10-22-2024 01:19 PM - edited 10-22-2024 01:25 PM
I was unable to use the migration tool so had to configure manually. Now I am in a situation where I only have one tunnel group showing on the anyconnect drop down as seen below.
I should have three other tunnel groups showing here. How do I configure these within FMC and what configuration should I be paying close attention to from the old ASA I have migrated from?
Also do I need to run through the RAVPN wizard for each tunnel group I want to add?
Do you create a new connection profile or add additional alias's to the already create profile?
Solved! Go to Solution.
10-23-2024 01:38 AM
You would need to configure a secondary authentication server under the connection profile.
10-22-2024 01:26 PM
@NetworkMonkey101 check your connection profiles and ensure the alias is enabled for the other connection profiles.
Ensure that Allow Users to select connection profile while logging in is selected.
Choose Devices > VPN > Remote Access.
Select the following under Access Settings:
Allow Users to select connection profile while logging in—If you have multiple connection profiles, selecting this option allows the user to select the correct connection profile during login.
10-22-2024 01:27 PM - edited 10-22-2024 01:29 PM
Should I have a separate connection profile for each tunnel group? and then set the Alias within it...?
this is ticked
10-22-2024 01:30 PM
@NetworkMonkey101 yes you define an alias for each.
10-22-2024 02:32 PM
Thanks I can now see the different drop down options for each profile/alias.
On the old anyconnect connection when I select the portal profile it asks me for two passwords how do I set these settings?
When I select portal_no_split tunnel it should also be two passwords but split tunnel disabled. How do I amend that for this profile?
When I select Radio it should ask for a single password as seen below
And finally when I select BMS it should ask for a username and password and second username and password
How are these profiles amended for this, I have the old ASA configuration file to review but unsure what is missing.
10-22-2024 11:43 PM
@NetworkMonkey101 these settings (authentication method, AAA server and split tunneling) are configured under the respective connection profile.
10-23-2024 01:38 AM
You would need to configure a secondary authentication server under the connection profile.
10-23-2024 01:40 AM
Thanks for your reply, I have configured the secondary server as suggested. How does each profile differentiate from the sign in options such as second username/password or just second password, is that pushed by the server?
10-23-2024 01:49 AM
The Firewall and Authentication server work together. It is the Firewall that prompts for authentication, but the backend authentication server must also accept the authentication request being passed from the Firewall.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide