cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
247
Views
0
Helpful
5
Replies
Beginner

Different login scripts for different anyconnect profile/policy?

Hi,

 

Wonder if the ASA/FTD with Anyconnect can apply different login scripts to different anyconnect profiles/policies?

 

Say I have a windows login script added on the firewall. I want to associate this script with corp users only when they login to anyconnect VPN using "vpn.company.com" and not pushing the script to contractors when they login to VPN using "vpn.company.com/contractors".

 

I actually disabled the Scripting in the contractor Anyconnect profile but the same script is still pushed down to the contractor's laptop...

 

Thanks,

/S

5 REPLIES 5
VIP Advisor

Re: Different login scripts for different anyconnect profile/policy?

Hi

FTD doesn't support login script. You can't push them through FTD.

With ASA, execution of scripts is based on the anyconnect profile which is linked to a a group policy.
How do you authenticate your users?

Let's assume you use a radius server. When a corporate user connects you can assign them to the group policy that has an anyconnect profile running scripts whereas if a non corporate user connects, you assign them an another group policy with an anyconnect profile that doesn't have scripting configured.

Does that make sense?

Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question
Beginner

Re: Different login scripts for different anyconnect profile/policy?

This does make sense... so the bottom line is everyone will download the script after connecting anyconnect but execution is controlled by profile.

I was not aware that scrip is not supported on FTD, even 6.4.0.1 code?
VIP Advisor

Re: Different login scripts for different anyconnect profile/policy?

Yes quite sure it's not. There's no way you can push the script from ftd itself.
If you push scripts through another way, you can import the anyconnect xml profile into ftd to be delivered to clients and this script has to be done out of ftd using profile editor. Then the script could run.

Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question
Beginner

Re: Different login scripts for different anyconnect profile/policy?

Thanks, I certainly would like to give that a try...
VIP Advisor

Re: Different login scripts for different anyconnect profile/policy?

Ok no pb let me know if you need help

Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question