cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
646
Views
0
Helpful
1
Replies
Highlighted
Beginner

AnyConnect and AD machine auth

We are running ASA 5550's, version 8.0(5), and are using the AnyConnect client, version 2.5.0217.

We have several different VPN groups created, but we have the need on one of the VPN groups to limit access to only machines that are members of our Corporate Active Directory domain.  So we need to check not only the username and password, but we also need to check the local machine for domain membership.

We would like to query the machine and then query AD to verify membership natively, as we are not using certificates.

We also have Ciscosecure ACS servers tied in to AD, if they need to be part of this solution.

Is anyone else doing this, and if so, can you point me in the right direction?

TIA

Daniel

1 REPLY 1
Highlighted
Rising star

To my knowledge, you can enable both AAA and cert for authentication and use machine cert for machine authentication accordingly.

I don't think you can do what you mentioned "We would like to query the machine and then query AD to verify membership natively" without using certificate.