Enforce a connection profile for a user group

By default, Secure Client displays all connection profiles configured in the Cloud-Delivered Firewall Management Center and deployed on the Firewall Threat Defense device, listed by connection profile name, alias, or alias URL. If no connection profiles are configured, Secure Client displays the DefaultWEBVPNGroup connection profile.

To enforce a specific connection profile for a user or user group, you can disable all other connection profiles so that their group aliases and URLs are hidden from users during login. This configuration ensures that users connect only through the connection profile meant for their group.

Use this approach to apply distinct VPN configurations for different user groups, such as mobile users, corporate-issued laptop users, or personal laptop users. Configure a dedicated connection profile for each group and disable the others to automatically apply the correct settings when users connect.

Before you begin

  • In Cloud-Delivered Firewall Management Center, configure a remote access VPN policy with the authentication method as Client Certificate Only or Client Certificate & AAA.

  • Configure ISE or RADIUS server for authorization and associate the group policy with the server.

Procedure


Step 1

In Cloud-Delivered Firewall Management Center, choose Secure Connections > Remote Access VPN.

Step 2

Click the edit icon next to the remote access VPN policy and click the Access Interfaces tab.

Step 3

Uncheck the Allow users to select connection profile while logging in check box.

Step 4

Click the Advanced tab.

Step 5

In the left pane, click Certificate Maps.

Step 6

Check the Use the configured rules to match a certificate to a Connection Profile check box.

Step 7

Click Add Mapping to map the connection profile with a certificate rule.

Step 8

In the Add Connection Profile to Certificate Map dialog box, configure these parameters:

  1. From the Certificate Map Name drop-down list, choose a certificate map, or click + to add a new map.

  2. From the Connection Profile drop-down list, choose a connection profile.

  3. Click OK.

Step 9

Click Save.