<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Anyconnect 2.x, certificates and ACS 5.2 samples in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/anyconnect-2-x-certificates-and-acs-5-2-samples/m-p/1665997#M371459</link>
    <description>&lt;P&gt;Hi, I'm looking for samples about anyconnect 2.x with PKI authentication through ASA 8.x and ACS 5.2.&lt;/P&gt;&lt;P&gt;The CA could be a internal Microsoft CA.&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;rs&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 01:10:27 GMT</pubDate>
    <dc:creator>r.spiandorello</dc:creator>
    <dc:date>2019-03-11T01:10:27Z</dc:date>
    <item>
      <title>Anyconnect 2.x, certificates and ACS 5.2 samples</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-2-x-certificates-and-acs-5-2-samples/m-p/1665997#M371459</link>
      <description>&lt;P&gt;Hi, I'm looking for samples about anyconnect 2.x with PKI authentication through ASA 8.x and ACS 5.2.&lt;/P&gt;&lt;P&gt;The CA could be a internal Microsoft CA.&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;rs&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:10:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-2-x-certificates-and-acs-5-2-samples/m-p/1665997#M371459</guid>
      <dc:creator>r.spiandorello</dc:creator>
      <dc:date>2019-03-11T01:10:27Z</dc:date>
    </item>
    <item>
      <title>Anyconnect 3.0 certificates and ACS 5.2 samples</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-2-x-certificates-and-acs-5-2-samples/m-p/1665998#M371498</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi rs,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;not sure if I understand what you want to achieve. If all you want to do is certificate authentication, you don't need ACS. &lt;/P&gt;&lt;P&gt;In short:&lt;/P&gt;&lt;P&gt;- import the CA cert on the ASA &lt;/P&gt;&lt;P&gt;- configure the tunnel-group to use certificate auth &lt;/P&gt;&lt;P&gt;- make sure the connection lands on the correct tunnel-group (lots of possibilities here, but for a very basic scenario, just use the default tunnel-group).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there anything specific you need help with or are you just looking for a step by step guide?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA config guide could be a good start:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/vpngrp.html"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/vpngrp.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(I'm assuming you're using an ASA as the head end, if it's an IOS router let me know).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or is it two-factor authentication that you're after? I.e. users need to authenticate using certificate AND username/password?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hth&lt;/P&gt;&lt;P&gt;Herbert&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 09:16:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-2-x-certificates-and-acs-5-2-samples/m-p/1665998#M371498</guid>
      <dc:creator>Herbert Baerten</dc:creator>
      <dc:date>2011-06-21T09:16:29Z</dc:date>
    </item>
    <item>
      <title>Anyconnect 3.0 certificates and ACS 5.2 samples</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-2-x-certificates-and-acs-5-2-samples/m-p/1665999#M371527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Herbert, I want to use ACS 5.2, because I need to use ACS 5.2 as center of AAA for vpn remote-access users, in particular for authorization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some remote-access user groups could use ACS username/password authentication, other groups could use certificate authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, if authentication using certificate and username/password could be the solution, do you have samples ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 10:26:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-2-x-certificates-and-acs-5-2-samples/m-p/1665999#M371527</guid>
      <dc:creator>r.spiandorello</dc:creator>
      <dc:date>2011-06-21T10:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect 3.0 certificates and ACS 5.2 samples</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-2-x-certificates-and-acs-5-2-samples/m-p/1666000#M371586</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, I'm still looking for a sample&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Sep 2011 17:21:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-2-x-certificates-and-acs-5-2-samples/m-p/1666000#M371586</guid>
      <dc:creator>r.spiandorello</dc:creator>
      <dc:date>2011-09-21T17:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect 3.0 certificates and ACS 5.2 samples</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-2-x-certificates-and-acs-5-2-samples/m-p/1666001#M371632</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, I was looking for some examples but couldn't really find any basic ones.&lt;/P&gt;&lt;P&gt;Could you clarify what part you need help with?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Sep 2011 10:48:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-2-x-certificates-and-acs-5-2-samples/m-p/1666001#M371632</guid>
      <dc:creator>Herbert Baerten</dc:creator>
      <dc:date>2011-09-26T10:48:30Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect 3.0 certificates and ACS 5.2 samples</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-2-x-certificates-and-acs-5-2-samples/m-p/1666002#M371687</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, the configuration needed of the ASA is a bit unclear because I need to use radius toward the ACS 5.2, not directly to the Microsoft CA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Than I'd like to have a sample of the ASC 5.2 configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you in advance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rs&lt;/P&gt;&lt;P&gt;﻿&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Sep 2011 11:47:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-2-x-certificates-and-acs-5-2-samples/m-p/1666002#M371687</guid>
      <dc:creator>r.spiandorello</dc:creator>
      <dc:date>2011-09-26T11:47:22Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect 3.0 certificates and ACS 5.2 samples</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-2-x-certificates-and-acs-5-2-samples/m-p/1666003#M371755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;on my ASA I have:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __default_attr="plain" __jive_macro_name="code" class="jive_text_macro jive_macro_code"&gt;&lt;P&gt;aaa-server acs2 protocol radius&lt;/P&gt;&lt;P&gt;aaa-server acs2 (inside) host 10.0.0.1&lt;/P&gt;&lt;P&gt; key *****&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tunnel-group test type remote-access&lt;/P&gt;&lt;P&gt;tunnel-group test general-attributes&lt;/P&gt;&lt;P&gt; authentication-server-group acs2&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On ACS, I've just defined an AAA client with the ip address of my ASA (note, the ip address of the interface facing the ACS) with the same key (aka 'secret').&lt;/P&gt;&lt;P&gt;For ACS 5.2 specifically, I'm afraid I can't help you, but if the above doesn't help, try asking in the &lt;A __default_attr="2026" __jive_macro_name="community" _modifiedtitle="AAA, Identity and NAC" class="jive_macro jive_macro_community" modifiedtitle="AAA, Identity and NAC" title="AAA, Identity and NAC"&gt;&lt;/A&gt; forum.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hth&lt;/P&gt;&lt;P&gt;Herbert&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Sep 2011 11:52:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-2-x-certificates-and-acs-5-2-samples/m-p/1666003#M371755</guid>
      <dc:creator>Herbert Baerten</dc:creator>
      <dc:date>2011-09-26T11:52:45Z</dc:date>
    </item>
    <item>
      <title>Anyconnect 2.x, certificates and ACS 5.2 samples</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-2-x-certificates-and-acs-5-2-samples/m-p/1666004#M371804</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; In particular, I have a sample "ASA/PIX 8.x and VPN Client IPSec Authentication Using Digital Certificates with Microsoft CA Configuration Example", document 100413 and I need to place the ACS 5.2 between ASA and Microsoft CA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In particular, I need to understand how to modify the isakmp and ipsec configuration to use ACS for certificate authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rs&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Sep 2011 14:12:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-2-x-certificates-and-acs-5-2-samples/m-p/1666004#M371804</guid>
      <dc:creator>r.spiandorello</dc:creator>
      <dc:date>2011-09-27T14:12:59Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect 3.0 certificates and ACS 5.2 samples</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-2-x-certificates-and-acs-5-2-samples/m-p/1666005#M371839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, we have realized a pilot with 2-factor authentication (ASA 8.2.x, anyconnect 2.5.x, certificate + AAA) and it's running.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First of all, it's essential to populate the tunnel-group web-attributes with authentication aaa certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;About tunnel-group (connection profile) selection:&amp;nbsp; in our pilot we have test the manual selection and the map from certificate fileds.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is better to fetch it from ACS 5.2 ? How ?&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rs&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Nov 2011 13:16:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-2-x-certificates-and-acs-5-2-samples/m-p/1666005#M371839</guid>
      <dc:creator>r.spiandorello</dc:creator>
      <dc:date>2011-11-17T13:16:49Z</dc:date>
    </item>
  </channel>
</rss>

