Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
ASA version 8.4(5), AnyConnect clients, Cisco ACS 4.2I need to pass on (inbound RADIUS attribute) to ACS what tunnel-group is being used to establish a VPN session. I don't see this as an option anywhere ... does anyone know if this is possible?Than...
I want to configure ACS 4.2 to only attempt to authenticate AD authentication requests that include the domain information. Valid AD user account formats would be 'domain\userid' and 'userid@domain.xyz'. I don't want ACS to accept the request if th...
ASA 8.21Within a clientless WebVPN homepage, is there a way to open a listed link/bookmark in a new tab? When I try to do it with the browser (right click.. Open in New Tab) it simply opens the site in the current tab.Thanks!Jeff
We have an application supplied to us by a vendor that verifies connectivity by firing out an ICMP echo request to the vendors back-end server (via a routed vendor "Extranet" connection). We've observed that the ICMP echo request is sent out with a ...
I have SSL VPN Clients connecting to an ASA 5520 using RADIUS to a backend Cisco ACS. I want to support two authentication options for the clients. The first is a certificate combined with an Active Directory username & password. The second is a t...
I discovered the "Tunnel Group Name" attribute was added in ASA 8.4.3 ... see release notes.It turns out our actual problem is that ACS Windows 4.x does not recognize this new attribute.I opened a TAC case and hooked up with a great support engineer....
I was able to accomplish this in ACS 4.2. I created a Network Access Profile with a regex that matched usernames not containing a backslash. I set the allowed authentication protocols to none. Seems to work as needed.Thanks, Jeff K
I had a problem with these exact symptoms/error messages. In my case, I had a typo in an access-list name that I was passing down as a RADIUS attribute. Hope this helps others. Thanks, Jeff K