C H A P T E R
1-1
Cisco ASA Series CLI Configuration Guide
1
Configuring Connection Profiles, Group
Policies, and Users
This chapter describes how to configure VPN connection profiles (formerly called “tunnel groups”),
group policies, and users. This chapter includes the following sections.
•
Overview of Connection Profiles, Group Policies, and Users, page 70-1
•
Configuring Connection Profiles, page 70-6
•
Group Policies, page 70-36
•
Configuring User Attributes, page 70-89
In summary, you first configure connection profiles to set the values for the connection. Then you
configure group policies. These set values for users in the aggregate. Then you configure users, which
can inherit values from groups and configure certain values on an individual user basis. This chapter
describes how and why to configure these entities.
Overview of Connection Profiles, Group Policies, and Users
Groups and users are core concepts in managing the security of virtual private networks (VPNs) and in
configuring the ASA. They specify attributes that determine user access to and use of the VPN. A
group
is a collection of users treated as a single entity.
Users
get their attributes from
group policies
.
A
connection profile
identifies the group policy for a specific connection. If you do not assign a particular
group policy to a user, the default group policy for the connection applies.
Note
You configure connection profiles using
tunnel-group
commands. In this chapter, the terms “connection
profile” and “tunnel group” are often used interchangeably.
Connection profiles and group policies simplify system management. To streamline the configuration
task, the ASA provides a default LAN-to-LAN connection profile, a default remote access connection
profile, a default connection profile for SSL/IKEv2 VPN, and a default group policy (DfltGrpPolicy).
The default connection profiles and group policy provide settings that are likely to be common for many
users. As you add users, you can specify that they “inherit” parameters from a group policy. Thus you
can quickly configure VPN access for large numbers of users.
If you decide to grant identical rights to all VPN users, then you do not need to configure specific
connection profiles or group policies, but VPNs seldom work that way. For example, you might allow a
finance group to access one part of a private network, a customer support group to access another part,
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......