<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AnyConnect SSL VPN in VPN</title>
    <link>https://community.cisco.com/t5/vpn/anyconnect-ssl-vpn/m-p/3715430#M146753</link>
    <description>&lt;P&gt;Hi guys,&lt;/P&gt;
&lt;P&gt;My VPN is using cert based authentication but we just found out that even non-corporate devices can still connect to the VPN by not checking the "Block Untrusted Servers" in the AnyConnect settings. Is it possible to block those non-corporate devices to connect to the VPN by using certificate alone?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it possible to block those 3rd party certificate right away?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Sat, 22 Feb 2020 05:28:24 GMT</pubDate>
    <dc:creator>fatalXerror</dc:creator>
    <dc:date>2020-02-22T05:28:24Z</dc:date>
    <item>
      <title>AnyConnect SSL VPN</title>
      <link>https://community.cisco.com/t5/vpn/anyconnect-ssl-vpn/m-p/3715430#M146753</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;
&lt;P&gt;My VPN is using cert based authentication but we just found out that even non-corporate devices can still connect to the VPN by not checking the "Block Untrusted Servers" in the AnyConnect settings. Is it possible to block those non-corporate devices to connect to the VPN by using certificate alone?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it possible to block those 3rd party certificate right away?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 22 Feb 2020 05:28:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/anyconnect-ssl-vpn/m-p/3715430#M146753</guid>
      <dc:creator>fatalXerror</dc:creator>
      <dc:date>2020-02-22T05:28:24Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect SSL VPN</title>
      <link>https://community.cisco.com/t5/vpn/anyconnect-ssl-vpn/m-p/3715442#M146754</link>
      <description>&lt;P&gt;I think you are mixing up the certificate on the server (which is what the check box you mentioned covers) vs. a certificate on the clients.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Certificate-based client authentication requires the actual certificate and private key to be present on the client. While it's possible (in most cases) to copy the client certificate to another device it's much more involved than unchecking a checkbox.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Confirm your authentication type via the command:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;show run tunnel-group&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The output should include a subcommand indicating the type of authentication being used.&lt;/P&gt;</description>
      <pubDate>Sat, 29 Sep 2018 07:14:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/anyconnect-ssl-vpn/m-p/3715442#M146754</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-09-29T07:14:27Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect SSL VPN</title>
      <link>https://community.cisco.com/t5/vpn/anyconnect-ssl-vpn/m-p/3715444#M146755</link>
      <description>&lt;P&gt;Yes, this is possible, But depends on how you configured, check the below configuration to help you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-blogs/anyconnect-certificate-based-authentication/ba-p/3105546" target="_blank"&gt;https://community.cisco.com/t5/security-blogs/anyconnect-certificate-based-authentication/ba-p/3105546&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How is the certificate installed to devices, is this pre-defined certificate as part of build ?&lt;/P&gt;</description>
      <pubDate>Sat, 29 Sep 2018 07:21:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/anyconnect-ssl-vpn/m-p/3715444#M146755</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2018-09-29T07:21:48Z</dc:date>
    </item>
  </channel>
</rss>

