cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1203
Views
0
Helpful
3
Replies

ISE Result - Customized Error Message On AnyConnect

Phi Yim
Cisco Employee
Cisco Employee

ISE experts,

My customer has the following AuthZ rule in ISE:

If Cisco-VPN3000:CVPN3000/ASA/PIX7.x-Tunnel-Group-Name=internal + authentication is EAP-TLS, then permit.  If an employee uses AnyConnect with their personal device without a valid client certificate, the end user sees the “Certificate Validation Failure”.  Please see screen capture below.

Is it possible for ISE to have AnyConnect display another message such as: “AnyConnect has detected that this machine is out of compliance”?

AnyConnect.jpg

1 Accepted Solution

Accepted Solutions

Timothy Abbott
Cisco Employee
Cisco Employee

Unfortunately, no.  ISE doesn't play a roll in the AnyConnect messaging for VPN authentication.  If AnyConnect were doing posture assessment, then you would have the ability to customize the posture messaging to the end user.

Regards,

-Tim

View solution in original post

3 Replies 3

Timothy Abbott
Cisco Employee
Cisco Employee

Unfortunately, no.  ISE doesn't play a roll in the AnyConnect messaging for VPN authentication.  If AnyConnect were doing posture assessment, then you would have the ability to customize the posture messaging to the end user.

Regards,

-Tim

Thanks for getting back to me Tim!

lnemec
Level 4
Level 4

Hi, sure, you can customize Anyconnect client error messages on ASA via ASDM.

Regards,

Laci,.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: