i already configure my google ldap in ldap server authentication, but all user inside our google ldap directory can login, what i want is only certain can do login..
Hello Wilfredo,
Could you share your current configuration for this:
but i want to restrict other group to login to ssl vpn connection and allow only remoteaccess group
Also, could you further elaborate the "other group" you mentioned and if it's possible kindly share any details/screenshot of the current config and share expected output.
Thank you
Raphael Alganes
Global Community Engineer, Support & Services
Are you a Sophos Partner? | Product Documentation | @SophosSupport | Sign up for SMS Alerts
If a post solves your question, please use the 'Verify Answer' button.
The award-winning home for Sophos Support videos! - Visit Sophos Techvids
this is the setting in ldap server authentication.
inside our google ldap we have many groups like wasabi for our storage , remoteacess for our VPN Connection. user in this group are allow to do remote SSL VPN Connection, but the issue is all group | all user inside our google ldap can login in SSL VPN, what i want is only this remoteacess group can login to SSL VPN
in this group attributes: i try to input memberOf: cn=remoteaccess to allow only remoteacess group user can login in SSL VPN but still all user can do login..
Hello,
You may try to use IPsec Remote Access for the said requirement under Remote Access VPN>IPsec>Allowed users and groups*
You should be able to input preconfigured users and groups here who can connect through remote access IPsec tunnels.
Regards,
Raphael Alganes
Global Community Engineer, Support & Services
Are you a Sophos Partner? | Product Documentation | @SophosSupport | Sign up for SMS Alerts
If a post solves your question, please use the 'Verify Answer' button.
The award-winning home for Sophos Support videos! - Visit Sophos Techvids
Sir,
thanks for the reply Sir
i already try group, what i mean inside google business we have some group as what i mentioned before, my question how i can select the specific group to add in sophos authentication since some group in our google account not allow to use vpn?
Hello,
Could you confirm if I understand your requirements correctly?
You're able to setup Google LDAP already: https://docs.sophos.com/nsg/sophos-firewall/21.0/Help/en-us/webhelp/onlinehelp/AdministratorHelp/Authentication/Servers/LDAP/AuthenticationGoogleLDAP/index.html#upload-the-certificate
Then, you want to allow only a specific user/group to use RA VPN?
If this is the case, you may try following the steps shared above.
Raphael Alganes
Global Community Engineer, Support & Services
Are you a Sophos Partner? | Product Documentation | @SophosSupport | Sign up for SMS Alerts
If a post solves your question, please use the 'Verify Answer' button.
The award-winning home for Sophos Support videos! - Visit Sophos Techvids
Hi Raphael,
Yes, Google Ldap Configuration is all working they can login via ssl vpn using there google account.
the issue is all user inside the google ldap directory can login using their own credential, my question is, if possible, to select only specific group to login in not all group.
Hello Wilfredo,
did you try it like this:
Mit freundlichem Gruß, best regards from Germany,
Philipp Rusch
New Vision GmbH, Germany
Sophos Silver-Partner
If a post solves your question please use the 'Verify Answer' button.