<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Set up AnyConnect using AD from outside interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/set-up-anyconnect-using-ad-from-outside-interface/m-p/4611869#M1090147</link>
    <description>&lt;P&gt;try this way&lt;BR /&gt;I think that the any connect traffic not allow to pass through S2S VPN&lt;BR /&gt;In Site-2 S2S VPN&amp;nbsp;&lt;/P&gt;&lt;P&gt;S2S VPN ACL must be include&amp;nbsp;&lt;BR /&gt;access-list VPN-POOL AD-SUBNET&lt;/P&gt;</description>
    <pubDate>Tue, 17 May 2022 19:04:57 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2022-05-17T19:04:57Z</dc:date>
    <item>
      <title>Set up AnyConnect using AD from outside interface</title>
      <link>https://community.cisco.com/t5/network-security/set-up-anyconnect-using-ad-from-outside-interface/m-p/4611821#M1090143</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have two site as below. Site 2 is the backup of site1. They connect via site to site vpn tunnel. LAN-1 and LAN-2 can talk with each other well.&lt;/P&gt;&lt;P&gt;I set up AnyConnect for Site 1, AAA is from Microsoft AD at LAN-1. It works well.&lt;/P&gt;&lt;P&gt;Now I am trying to setup&amp;nbsp;AnyConnect for Site 2 (on Firewall-2):&lt;/P&gt;&lt;P&gt;- I also use the AD of site1 as AAA. It is not working now.&lt;/P&gt;&lt;P&gt;- I can receive the window pop up asking for username and password, but when I enter the credential, it freeze for a minute and ask me the username and password again.&lt;/P&gt;&lt;P&gt;- It looks like the Firewall-2 could not reach the AD.&lt;/P&gt;&lt;P&gt;- LAN-2 can reach AD well, so I am not sure what to check, set up to make it work.&lt;/P&gt;&lt;P&gt;Please advise&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JFK-Anyconnect.jpg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/151415iA5E66242FF32C668/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JFK-Anyconnect.jpg" alt="JFK-Anyconnect.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Note: both firewall are FTD 2100. I use FMC to set them up.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Loc&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2022 17:39:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/set-up-anyconnect-using-ad-from-outside-interface/m-p/4611821#M1090143</guid>
      <dc:creator>loc.nguyen</dc:creator>
      <dc:date>2022-05-17T17:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: Set up AnyConnect using AD from outside interface</title>
      <link>https://community.cisco.com/t5/network-security/set-up-anyconnect-using-ad-from-outside-interface/m-p/4611869#M1090147</link>
      <description>&lt;P&gt;try this way&lt;BR /&gt;I think that the any connect traffic not allow to pass through S2S VPN&lt;BR /&gt;In Site-2 S2S VPN&amp;nbsp;&lt;/P&gt;&lt;P&gt;S2S VPN ACL must be include&amp;nbsp;&lt;BR /&gt;access-list VPN-POOL AD-SUBNET&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2022 19:04:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/set-up-anyconnect-using-ad-from-outside-interface/m-p/4611869#M1090147</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-05-17T19:04:57Z</dc:date>
    </item>
    <item>
      <title>Re: Set up AnyConnect using AD from outside interface</title>
      <link>https://community.cisco.com/t5/network-security/set-up-anyconnect-using-ad-from-outside-interface/m-p/4612122#M1090169</link>
      <description>&lt;P&gt;in my understanding, the problem is that the firewall 2 cannot pass through the S2S VPN to check AD credentials from firewall 1 network.&lt;/P&gt;&lt;P&gt;i think the best thing to do is add your LAN1 subnet in firewall 2 S2S VPN config and also add your LAN2 subnet in firewall 1 config so that both firewalls can see what ip addresses and subnets that are being used on each other side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;have you tried pinging the ip address of your AD from your Firewall 2 and/or LAN2?&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 06:53:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/set-up-anyconnect-using-ad-from-outside-interface/m-p/4612122#M1090169</guid>
      <dc:creator>Tritontek</dc:creator>
      <dc:date>2022-05-18T06:53:38Z</dc:date>
    </item>
    <item>
      <title>Re: Set up AnyConnect using AD from outside interface</title>
      <link>https://community.cisco.com/t5/network-security/set-up-anyconnect-using-ad-from-outside-interface/m-p/4612449#M1090184</link>
      <description>&lt;P&gt;are you using realms on your FMC? check your ldap attributes are pointing to the correct CN and OU on your AD. try pinging the IP of your AD from your Firewall 2 CLI via SSH.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also in your CLI via SSH of your firewall 2 try this command:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;test aaa-server authentication (Your Realms Name) host (Your AD IP Address)&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 15:02:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/set-up-anyconnect-using-ad-from-outside-interface/m-p/4612449#M1090184</guid>
      <dc:creator>Herald Sison</dc:creator>
      <dc:date>2022-05-18T15:02:51Z</dc:date>
    </item>
  </channel>
</rss>

