Deny VPN Access to a User Group
Before you begin
Ensure that you have configured remote access VPN using the Remote Access Policy wizard and configured authentication settings for the remote access VPN policy.
Procedure
1 |
On your Secure Firewall Management Center web interface, choose Devices > VPN > Remote Access. |
2 |
Select a remote access policy and click Edit. |
3 |
Select Advanced > Group Policies. |
4 |
Select a group policy and click Edit or add a new group policy. |
5 |
Select Advanced > Session Settings and set Simultaneous Login Per User to 0 (zero). This stops the user or user group from connecting to the VPN even once.
|
6 |
Click Save to save the group policy and then save the remote access VPN configuration. |
7 |
Configure ISE or the RADIUS server to set the Authorization Profile for that user/user-group to send IETF RADIUS Attribute 25 and map to the corresponding group policy name. |
8 |
Configure the ISE or RADIUS server as the authorization server in the remote access VPN policy. |
9 |
Save and deploy the remote access VPN policy. |