Can you restrict a user in ASDM to only allow them to log a user out of a VPN session

We support many clients and we have found that many of them are sharing VPN credentials when logging in via AnyConnect/WebVPN. We were thinking about restricting simultaneous log in to 1. I also know that users may have situations where they lock up a session due to ISP or PC issues and won't be able to connect again until that session drops from the ASA. We would like to enable our helpdesk to log in to the ASA via ASDM and be able to logout a user that has an active connection. This would be in the logging area of the ASA where they could highlight a user and click logout. Is it possible to restrict a user to just this and not allow them to make any other changes to the ASA?

You should be able to do that. You would create a new privilege level (ie 7), assign all commands to that level except (this is my guess) the command vpn-sessiondb, you would put that at a lower privilege level (ie 6). Here's a write-up that may help getting you in the right direction.
http://www.packetpros.com/2012/08/read-only-asdm.html

Similar Messages

  • Can you edit a person from one photo and add them to another photo?

    Can you edit a person out of one photo and add them to another photo?  Like if you need the head shot from one photo to replace closed eyes in the other photo?  Thanks.

    Thank you very much!  Does this require software to be purchased?  I'm new to Photoshop. 
    From: Bill Hunt <[email protected]>
    To: Kittie Gugenheim <[email protected]>
    Sent: Monday, April 25, 2011 11:46 AM
    Subject: Re: Can you edit a person from one photo and add them to another photo?
    Welcome to the forum.
    Yes, this is done often. You will need to create a Mask of that person, to separate them from the background of the original Image.
    I like to do this with a Layer Mask, as it offers control, and really does not alter the Image, so you can go back and make changes.
    Let's say that you have Image 01 w/ the head of your subject, and want to place it into Image 02. In Image 01, make a rough Selection. I would include a bit of extra background, as we will take care of that in a moment. With that Selection active, Copy the head shot. Go to Image 02, and Paste it. It will Paste in its own Layer. Ctrl+T (Free Transform) can be used to Scale and also position that Layer with the head. Once you have that Scaled and positioned about where you want it, create a Layer Mask. In QuickMask Mode, just paint in the additional Mask to remove all traces of the background that came in with the head shot. As you can paint OUT, and also paint IN the Mask, you can work on this, as many times as you wish - even next year.
    For getting that Layer Mask looking good, work slowly, also see this http://graphicssoft.about.com/od/photoshop/l/blrbps_5agirl.htm.
    I've got another tutorial, that addresses the hair area, and will post that, when I find my bookmark.
    Good luck,
    Hunt

  • How can you pull in pdf's from iBooks and bring them into the Box app?

    How can you pull in pdf's from iBooks and bring them into the Box app?

    That sounds great, but I'm lost.
    I followed these steps:
    1) Open your PDF (in Adobe Acrobat Pro)
    2) Chose print
    The print/printer options pop-up will show.
    3) In the printer section, do not use your normal printer, a printer named Adobe PDF should be an option. Chose it.
    4) Under the "Page handling" section, change the Page Scaling drop-down menu to "Multiple pages per sheet".
    It works fine, but it looses all of the font information and the search no longer works. How can you do it and save the font info, so the search tool continues to operate.
    Am I missing anything?

  • Can you force a value into a read-only numeric data member?

    I have code that will force a value into a numeric data member. Unfortunately the numeric data member in question is read-only. Can you force a value into a read-only numeric data member?

    Andre,
    I think you should get together with the other engineers there at NI. I spoke to one on the phone yesterday and he told me that the read-only aspect relates to writing between the database and PLC. I'm trying to write to the database and he told me that I could do it.

  • Hi can you still turn off 3G and use only GPRS service on the 5s?

    Hi can you still turn off 3G and use only GPRS service on the 5s?

    Whether you have a setting to do such is determined/controlled by your carrier.

  • HT201240 This process does not appear to work for me.  I'm running 10.8.3.  I created a new user for a guest staying with me.  They have gone now and I am attempting to either change the password or delete the user.  It won't allow me to choose the user I

    This process does not appear to work for me.  I'm running 10.8.3.  I created a new user for a guest staying with me.  They have gone now and I am attempting to either change the password or delete the user.  It won't allow me to choose the user I created.  I am logged in as myself and it states that I am an "Admin".  The user I'm attempting to change is listed as a "standard" user and there is a white checkmark inside an orange circular background on the user pic in the list of users. 
    Can someone help me?  I am having a hard time believing that OSx will allow me to create users and allow them use of my computer and it's drives, yet it will not allow me to change the password so I can monitor what they might have been doing while logged on?  What if this were my child?  This guest left under sketchy circumstances, and I'd really like to be able to ensure they were not using my computer to do illegal things or to have illegal communications.
    Any help would be appreciated.  (It's odd that it was so simple to "create" a user and set a password for them.......but it's complicated or a little known process to reverse.
    Thanks.

    Here are two screen shots to show you what I am seeing.  The first screen shot shows it allowing me to select (highlighted in blue) my admin user (which is what I am locced in as).  The second screen shot shows it allowing me to select the "Guest" user (highlighted in blue).  However when I click on the user "Orion" nothing happens.  It will not change to highlight that user.

  • Global Variants- can you restrict them?

    I know that in finance you can control who has access to global variants by an authorization object.  However, with the rest of the modules (mainly PM, MM) how do you restrict the global variants so they can not be edited?

    Perhaps you would like to post your solution, so that others who use the search can benefit from it.
    (please use a few technical terms like the objects and PIDs to help the search..)
    I have a faint suspect that a rather lively discussion around the topic cannot be excluded...
    Cheers,
    Julius

  • Can you restrict or password protect podcasts?

    I would like to do a podcast but would like to be able to restrict or password protect it. Is this possible? if not are there any other options?
    Thxs.

    Yes if you have a program that allows you to set a password on the PDF file or you ZIP it with a password set on it. For that you wouild also need a ZIPping program that allows you to set a password. Adobe Acrobat does, not sure about Acrobat reader. And there may be other PD creator programs that allow a password to be set.
    But with a password set, either on the PDF or a ZIP file, the person you are sending it to would need to know the password to even open it for viewing. Maybe you are looking to Lock the PDF from being edited?

  • How can I restrict certain apps to cellular data only?

    Product Name: iPhone 6
    Product iOS: 8.3
    Background: I listen to Pandora at work through my iPhone 6. My work has pandora traffic blocked through their WiFi network. I want to keep my iPhone connected to the work WiFi because 1) I don't want to turn on and off my WiFi on my phone 2) I want to my email and other apps to use WiFi since they are not blocked.
    Current Workarounds (not a solutions):
    1) Turn off and on WiFi on iPhone 6- This is a pain/hassle and I forget to turn the WiFi back on.
    2) Switching to a different streaming music providers that aren't blocked by work WiFi- I pay for Pandora One and I like this service the best. I really don't want to switch.
    3) Download music to iPhone memory- I pay for Pandora One and I'd like to use it.
    4) Jailbreak- Not sure if this a solution but I'd rather not jailbreak my device.
    Question: How can I restrict certain apps (Pandora) to use cellular data only?
    Best Regards,
    Chasen

    The network settings in iOS are global and do not support assigning specific networks to specific apps. You cannot do what you describe.

  • Can we restrict a Procedure to be called only once in a session or package?

    Hi,
    I am having a procedure which is called for each insert statement.
    The code is non-Editable.
    So, I want to restrict the procedure to be called only once for the entire session or package.
    Could any one please suggest me, can we do this?
    Thak you,
    Regards,
    Gowtham Sen.

    Hi,
    Actually, I am using OWB tool. I used a procedure with output parameters, to map to the target table. So, OWB creates a package. In that package its calling the procedure for each record.
    So, in order to avoid that, can I do any thing else, which would restrict it to call for each record.
    Thank you,
    Regards,
    Gowtham Sen.

  • Can you set iphone alarm to phone calls only?

    when i had a blackberry you could set it to "phone calls only" in one simple step, so while you were sleeping you didn't get bothered by emails and texts, but still would hear the phone ring for emergencies.  can you set this easily on iphone with out having to uncheck all notifications etc?

    **** it!  thanks for the quick resposne...you would think for something that simple you'd be able to

  • My Iphone 3GS can no longer get ESPN Podcasts.  It only allows me to type a review.  What is happening and how can I fix it?

    My Iphone 3GS can no longer get ESPN And CBS Sports Podcasts.  They only let me place reviews of the podcasts.  This happened a week ago.  Does anyone know what happened and if there is anything I can do to fix it?

    Could be any number of things. What user trobleshooting have you tried? Restart (power off/on) reset, hold the sleep/wake and home buttons together until you see the Apple logo and then release. See if it works after the phone restarts. Next is a restore from a backup (make sure you made a current one), then restore as a new device, which deletes all data from your device. If it doesn't work after all that, then make an appointment at the Genius Bar at the local Apple store, it is probably a hardware issue.
    I have seen something similar which is generally diagnosed as a hardware issue.

  • My screen will not allow me to log in " User profile servc failed the log "

    my screen will not allow me to log in it states " User profile servce failed the log in. User profile can not load"
    This question was solved.
    View Solution.

    Hi,
    You could try the following.
    Shut down the notebook.  Tap away at f8 as you start the notebook to enter Windows Recovery Console.  Use the arrow keys to select Safe Mode and hit enter.  If windows will load in this mode, from the Start Menu, click All Programs, click Accessories, click System Tools and launch System Restore.  Pick a restore point at least 24 hours before the log-on issue and then proceed with the restore process.  When complete, Windows will reboot as normal so check if you can now log in correctly.
    Another option if the above does not help is as follows.
    Shut down the notebook.  Tap away at f8 as you start the notebook to enter Windows Recovery Console.  Use the arrow keys to select 'Start Using Last Known Good Configuration' and hit enter.
    Regards,
    DP-K
    ****Click the White thumb to say thanks****
    ****Please mark Accept As Solution if it solves your problem****
    ****I don't work for HP****
    Microsoft MVP - Windows Experience

  • How can i fix my laptop. It does not allow me to log in.

    I have a problem with my macbook. It does not allow me to log in. What can I do to resolve this problem?

    Knowledge46 wrote:
    I have a problem with my macbook. It does not allow me to log in.
    Can you describe exactly what happens and any messages you get when you attempt to log in?
    cornelius

  • Can you restrict APEX users to a single browser session?

    I'm using APEX3.2.1
    Is there a package,function, view or table in APEX that can be checked to see if a user_id
    already has an active session (one that hasn't been purged yet).
    I wish to restrict each user to a single active browser session.
    Cheers
    dfrost

    Hi Roel
    I've had a look at the views and it looks to be exactly what I'm after thanks very much for your help.
    I've only been working on APEX a short while the info on the forum and all the expert blogs are of huge help.
    Thanks
    Derek
    Australia

Maybe you are looking for