07-11-2023 03:56 AM
Hi, I have the Anyconnect management tunnel feature configured on FMC/FTD which is working as expected:
- Mgmt tunnel establishes before user logins into Windows
- After Windows login, mgmt tunnel remains up, but disconnects when the user tunnel is established
Is there a way to only have the mgmt tunnel establish before the user logs into Windows i.e. once the user logs into Windows the mgmt tunnel won't establish, even if the user tunnel is not connected?
Thanks
Solved! Go to Solution.
07-11-2023 12:49 PM
I think you can achieve that by relying on TND (Trusted Network Detection) but that would only work when the clients are on the corporate network. However, if you are trying to do that for the users located out of the corporate network then I don't believe that is possible.
07-11-2023 05:32 PM
Yeah, what Aref said, the definition of Management tunnel is to stay active as long as there is no user tunnel. We can't have management tunnel before the user logs in and then no management tunnel after the user logs in.
07-11-2023 12:49 PM
I think you can achieve that by relying on TND (Trusted Network Detection) but that would only work when the clients are on the corporate network. However, if you are trying to do that for the users located out of the corporate network then I don't believe that is possible.
07-11-2023 05:32 PM
Yeah, what Aref said, the definition of Management tunnel is to stay active as long as there is no user tunnel. We can't have management tunnel before the user logs in and then no management tunnel after the user logs in.
07-12-2023 01:07 AM
I thought that would be the case, but just wanted to double check that my understanding was correct and I wasn't missing anything.
I appreciate you both taking the time to reply.
Thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide