|
成功在ASA5550上配置SSL VPN+隧道分离+LDAP认证!!
ASA Version 8.0(3)
interface GigabitEthernet0/0
nameif outside
security-level 0
ip address 221.xxx.xxx.xxx 255.255.255.xxx
!
interface GigabitEthernet0/1
nameif inside
security-level 100
ip address 172.16.36.10 255.255.255.128
!
access-list vpn-test standard permit 10.8.0.0 255.255.0.0
access-list vpn-test standard permit 172.16.0.0 255.240.0.0
access-list vpn-test standard permit 192.168.0.0 255.255.0.0
ip local pool vpn-test 172.18.0.2-172.18.63.254
ip local pool vpn-test1 172.18.64.2-172.18.127.254
ip local pool sslvpn01 172.18.128.1-172.18.128.254
ip local pool sslvpn02 172.18.129.1-172.18.129.254
route outside 0.0.0.0 0.0.0.0 221.xxx.xxx.xxx 1
route inside 10.8.0.0 255.255.0.0 172.16.36.1 1
route inside 172.16.0.0 255.240.0.0 172.16.36.1 1
route inside 192.168.0.0 255.255.0.0 172.16.36.1 1
ldap attribute-map vpntest
map-name
memberOf IETF-Radius-Class
map-value memberOf CN=vpngroup1,CN=Users,DC=xxx,DC=ad sslvpn01
map-value memberOf CN=vpngroup2,CN=Users,DC=xxx,DC=ad sslvpn02
aaa-server xxx-LDAP protocol ldap
aaa-server xxx-LDAP host 172.16.41.53
ldap-base-dn DC=xxx,DC=ad
ldap-scope subtree
ldap-naming-attribute sAMAccountName
ldap-login-password *
ldap-login-dn CN=vpn,CN=Users,DC=xxx,DC=ad
server-type microsoft
ldap-attribute-map vpntest
nac-policy DfltGrpPolicy-nac-framework-create nac-framework
reval-period 36000
sq-period 300
webvpn
enable outside
svc image disk0:/anyconnect-win-2.2.0136-k9.pkg 1
svc enable
tunnel-group-list enable
group-policy DfltGrpPolicy attributes
dns-server value 172.16.35.20
vpn-tunnel-protocol svc
split-tunnel-policy tunnelspecified
split-tunnel-network-list value vpn-test
address-pools value vpn-test
webvpn
svc ask none default svc
customization value DfltCustomization
file-entry disable
file-browsing disable
group-policy GroupPolicy1 internal
group-policy GroupPolicy1 attributes
dns-server value 172.16.35.20
vpn-tunnel-protocol svc
split-tunnel-policy tunnelspecified
split-tunnel-network-list value vpn-test
address-pools value vpn-test1
webvpn
svc keep-installer installed
svc rekey time 30
svc rekey method ssl
svc ask none default svc
username cisco123 password ffIRPGpDSOJh9YLq encrypted privilege 15
tunnel-group DefaultRAGroup general-attributes
authentication-server-group xxx-LDAP
tunnel-group DefaultWEBVPNGroup general-attributes
address-pool vpn-test
authentication-server-group xxx-LDAP
tunnel-group sslvpn type remote-access
tunnel-group sslvpn general-attributes
address-pool vpn-test
authentication-server-group xxx-LDAP
tunnel-group sslvpn webvpn-attributes
group-alias LDAP-server enable
tunnel-group TestGroup1 type remote-access
tunnel-group TestGroup1 general-attributes
address-pool vpn-test1
default-group-policy GroupPolicy1
tunnel-group TestGroup1 webvpn-attributes
group-alias Local-server enable
!
: end
ciscoasa# |
|