02-09-2009 10:39 AM - edited 02-21-2020 03:16 AM
I was wondering if there is a setting on the ASA that will prevent the AnyConnect client from saving and displaying the username that was last used to create a VPN connection. I was originally going to force the end user to re-install the AnyConnect client for each connection, but this makes the connection time that much longer...
02-18-2009 03:50 PM
If you use local authentication (the default), you must define user names and passwords in the local database for user authentication.
http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00808efbd2.shtml#comm
02-19-2009 07:50 AM
I'm not sure how your comment applies to my question. We do not use local authentication. These particular connections are authenticated through Cisco ACS. I'm trying to find the mechanism that saves the password in the username field of the AnyConnect Client on the remote host.
02-19-2009 08:17 AM
I am not sure if there is such thing as to enable the AnyConnect to avoid displaying the username, there is a save password option on the group-policy you can try to disable that and see if it makes a difference but I don't think it will help, a more drastic solution will be to have AnyConnect client removed everytime the user logs out.
02-19-2009 08:31 AM
From your description sounds more like a cached credential on the PC, than the ASA keeping the user information in your browser.
Attachment Keywords
1) IE AutoComplete.bmp - IE Auto Complete Forms
Are you downloading a User Profile?
An AnyConnect client profile is a group of configuration parameters, stored in an XML file, that the client uses to configure the connection entries that appear in the client user interface. The client parameters (XML tags) include the names and addresses of host computers and settings to enable additional client features.
02-19-2009 08:45 AM
You have tweaked my memory and I previously did find the username in the .XML file that downloads to the host machine under the current user profile. We don't use a "User Profile" per say, but the ASA probably uses the default Connection Profile for this. Maybe I can create a User Profile that will not cache the username...thanks for the info!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide