cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3005
Views
0
Helpful
4
Replies

Umbrella package and certificate

skywalker_007
Spotlight
Spotlight

We have anyconnect vpn software on all client machines connecting to a central site having ASAv.

 

The client machines are mix of windows and Mac OS.

Customer has purchased umbrella advantage .

 

Goal is to distribute modulen package, config  and root certificate to all clients .

There is no sccm .

But there's is airwave. Do we have a guide how to do it ?

 

Can we do it directly from ASAv the moment user connect next time to vpn? 

 

There should be a standard procedure for all client types like windows macos

 

2 Accepted Solutions

Accepted Solutions

takiadeen
Level 1
Level 1

With ASA AnyConnect you can enable pushing the Umbrella module as well the deployment of OrgInfo.json file to the AnyConnect clients. For Certificates I believe it won't be possible to do it through the ASA and you will need to deploy it yourself. 

For Umbrella module
1- upload the OrgInfo.json (if required to be installed) to disk of the ASA. 
2- the configuration under webvpn 

 

Webvpn
anyconnect profiles orginfo disk0:/OrgInfo.json
exit

 

3- Enable the Umbrella module for the anyconnect group policy

group-policy <Group_Policy_Name> attribute
    webvpn
        anyconnect profiles value orginfo type umbrella
        anyconnect modules value Umbrella 

 

 

For more info you can check umbrella documentation
https://docs.umbrella.com/deployment-umbrella/docs/the-anyconnect-plugin-umbrella-roaming-security-client-administrator-guide#update

View solution in original post

Thank you . This is clear now 

View solution in original post

4 Replies 4

ToucanzooX
Level 1
Level 1

Hello, you can not do this directly from the ASA at the moment.

takiadeen
Level 1
Level 1

With ASA AnyConnect you can enable pushing the Umbrella module as well the deployment of OrgInfo.json file to the AnyConnect clients. For Certificates I believe it won't be possible to do it through the ASA and you will need to deploy it yourself. 

For Umbrella module
1- upload the OrgInfo.json (if required to be installed) to disk of the ASA. 
2- the configuration under webvpn 

 

Webvpn
anyconnect profiles orginfo disk0:/OrgInfo.json
exit

 

3- Enable the Umbrella module for the anyconnect group policy

group-policy <Group_Policy_Name> attribute
    webvpn
        anyconnect profiles value orginfo type umbrella
        anyconnect modules value Umbrella 

 

 

For more info you can check umbrella documentation
https://docs.umbrella.com/deployment-umbrella/docs/the-anyconnect-plugin-umbrella-roaming-security-client-administrator-guide#update

Thank you . This is clear now 

Marvin Rhoads
Hall of Fame
Hall of Fame

@takiadeen 's solution takes care of the AnyConnet module plus required OrgInfo.json.

The Umbrella root certificate can be pushed via GPO.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: