This guide explains how use the Roles in Clavister IdAuth Cloud, not just to limit access in IP Policies bu also to implement Role-Based Access Control for the specific Clavister OneConnect server.
The guide assumes you are already enrolled as an administrator in the service.
Organizations often require different user groups to access specific resources for security and operational efficiency. In environments where multiple Clavister NetWall firewalls are are deployed, controlling access per OneConnect tunnel interfaces becomes crucial. This guide explains how to use roles within Clavister IdAuth Cloud to manage user access effectively across different VPN gateways.
Introduction
In scenarios where an organization operates multiple OneConnect servers, it is essential to ensure that users can access only the OneConnect server relevant to their role. For instance, some users need access to VPN server A, others to VPN server B, and a select few require access to both.
Clavister Cloud Authentication allows the creation of roles, such as “OneConnect_A” and “OneConnect_B”, to manage access permissions. These roles are assignable to users, enabling precise control over which VPN gateway they can access.
Configuring Roles
- Add the Role: Define the roles "OneConnect_A" and "OneConnect_B" under Users → Roles.

- Assign Roles to Users: On the user, select one or more applicable Roles.

- Configure NetWall: In Clavister NetWall, set up a OneConnect VPN interface. Assign the created roles to the "User Groups:" setting in each corresponding VPN interface configuration.

By leveraging roles in Clavister IdAuth Cloud, administrators can tailor user access to specific OneConnect VPN , enhancing both security and usability. This setup ensures that users access only the necessary resources, aligning with best practices for network security and management.
Related articles
6 Dec, 2025 sase cloud oidc
17 Mar, 2025 oneconnect sase cloud
5 Feb, 2024 oneconnect sase
17 Sep, 2025 sase
6 Dec, 2025 sase cloud oidc oneconnect core
16 Feb, 2023 sase
6 Dec, 2025 sase cloud oidc
21 Nov, 2025 sase cloud ad
31 Jan, 2023 sase
21 Nov, 2025 sase azure cloud
4 Jul, 2025 core oneconnect oidc
4 Nov, 2024 oidc core authentication
21 Nov, 2025 oneconnect sase cloud radius
8 Jan, 2025 sase
7 Feb, 2024 sase
14 Apr, 2023 sase
25 Mar, 2025 cloud sase
21 Nov, 2025 sase cloud ad