Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hi all,Here is our scenario:We have an MX84 with AnyConnect configured to use the DDNS name of our router. This then forwards the SAML request to our Azure instance to authenticate users. This all works fine. However, we have fairly unreliable intern...
Hi All,I have multiple sites configured using various models of MX routers. At one site (lets call it base site) we have AnyConnect set up and working with the MX and using Azure as the IDP. It works a charm. However, I do not like relying on the int...
I am attempting to enable SSO for Cisco AnyConnect through Meraki using Azure AD as the Ipd.I am following this guide:AnyConnect Azure AD SAML Configuration - Cisco MerakiWhich in step 7 says to set these two values in Azure like this:If my AnyConnec...
Hi All,I have setup a client VPN connecting into an MX84 router. For the majority of users this is working absolutely fine. However, one user running windows 7 is experiencing error 741 when trying to connect. This is the error for their computer not...
Hi All,I have a network setup where there are 2 VLANs. The servers are on 118 and the clients are on 128. The server ports on the MS120 are set to trunk mode and all the other ports are access on 128. Clients connected directly into the switch work f...
Hi rhbirkelund,From my experience it simple does not fail over. I cannot say for certain if I have waited the full 10 minutes but even if that is correct it is not a very useful failover as that it too much down time.
Hi Alemabrahao,Thanks for this. I don't need them working at the same time I need it for backup purposes. So should our WAN1 connection fail VPN connections can then be made via the WAN2 interface. Is this possible? I have been in contact with Meraki...
I played around a bit more and figured it out (always the way just after you decide to post on a forum). Basically you have to register each AnyConnect instance as a separate enterprise app in Azure. Under Organisation -> Settings -> Authentication o...
Both PhilipDAth and AaronDo were correct, I needed to test it from outside my MX and I had forgotten to add teh custome port. Thank you both for you help.
@luceroc Unfortunately the short answer is no. I believe it would be possible with another layer 3 device which you could use to essentially split the traffic into what you wanted to go over the auto VPN and what don't want to. I haven't tested this ...