Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

ASA / Wireless / VPN

Status
Not open for further replies.

leaky5

Technical User
May 20, 2009
4
GB
I have created a subinterface for a Wireless only subnet on an ASA. This is also providing the DHCP for the wireless subnet.

Now I would like to bring wireless users in as securely as possible, within the constraints of the network infrastructure.

On AP. (AP will be locked down as securely as possible)
1/ Don't broadcast SSID.
2/ WPA2 authentication. Pre shared key
3/ Implement MAC address filtering. ( for when people give their friends the Pre shared key )

On ASA.
4/ Create Remote Access VPN group with AD authentication.
5/ Create Firewall rules to restrict access as required.

What I need to know is this.
I want the traffic to have to authenticate at point 4/ before continuing through the ASA at point 5/.

Is this possible ?
 
I dont think the ASA offers a capture or authentication server in this way.

Could be wrong, but we tend to use these as fairly basic site to site VPN devices.



ACSS - SME
General Geek

CallUsOn.png


1832163.png
 
You can configure an ASA to use AD authentication for VPN access.

This is for an older software version but it should get you pointed in the right direction.


Stubnski
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top