AnyConnect password
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-09-2013 01:22 AM
Hello guys,
we have ASA5510 with AnyConnect and Clientless VPN enabled on.
The authentication and authorization goes through AAA server, based on information retrieved from client's eToken.
On login page of clientless VPN I should choose an alias and enter password. The password could be anything. Literally anything.
Is there a way to disable the password request?
I've tried to remove the checkbox from Configuration -> Remote Access VPN - > Clientless SSL VPN Access -> Connection profiles -> "Allow user to select connection profile ....".
This enables DefaultWEBVPNGroup profile. Yeah, drop down menu with alias selection disappears, but I still should enter the password.
Is there a way to remove this password request?
--
Regards,
Sergey
- Labels:
-
Remote Access
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-09-2013 02:37 AM
If you don't want to use any passwords for your VPN, then you have to deploy client-certificates to your users. With these the users can also be authenticated.
--
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-09-2013 03:37 AM
Karsten, does this mean that I should add a certificate for each user?
I have few CA certificates. If user "matches" one of these certs, I let this user to try to authenticate and authorize on AAA server.
--
Regards,
Sergey
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-09-2013 03:50 AM
Yes, you can use the ASA as a CA-server (unless you run Failover where the local CA is not supported) or you use a separate CA like the one included in Windows Server. Each user/device is enrolled with a certificate. If that user connects, the ASA can be configured to don't prompt for a username/password and just let the user in.
--
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-09-2013 04:49 AM
Thanks.
I guess I get it now.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-15-2013 04:57 PM
You could check this out:
AnyConnect Certificate Based Authentication
Hope to help
Portu.
Please rate any helpful posts!
