Forum Discussion

Cisco2F5_16233's avatar
Cisco2F5_16233
Icon for Nimbostratus rankNimbostratus
Jan 04, 2017

SSL VPN Beyond the Template

So we are looking to SSL VPN with APM. I've gone though the template to see what it created and try to build on that but what i need is more advanced. I'm looking for a place to start even some example polices.

 

Here is the flow I need. I know APM should be able to do it just not sure where to start.

 

  1. User goes portal enters AD Username and Password

     

  2. a.If user is in a power user AD group and above like app admin,network admin..etc use second factor radius with Entrust/Open AM. b.If not allow user to access portal only with app links / no full VPN.

     

  3. If users passes second factor auth assign IP information based on group i.e PowerUser(subnet1),WebAdmin(subnet2),Network Admin(subnet3)..etc

     

It seems like it could be possible just not sure where to start next. Any help would be awesome!

 

1 Reply

  • I don't see an issue implementing this scenario with APM. Generally speaking, you would have to create different branches based on initial AD query. For different VPN networks your would create 3 appropriate "Network access lists" with corresponding lease pools and assign VPN resource to those branches.