Firewall rule for certain VPN clients based on the username

Subash
Comes here often

Firewall rule for certain VPN clients based on the username

Hi, I have a client VPN enabled on a MX450. I need to configure a rule to access only particular servers in my local network for certain users on client VPN.

 

Is there a way to configure a firewall rule or group policy for my requirement ?

4 Replies 4
Bruce
Kind of a big deal

Assuming you are using the ‘classic’ L2TP/IPSec VPN Client then unfortunately there is no way to assign a policy based on a user. The closest you’ll be able to get is manually assign a Group Policy to a client once they are connected. Each time they reconnect that policy will be applied to the client.

 

If you’re game enough to try the MX16 code then you can use the AnyConnect VPN Client. Using the AnyConnect VPN Client you can perform RADIUS authentication and return a Filter-ID attribute which can be used to apply a Group Policy to the client.

Subash
Comes here often

Thanks for your response bruce . I need to try applying group policy once the device is connected to the network.

 

I remember that in other thread somebody mentioned the group policy will remain same for the applied device as it is working based on the mac id. If that is a case I can try using this option.

 

 

Bruce
Kind of a big deal

Yep, that should be the case. Once applied the Group Policy should 'stick' to the client, and so be applied each time they connect.

Subash
Comes here often

Okay. Thank you bruce

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels