11-26-2018 08:14 PM - edited 02-21-2020 09:31 PM
Hi All,
We have a simple Anyconnect structure in our environment where Anyconnect users are getting authenticated against AD for registered laptops. However, recently we could see some of our employees are trying to access our internal networks via Anyconnect on unregistered BYODs; so far none have been successful. So here are my queries:
1) Is it possible to access internal networks via Anyconnect on unregistered BYODs? If yes, how? And what are the workarounds for it?
2) What are some of the best MFA mechanisms which can be used with Anyconnect in the market today?
11-26-2018 08:44 PM
check this post:
can use symantec VIP, Duo and a few others
11-27-2018 03:53 AM
Are you talking about AnyConnect Network Access Module (NAM) vs the VPN client?
11-28-2018 10:55 AM
1) AnyConnect, by default, does not restrict which device a user can connect from. If you want to restrict AnyConnect to only corporate machines, you can use the Hostscan/DAP/Posture functionality to only allow Domain machines to connect successfully.
Example:
2) I think @Dennis Mink mentioned a few of them. Duo is now part of Cisco, and works well in my experience. Example guide are here:
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide