cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
626
Views
4
Helpful
7
Replies

Cisco ise DACL for vpn connexion

MED Amine MB
Level 1
Level 1

Hello ,

I m trying to configure DACL on ise to allow vpn traffic to specific destinations. 

But after i configure them i get the auth logs as passed and authorized but on my machine it asks me to reconnect again and again. 

 

Can any one help me please. 

 

  • Regards, 
1 Accepted Solution

Accepted Solutions

Hello ,

 

i changed the syntax and it worked , the problem is i was using wildcad mask and all i had to do is to use regular mask .

 

regards ,

 

View solution in original post

7 Replies 7

Need some more detail here.  What is the NAD?  What version of ISE?  Is the dACL being applied?  

See: https://community.cisco.com/t5/security-knowledge-base/how-to-ask-the-community-for-help/ta-p/3704356

hello ,

My topology is like so :

users will connect to vpn configured on my FTD 

FTD then will send RADIUS requests to ISE

On the ISE i have two rules with itch have one groupe user from AD

and on those rules i want to permit access to certain destination and it doesn't seems to work as i see the logs everything is fine but the users still doesn't connect .

 

regards , 

config the VPN-filter under each group 
the ISE will only return the group of anyconnect and it will by default use the VPN-filter you use under that group 
no need dACL in this case

hello ,

 

accually my FTD is messed-up that's why i 'am using ISE for authentication i can't perform any filter or new configuration on it and the last solution i fund is to use DACL .

i used simple syntaxe like :

permit ip any X.X.X.X 0.0.255.255

permit ip any Y.Y.Y.Y 0.0.255.255

deny any any 

 

regards , 

What do you mean you can’t perform any configuration changes? This is going to be impossible to troubleshoot/implement if you don’t have admin access to the FTD. IMHO, that issue needs to be fixed first.

Hello ,

 

i changed the syntax and it worked , the problem is i was using wildcad mask and all i had to do is to use regular mask .

 

regards ,

 

can I see the config of ASA/FPR?