cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
194
Views
0
Helpful
6
Replies

Cisco FPR version 7.2.5 is possible make group lock for local user

faruk.zaimovic
Level 1
Level 1

Hello ,

Cisco FPR version 7.2.5 is possible make group lock for local user that connect to local network over AnyConnect. 

I want to make Anyconnect access in our network where we have more group policy, we can not find that we can lock local user for some group policy.

 
does anybody have same problem, and how to solve  it ?
Thank you very much.
6 Replies 6

tvotna
Spotlight
Spotlight

I believe this feature is still not natively supported in the GUI:

CSCvz10754 ENH: RAVPN(FMC): Option to add attributes for Local user

You can try to use Flex config to generate same CLI on FTD as on ASA to lock users:

user <name> attributes
 group-lock value <tunnel-group>

 

HI,

I tried, and it is unsupprted.

farukzaimovic_0-1713358232613.png

 

This feature is depend on that user is local in db of ftd' 

You use AD ? What is the connection profile ypu use' can you share screenshots of auth server page?

MHM

thank you for your resonse. i want to use local user, same as cisco ASA have that feature.

i have that user in local in db. it is so strange why it is not accept.

> show running-config username

username zsanjin password ***** encrypted

thank you

Interesting because the "username" command doesn't seem to be part of the blacklisted commands on FlexConfig. Does the error show you anything if you try to scroll down using the little arrows? also, did you try without adding any spaces on the "group-lock" line?

Cisco Secure Firewall Management Center Device Configuration Guide, 7.2 - FlexConfig Policies [Cisco Secure Firewall Management Center] - Cisco

Hello, 

Thank you very much for your response.

I tried to add username and password only  it show unsupported.

farukzaimovic_0-1713436559348.png