Cisco Systems Cisco ASA 5510/5520 and VLAN ? Affect IPSEC Remote User at one vlan

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Cisco ASA 5510/5520 and VLAN ? Affect IPSEC Remote User at one vlan Mag 01-31-09
Posted by Mag on January 31, 2009, 2:59 am
Please log in for more thread options
Hi

anyone know if it's possible that configure a lot of VLAN on
a Cisco ASA 5510/5520 LAN Interface and affect a Pool + User right
at one vlan ?





Internet ==> 80.xx.xx.xx => Cisco ASA5510 Wan Interface


                |==> Vlan 10 - 172.20.10.0/24 =>
                |==> Vlan 20 - 172.20.11.0/24 =>
ASA 5510 LAN        |==> Vlan 30 - 172.20.12.0/24 =>
                |==> Vlan 40 - 172.20.13.0/24 =>
                |==> Vlan 50 - 172.20.14.0/24 =>

One Pool IPSec Remote per Vlan:

User_Groupe_1 => Pool 172.21.10.0/24
        Can access only Vlan 10 Network

User_Groupe_2 => Pool 172.21.20.0/24
        Can access only Vlan 20 Network

User_Groupe_3 => Pool 172.21.30.0/24
        Can access only Vlan 30 Network

User_Groupe_4 => Pool 172.21.40.0/24
        Can access only Vlan 40 Network

User_Groupe_5 => Pool 172.21.50.0/24
        Can access only Vlan 50 Network



Thanks for your help

Posted by Brian V on January 31, 2009, 10:36 am
Please log in for more thread options

> Hi
>
> anyone know if it's possible that configure a lot of VLAN on
> a Cisco ASA 5510/5520 LAN Interface and affect a Pool + User right
> at one vlan ?
>
>
>
>
>
> Internet ==> 80.xx.xx.xx => Cisco ASA5510 Wan Interface
>
>
> |==> Vlan 10 - 172.20.10.0/24 =>
> |==> Vlan 20 - 172.20.11.0/24 =>
> ASA 5510 LAN |==> Vlan 30 - 172.20.12.0/24 =>
> |==> Vlan 40 - 172.20.13.0/24 =>
> |==> Vlan 50 - 172.20.14.0/24 =>
>
> One Pool IPSec Remote per Vlan:
>
> User_Groupe_1 => Pool 172.21.10.0/24
> Can access only Vlan 10 Network
>
> User_Groupe_2 => Pool 172.21.20.0/24
> Can access only Vlan 20 Network
>
> User_Groupe_3 => Pool 172.21.30.0/24
> Can access only Vlan 30 Network
>
> User_Groupe_4 => Pool 172.21.40.0/24
> Can access only Vlan 40 Network
>
> User_Groupe_5 => Pool 172.21.50.0/24
> Can access only Vlan 50 Network
>
>
>
> Thanks for your help

Sure, of course, doesn't have anything to do with VLAN's tho, based off of
subnets and it's controlled via the crypto maps. User group 1 has crypto map
1 assigned which permits vpnpool1 to talk to subnet1, group2 has pool2 to
subnet2, etc etc. You can also add cgoups which have access to one or more,
i.e. admin group has pool10 which has access to subnets1 thru 10.


Posted by alexd on January 31, 2009, 10:48 am
Please log in for more thread options
Mag wrote:

> anyone know if it's possible that configure a lot of VLAN on
> a Cisco ASA 5510/5520 LAN Interface and affect a Pool + User right
> at one vlan ?


> One Pool IPSec Remote per Vlan:
>
> User_Groupe_1 => Pool 172.21.10.0/24
> Can access only Vlan 10 Network

...etc...

> User_Groupe_5 => Pool 172.21.50.0/24
> Can access only Vlan 50 Network

VLANs are L2, subnets are L3. Happily you've given each VLAN its own subnet,
so I don't see a problem with that. I don't know how many subinterfaces a
5510 supports, but I'd be surprised if it didn't cope with 5 VLANs.

--
<http://ale.cx/> (AIM:troffasky) (UnSoEsNpEaTm@ale.cx)
15:42:52 up 57 days, 17:54, 2 users, load average: 0.02, 0.06, 0.03
Sexy ladies, and nasty boys, all freaky freakin', to the robot noise


Similar ThreadsPosted
Cisco ASA 5510/5520 and VLAN ? Affect IPSEC Remote User at one vlan January 31, 2009, 2:59 am
preserve remote vlan with Q in Q April 28, 2006, 1:04 pm
Cisco Softphone Vlan Versus Preexisting Hardphone Voice Vlan September 23, 2005, 7:43 am
VLAN Security vs. Inter-VLAN Routing December 18, 2007, 4:26 pm
Remote user VPN - Design help May 9, 2008, 1:31 am
Remote user can connect to the PIX 501 but cannot see the network behind it. November 8, 2005, 2:03 pm
ASA 5510 Remote VPN user question April 20, 2007, 4:21 pm
Remote User VPN - ASA 5505 and Client 5.0.02 January 16, 2009, 2:08 pm
Native, and management vlan "Vlan 1" September 21, 2005, 2:50 pm
User's VLAN and special VLAN August 25, 2006, 11:45 am
VLAN Project and Native VLAN July 13, 2007, 5:06 am
Remote access server user kickoff November 30, 2005, 9:14 am
Pix connection limit settings don't take affect? December 14, 2008, 9:31 pm
VLAN port with internet access can access only one vlan? April 21, 2006, 3:38 pm
cisco pix and vlan May 12, 2006, 11:04 am
Residential Cabling Guide

Home Cabling Guide

Finally, an instantly downloadable book that saves you thousands in home improvement dollars! Enjoy living in 21st century technology-advanced home while increasing its selling value and competitive advantage on the real estate market. Whether your cabling is for home office or high-tech leisure, you can wire your home yourself or learn "wirish" to speak with your cabling contractors in their language!

Learn More