cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
843
Views
10
Helpful
5
Replies

AnyConnect Fallback Authentication

RGIE3779
Level 1
Level 1

Hello CSC,

I have an AC setup where the initial authentication is done via certificate with the username being pulled from UPN. This is then checked / authorised against ISE/AD with ISE saying YES or NO

Is there a way to force a fallback method to say a simple username/password against LDAP server based my setup if an end device doesn't have a valid certificate? The end devices are locked down so it is difficult to get them to manually point to somewhere else.I see under the connection profile / general there is "use LOCAL if server group fails" but don't think this is what I'm looking for.

 

1 Accepted Solution

Accepted Solutions

@RGIE3779 no, you'd have to create another connection profile/tunnel-group that uses LDAP authentication. The users would have to manually select that connection profile, the downside is the user may just continue to use that connection profile instead of certificates.

 

View solution in original post

5 Replies 5

@RGIE3779 no, you'd have to create another connection profile/tunnel-group that uses LDAP authentication. The users would have to manually select that connection profile, the downside is the user may just continue to use that connection profile instead of certificates.

 

Thanks Rob, yes this is what I thought would be the only option the more I thought about it. Thank for the information.

Thought I'd lost my old CSC account.... Turns out I haven't. Sorry for the confusion :-). I had been trying to change my email address on here. Anyways, thanks again @Rob Ingram 

I wouldn't be able to have "Always On" with this I'd assume?