Use Roles in Cloud Authentication to limit user access to OneConnect

Last modified on 10 Oct, 2024. Revision 7
Up to date for
Clavister Cloud Services 3.5.0
cOS Core 14.00.16
Status OK

This guide explains how use the Roles in Clavister Cloud Service to implement Role-Based Access Control for Clavister OneConnect.

The guide assumes you are already enrolled as an administrator in the service.

Organizations often require different user groups to access specific resources for security and operational efficiency. In environments where multiple Clavister NetWall firewalls are are deployed, controlling access per OneConnect tunnel interfaces becomes crucial. This guide explains how to use roles within Clavister Cloud Authentication to manage user access effectively across different VPN gateways.

Introduction

In scenarios where an organization operates multiple OneConnect servers, it is essential to ensure that users can access only the servers relevant to their role. For instance, some users need access to VPN server A, others to VPN server B, and a select few require access to both.

Clavister Cloud Authentication allows the creation of roles, such as “OneConnect_A” and “OneConnect_B”, to manage access permissions. These roles are assignable to users, enabling precise control over which VPN gateway they can access.

Configuring Roles

  1. Add the Role: Define the roles "OneConnect_A" and "OneConnect_B" under Users → Roles.



  2. Assign Roles to Users: On the user, select one or more applicable Roles.



  3. Configure NetWall: In Clavister NetWall, set up a OneConnect VPN interface. Assign the created roles to the "User Groups:" setting in each corresponding VPN interface configuration.

By leveraging roles in Clavister Cloud Authentication, administrators can tailor user access to specific OneConnect VPN , enhancing both security and usability. This setup ensures that users access only the necessary resources, aligning with best practices for network security and management.

Related articles

Brian Smart Search (Beta)
15 Jan, 2024 dictionary troubleshoot core stream incontrol incenter oneconnect cloudservice
Configure Clavister OneConnect using deep links
13 Jun, 2022 oneconnect macos ios windows android
Configure Clavister OneConnect for macOS, iOS and iPadOS towards NetWall
28 Apr, 2023 openconnect oneconnect macos ios iphone
Configuring public certificates in NetWall firewalls
18 Mar, 2024 core certificate oneconnect ipsec vpn
Configure the Android OpenConnect client towards Clavister NetWall
23 Aug, 2022 sslvpn openconnect oneconnect android core
Configure Clavister OneConnect for Windows towards Clavister NetWall
29 Oct, 2021 sslvpn openconnect oneconnect windows
Lets Encrypt - error 9814 - chain had an expired certs
13 Oct, 2021 oneconnect macos openconnect ios
Certificate update in InControl global domain on certificate that is used on firewall(s)
18 Mar, 2024 core incontrol certificate oneconnect ipsec vpn
Configure Linux OpenConnect towards Clavister NetWall
5 Mar, 2021 sslvpn openconnect oneconnect linux core
Configuring SSL-VPN / OneConnect server on secondary Firewall IP address
8 Apr, 2021 core sslvpn oneconnect interfaces arp
OneConnect VPN certificate not trusted
18 Mar, 2024 onetouch sslvpn oneconnect troubleshoot certificate
Install OneConnect without Microsoft store
25 Feb, 2022 oneconnect windows howto
Howto - Userbased rules
27 Feb, 2024 oneconnect userbased core
Changing the certificate used by the OneConnect client/server
28 Nov, 2022 core configuration oneconnect
Clavister OneConnect server using cOS Core as CA Server
11 May, 2023 oneconnect certificate howto
Background apps premission
27 Aug, 2024 oneconnect windows
Configure the OpenConnect-GUI client towards Clavister NetWall
23 Aug, 2022 sslvpn openconnect oneconnect macos windows linux core