Lab 1.3: Create a new VPN Access profile

Note

Estimated time to complete: 25 minutes

Lab environment access

If you have not yet visited the page Getting Started, please do so.

Tasks

  • Navigate to ConfigurationAccessAccess Groups
  • Select BostonAG

image24

You can see all of the access policies listed in the Per Session Policies:

image25

Click Create and you will see the Access Policy creation screen. Give it a name of “VPN-AP” and click on Save & Close. You can change the view from Basic -> Advanced if you want to modify additional settings such as timeouts, SSO, logout URI, etc..

image26

Then click “New” in macros and select “AD Auth and resources” template. Then click the “OK” button.

image27

Click on the AD Auth object and use the Server drop down to select FrogPolicy-olympus-ad then click Save.

image28 image29

Now click the Resource Assign object. In the pop up window click the Add button. Expand the Network Access section and move the /Common/FrogPolicy-F5_VPN from the Available section to the Selected section and click the Save button.

image30

The result will look like the picture below, click the Save button on this screen.

image31

Then add the macro into the VPE by hovering mouse over blue line and selecting the Green plus sign. Then change the ending on the “Successful” branch to Allow. Then click Save buttons to complete.

image32image33

image34

After creating and saving the access profile, go to “Deployment - > Evaluate & Deploy -> Access”.

Click on “Create” in Evaluations, give it a name, and select BOS-vBIGIP01/02 devices.

image35

Click on View after the evaluation is done to view the changes in Green.

image36

image37

Then Click on Deploy and verify the new VPN Access Profile is pushed onto the BIG-IP device BOS01.

image38

image39