Deny VPN access to a user group

To block VPN access for a specific user or user group, create a group policy that denies VPN access and reference it in your ISE or RADIUS server authorization configuration.

Before you begin

Ensure that your remote access VPN policy includes authentication and authorization settings.

Procedure


Step 1

In Cloud-Delivered Firewall Management Center, choose Secure Connections > Remote Access VPN.

Step 2

Click the edit icon next to the remote access VPN policy and click the Advanced tab.

Step 3

In the left pane, click Group Policies.

Step 4

Click the edit icon next to a group policy or click + to add a new group policy.

Step 5

In the Add Group Policy or Edit Group Policy dialog box, click the Advanced tab.

Step 6

In the left pane, click Session Settings.

Step 7

In the Simultaneous Login Per User field, enter 0.

This configuration prevents the user or user group from connecting to the VPN even once.

Step 8

Click Save to save the group policy and then save the remote access VPN configuration.


What to do next

  1. Configure ISE or the RADIUS server to send IETF RADIUS Attribute 25 for the specific user or user group, mapping the attribute value to the corresponding group policy name.

    Ensure that the ISE or RADIUS server is the authorization server in the remote access VPN policy.

  2. Deploy the configuration on the Firewall Threat Defense device.