cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
353
Views
0
Helpful
2
Replies

Anyconnect For New Imaged Machine With Users And Machine Certificate

Hi All, 

 We have an issue with the new imaged machine. Here is a brief 

- We have a users and management tunnel with user certificates for the users and machine certificates for the Mgmt tunnel 

- User tunnel auto connect when the user logs in, and of course, mgmt tunnel connects automatically when users are not logged in the window. 

- Our IT support Imaging a new laptop with a preconfigured image. The new image it automatically domain joined and has the machine certificate included by default. 

- Management tunnel connect, The user is able to log in to the machine with AD credentials. There is a connection to AD from Mgmt tunnel

- THE ISSUE IS: when the first time user login to the machine " help desk doesn't want to access the user account on corp network" , the user account don't have a user certificate. it will try to download it from AD, BUT the mgmt tunnel is disconnecting cause the user is logged in to the window now. so there will be no connection to the certificate enrollment server to pull the user certificate

I guess what will solve my issue is if there is a way we can keep mgmt tunnel connected until the user account can connect the certificate enrolment server to pull the user certificate. 

Thank you in Advance 

 

 

 

2 Replies 2

Hi @AhmedALJAWAD44875 when the user logs into the VPN this will disconnect the mgmt tunnel. Perhaps just use the machine certificate instead of the user certificate. You can specify which certificate store to use in the XML profile, use the AnyConnect Profile Editor to select this.

Yes , I was thinking the same. hopfully our security department will like the idea.. 

Review Cisco Networking for a $25 gift card