cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
338
Views
10
Helpful
5
Replies

AnyConnect Fallback Authentication

RGIE3779
Beginner
Beginner

Hello CSC,

I have an AC setup where the initial authentication is done via certificate with the username being pulled from UPN. This is then checked / authorised against ISE/AD with ISE saying YES or NO

Is there a way to force a fallback method to say a simple username/password against LDAP server based my setup if an end device doesn't have a valid certificate? The end devices are locked down so it is difficult to get them to manually point to somewhere else.I see under the connection profile / general there is "use LOCAL if server group fails" but don't think this is what I'm looking for.

 

1 Accepted Solution

Accepted Solutions

Rob Ingram
VIP Master VIP Master
VIP Master

@RGIE3779 no, you'd have to create another connection profile/tunnel-group that uses LDAP authentication. The users would have to manually select that connection profile, the downside is the user may just continue to use that connection profile instead of certificates.

 

View solution in original post

5 Replies 5

Rob Ingram
VIP Master VIP Master
VIP Master

@RGIE3779 no, you'd have to create another connection profile/tunnel-group that uses LDAP authentication. The users would have to manually select that connection profile, the downside is the user may just continue to use that connection profile instead of certificates.

 

GRANT3779
Frequent Contributor
Frequent Contributor

Thanks Rob, yes this is what I thought would be the only option the more I thought about it. Thank for the information.

GRANT3779
Frequent Contributor
Frequent Contributor

Thought I'd lost my old CSC account.... Turns out I haven't. Sorry for the confusion :-). I had been trying to change my email address on here. Anyways, thanks again @Rob Ingram 

I wouldn't be able to have "Always On" with this I'd assume?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers