The VPN to which a user is to be terminated is sometimes known from the IKE identities attached to the user. However, to assist in connecting users to the correct AAA domain for authentication, you can use the domain-suffix command to append a domain suffix to the username. Using the default, no domain suffix, passes usernames transparently to AAA.
domain-suffix
- host1(config-ipsec-tunnel-profile)#domain-suffix
domain2