Restrict Remote VPN to a specific AD Group with NCC
Options
LESPIAUC_Info_40
Posts: 3
Freshman Member
Freshman Member
in Nebula
Hi,
I try to restrict Remote VPN to a specific AD group but I can't do it.
Here is screenshots of my configuration :
Do I've made a mistake ?
Thks
0
All Replies
-
Any ideas ?
0 -
I did a local lab with your security policy. Based on these security policies, the VPN connection will always hit the deny rule, since the VPN user information hasn't learned on firewall.
For workaround, we can set some rules to block VPN traffic for non-VPN group users. Below is the example:
For your original purpose, I'm checking with our engineer. I will update you once I get an update.
Zyxel Melen0 -
Update:
There is a workaround for this requirement:
- Create an user that can only access specific OU, like OU = vpnuser. Other privileges like cn=users, please remove them.
- Use this user to setup "authentication service > My AD server".
- Use this authentication method for the remote access VPN, this allows to authenticate the AD user that in specific OU.
Zyxel Melen0
Categories
- All Categories
- 442 Beta Program
- 3K Nebula
- 231 Nebula Ideas
- 131 Nebula Status and Incidents
- 6.6K Security
- 680 USG FLEX H Series
- 362 Security Ideas
- 1.8K Switch
- 87 Switch Ideas
- 1.4K Wireless
- 56 Wireless Ideas
- 7.1K Consumer Product
- 309 Service & License
- 502 News and Release
- 96 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5.1K FAQ
- 34 Documents
- 89 About Community
- 111 Security Highlight



Zyxel Employee
