Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

MS NPS server 2008 to assign local ip pools

Status
Not open for further replies.

peanican

MIS
Sep 18, 2007
13
CA
I run a cisco asa5520 and MS Server 2008 NPS server for VPN access. I normally assign vpn ip addresses to individual users through User properties > Dial-in > Assign static address in Active Directory.

I need to assign different address pools to different groups using my NPS server.

a) I want to keep just one tunnel group
b) Assign different local ip pools based on NPS policy

I've found online that I can send: cisco-avpair="ip:addr-pool=pool1" from my NPS server. Obviously it is not working, or I would not be posting. Is there a setting on the ASA that I need to set so it will respond to the pool request?

I found someone say "client configuration address respond" works on the pix but I have no idea what the the equvalnt command is for ASA or if I even need it.

tunnel group settings:
Code:
tunnel-group remote-vpn type ipsec-ra
tunnel-group remote-vpn general-attributes
 authentication-server-group Radius_Group
 default-group-policy default
tunnel-group remote-vpn ipsec-attributes
 pre-shared-key *
To recap. My tunnel gets created but then disconnects immediately with the error unable to obtain IP address. Any help would be awesome.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top