cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
805
Views
3
Helpful
8
Replies

How to create additional tunnel groups for RAVPN on FTD

I was unable to use the migration tool so had to configure manually. Now I am in a situation where I only have one tunnel group showing on the anyconnect drop down as seen below.

NetworkMonkey101_0-1729628300131.png

I should have three other tunnel groups showing here. How do I configure these within FMC and what configuration should I be paying close attention to from the old ASA I have migrated from?

Also do I need to run through the RAVPN wizard for each tunnel group I want to add?

Do you create a new connection profile or add additional alias's to the already create profile?

NetworkMonkey101_0-1729628719775.png

 

 

1 Accepted Solution

Accepted Solutions

You would need to configure a secondary authentication server under the connection profile.

Screenshot 2024-10-23 at 10.37.04.png

--
Please remember to select a correct answer and rate helpful posts

View solution in original post

8 Replies 8

@NetworkMonkey101 check your connection profiles and ensure the alias is enabled for the other connection profiles.

https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/740/management-center-device-config-74/vpn-remote-access.html#task_pvz_m35_5gb

Ensure that Allow Users to select connection profile while logging in is selected.

Choose Devices > VPN > Remote Access.

Select the following under Access Settings:

  • Allow Users to select connection profile while logging in—If you have multiple connection profiles, selecting this option allows the user to select the correct connection profile during login.

https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/740/management-center-device-config-74/vpn-remote-access.html#id_49114

 

Should I have a separate connection profile for each tunnel group? and then set the Alias within it...?

this is ticked

NetworkMonkey101_0-1729628978663.png

 

@NetworkMonkey101 yes you define an alias for each.

Thanks I can now see the different drop down options for each profile/alias. 

On the old anyconnect connection when I select the portal profile it asks me for two passwords how do I set these settings?

NetworkMonkey101_0-1729632481606.png

When I select portal_no_split tunnel it should also be two passwords but split tunnel disabled. How do I amend that for this profile?

When I select Radio it should ask for a single password as seen below

NetworkMonkey101_1-1729632683561.png

 

And finally when I select BMS it should ask for a username and password and second username and password

NetworkMonkey101_2-1729632734993.png

 

 

How are these profiles amended for this, I have the old ASA configuration file to review but unsure what is missing.

You would need to configure a secondary authentication server under the connection profile.

Screenshot 2024-10-23 at 10.37.04.png

--
Please remember to select a correct answer and rate helpful posts

Thanks for your reply, I have configured the secondary server as suggested. How does each profile differentiate from the sign in options such as second username/password or just second password, is that pushed by the server?

The Firewall and Authentication server work together.  It is the Firewall that prompts for authentication, but the backend authentication server must also accept the authentication request being passed from the Firewall.

--
Please remember to select a correct answer and rate helpful posts
Review Cisco Networking for a $25 gift card