Any connect-vpn

Hi everyone,

 

I want to enable the ability of "AnyConnect" on the mx.

I want to configure "split-Tunnel" and to do it I Have to set a subnet, but the mx want to allow to set my VPN subnet because it is already set on the "Addressing&vlan" is

Roni_0-1653808775935.png

 

it ok to delete the vpn vlan and set it only on the "AnyConnect" tab? 

4 Replies 4
Bruce
Kind of a big deal

Yes, the subnet that you’re using for remote access VPN (either AnyConnect or L2TP) only needs to be configured on the AnyConnect or L2TP page, you don’t need it configured on the “Addressing & VLAN” page.

Roni
Comes here often

Thank you All!

another thing is that I want to set to the VPN clients permissions "X" but I have one user that I want to set for him permissions "Y", to do so, I need that this specific user will connect to the VPN and get specific IP every time.

How can i do it with the "Anyconnect" ability?

 

Bruce
Kind of a big deal

I don’t believe you can do this directly with AnyConnect. What you’ll need to do is RADIUs authentication which returns a Filter-ID parameter that the MX then uses to apply a Meraki Group Policy to the user. Have a look in here under the Group Policy section, https://documentation.meraki.com/MX/AnyConnect_on_the_MX_Appliance.

 

The other option is once the device is connected to the VPN, find it in the client list on the Dashboard and manually apply a Group Policy to it.

KarstenI
Kind of a big deal
Kind of a big deal

You have to make sure that the VLAN from "Adressing & VLANs" is not used for something else. If it is in use, just pick a different free Subnet for AnyConnect.

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels