In article <> ,
japper_uk <> wrote:
:Is it possible within pix vpn 6.3 to lock down authenticated users to

nly be able to access server i.p's only? thinking along the lines of
:3rd party support that presently use dial up for access.
If you are using RADIUS, you can use downloadable ACLs.
The explanation of this is not very good in the Reference manual,
but the Configuration Guide has a enough more detail that you might
be able to get it to work.
If you are using TACACS+, then the documentation in a couple of
places indicates that you cannot do this, but then there's one
line in the Reference manual [in a relevant section] that seems to
indicate that TACACS+ is compatible with RADIUS for this function.
So I don't know if it can be done with TACACS+ or not.
--
"WHEN QUINED, YIELDS A TORTOISE'S LOVE-SONG"
WHEN QUINED, YIELDS A TORTOISE'S LOVE-SONG. (GEB)