Anyconnect client authentication via RSA & yubikey on the ASA at the same time - how to configure the ASA, that the correct Connection profile is selected.
we currently use RSA SecurID tokens & client certificates for authentication in the vpn connection. Is there a possibility to use an additional authentication methods in an additional connection profile? Background of the question is that the RSA tokens should be replaced by yubikeys and for the time of the transition both rsa and yubikeys should be used with the ASA, The aaa server for the rsa is different from the aaa server (Duo) for the yubikeys. How to make the ASA choose the correct connection profile (the one with RSA or the one with yubikey)? It would be OK, if the user selects at his Anyconnect Client drop down menu, what client connection profile to use, eg. company_RSA or company_yubikey. Unfortunately the asa always goes for the connection profile (tunnel group) with rsa authentication, no matter what is selected in Anyconnect. (I guess first match first serve is the reason for that.)
So what i want to ask is how the ASA decides what connection profile (tunnel group) is used? If needed, i can provide some configs from the ASA.
There are about 20 connection profiles, 1 for each department of our company. The client presents a certificate to the ASA. So the ASA knows the connection profile that should be used for that client. All clients use the same url: https.//company.com/anyconnect.
My idea was to use an additional url: https.//company.com/yubikey. So if the end user selects this in the drop down menu of the anyconnect client, the ASA use the correct profile for authentication against DUO. But it doesn't work as expected. Maybe i missed something in the config.
What is SecureX?
Cisco SecureX is included with all Secure Endpoint (formerly AMP for Endpoints) subscriptions. SecureX is a cloud-native platform that aggregates capabilities across your security environment. It’s designed to simplify your environment, ...
Cisco ISE Secure Wired Access Prescriptive Deployment Guide
Authors: Hariprasad Holla (until June 2018), Mahesh Nagireddy (until Dec 2018)
For an offline or printed copy of this document, simply choose ⋮ Options > Printer ...
Meet the Authors Slides- SecureX and the Evolution of Security Orchestration Automation and Response
(Live event – Wednesday, 20th, 2021 at 10:00 a.m. Pacific / 1:00 p.m. Eastern / 6:00 p.m. Paris)
This event had place on Wednesday 20th, January 202...
The following guide goes over the in and out of the Cisco Endpoints Security Analytics Dashboard as an overview and faq page
For more information on the product offering, licensing, support, and how to solution (TAC) guide links and more please visit the...
Join us live on Tuesday, January 19 at 10:00 am PT (and on demand after) as we discuss the latest version of ATT&CK and the expansion of TTPs in v8.
As a security expert, you are tasked with protecting your environment. You see the value of...