Assign group policy using the authorization server

Configure ISE or a RADIUS server to set the authorization profile for a user or user group and also select the group policy and other attributes. After users are authenticated, these authorization attributes are pushed to the Firewall Threat Defense device.

Before you begin

Ensure that you have a remote access VPN policy with RADIUS as the authentication server.

Procedure


Step 1

In Cloud-Delivered Firewall Management Center, choose Secure Connections > Remote Access VPN.

Step 2

Click the edit icon next to the remote access VPN policy.

Step 3

Click the Advanced tab.

Step 4

In the left pane, click Group Policies and add the required group policy.

You can map only one group policy to a connection profile. However, you can create multiple group policies within a remote access VPN policy and reference them in an ISE or a RADIUS server. After user authentication, the authorization server dynamically assigns one of these group policies using the authorization attributes, overriding the group policy configured in the connection profile.

Step 5

Deploy the configuration on the Firewall Threat Defense device.

Step 6

In the authorization server, create an authorization profile with RADIUS attributes for IP address and downloadable ACLs.