Restrict Remote VPN to a specific AD Group with NCC

LESPIAUC_Info_40
Posts: 3
Freshman Member



in Nebula
Hi,
I try to restrict Remote VPN to a specific AD group but I can't do it.
Here is screenshots of my configuration :
Do I've made a mistake ?
Thks
0
All Replies
-
Any ideas ?
0 -
I did a local lab with your security policy. Based on these security policies, the VPN connection will always hit the deny rule, since the VPN user information hasn't learned on firewall.
For workaround, we can set some rules to block VPN traffic for non-VPN group users. Below is the example:
For your original purpose, I'm checking with our engineer. I will update you once I get an update.
Zyxel Melen0 -
Update:
There is a workaround for this requirement:
- Create an user that can only access specific OU, like OU = vpnuser. Other privileges like cn=users, please remove them.
- Use this user to setup "authentication service > My AD server".
- Use this authentication method for the remote access VPN, this allows to authenticate the AD user that in specific OU.
Zyxel Melen0
Categories
- All Categories
- 438 Beta Program
- 2.7K Nebula
- 189 Nebula Ideas
- 121 Nebula Status and Incidents
- 6.2K Security
- 463 USG FLEX H Series
- 304 Security Ideas
- 1.6K Switch
- 81 Switch Ideas
- 1.3K Wireless
- 44 Wireless Ideas
- 6.8K Consumer Product
- 280 Service & License
- 439 News and Release
- 88 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.3K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 91 Security Highlight