<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SBL allowing users to connect without authentication in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sbl-allowing-users-to-connect-without-authentication/m-p/4957052#M1105733</link>
    <description>&lt;P&gt;Some sort of authentication must be happening - it could be transparent to the end user depending on the system settings (for example, using certificate or some sort of SSO method).&lt;/P&gt;
&lt;P&gt;Check your headend firewall and/or AAA server to see what it says about that in the logs and configuration.&lt;/P&gt;</description>
    <pubDate>Fri, 10 Nov 2023 16:27:37 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2023-11-10T16:27:37Z</dc:date>
    <item>
      <title>SBL allowing users to connect without authentication</title>
      <link>https://community.cisco.com/t5/network-security/sbl-allowing-users-to-connect-without-authentication/m-p/4956940#M1105727</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I am in the process of rolling out SBL and in the testing I realised that it works perfectly from the device logon screen. However, once I am logged in to the device, if I choose the SBL option from the Cisco AnyConnect dropdown list, I can connect to the VPN without any form of authentication...&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to configure this so that the SBL function is only available from the logon screen, or similarly the XML profile self-destructs after the first login to the device?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2023 13:17:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sbl-allowing-users-to-connect-without-authentication/m-p/4956940#M1105727</guid>
      <dc:creator>joemrris1</dc:creator>
      <dc:date>2023-11-10T13:17:54Z</dc:date>
    </item>
    <item>
      <title>Re: SBL allowing users to connect without authentication</title>
      <link>https://community.cisco.com/t5/network-security/sbl-allowing-users-to-connect-without-authentication/m-p/4957052#M1105733</link>
      <description>&lt;P&gt;Some sort of authentication must be happening - it could be transparent to the end user depending on the system settings (for example, using certificate or some sort of SSO method).&lt;/P&gt;
&lt;P&gt;Check your headend firewall and/or AAA server to see what it says about that in the logs and configuration.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2023 16:27:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sbl-allowing-users-to-connect-without-authentication/m-p/4957052#M1105733</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2023-11-10T16:27:37Z</dc:date>
    </item>
    <item>
      <title>Re: SBL allowing users to connect without authentication</title>
      <link>https://community.cisco.com/t5/network-security/sbl-allowing-users-to-connect-without-authentication/m-p/4957053#M1105734</link>
      <description>&lt;P&gt;Thanks for the reply Marvin, you are right there is authentication happening, probably my poor wording!&amp;nbsp;&lt;/P&gt;&lt;P&gt;My test device as an example... that has the SBL cert installed as well as the SBL XML profile. So i guess the cert is the authentication, however is there a way to configure it so that the authentication is required manually from the user? We have MFA for Cisco configured which works perfectly, but if a user chooses the SBL option from the dropdown then they can connect to the VPN without any form of MFA / password / manual authentication. This is exactly how we want it from the logon screen, but not once the device is logged in to.&lt;/P&gt;&lt;P&gt;Hopefully that explains it a bit better &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2023 16:32:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sbl-allowing-users-to-connect-without-authentication/m-p/4957053#M1105734</guid>
      <dc:creator>joemrris1</dc:creator>
      <dc:date>2023-11-10T16:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: SBL allowing users to connect without authentication</title>
      <link>https://community.cisco.com/t5/network-security/sbl-allowing-users-to-connect-without-authentication/m-p/4957077#M1105738</link>
      <description>&lt;P&gt;Ah ok. It sounds like you have SBL published as a selectable URL connection profile (tunnel-group). You could hide that but embed it in the client profile xml file so that it is automatically selected by SBL but not visible as a choice when logging on interactively.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2023 17:10:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sbl-allowing-users-to-connect-without-authentication/m-p/4957077#M1105738</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2023-11-10T17:10:30Z</dc:date>
    </item>
    <item>
      <title>Re: SBL allowing users to connect without authentication</title>
      <link>https://community.cisco.com/t5/network-security/sbl-allowing-users-to-connect-without-authentication/m-p/4973685#M1106667</link>
      <description>&lt;P&gt;Is there a way we can have SBL VPN automatically connect without login or any kind of user input (not even a laptop in laptop screen click ! ) ??&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 21:01:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sbl-allowing-users-to-connect-without-authentication/m-p/4973685#M1106667</guid>
      <dc:creator>jbhanderi671</dc:creator>
      <dc:date>2023-12-07T21:01:49Z</dc:date>
    </item>
  </channel>
</rss>

