cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2897
Views
15
Helpful
8
Replies

Anyconnect SBL for Firepower 1140

kapydan88
Level 4
Level 4

Hello for everybody.

 

Is there anyconnect start before logon in firepower 1140 devices managed by fmc? 

1 Accepted Solution

Accepted Solutions

Josue Brenes
Cisco Employee
Cisco Employee

Hi Kapydan88,

I agree with Rob’ reply, the FTD does not work the same way the ASA does for the modules deployment.

However, as a solution for this, the SBL’s module which is named “vpngina” can be enabled on the FTD/FMC by using FlexConfig.

See the following link under “Configure AnyConnect Modules and Profiles Using FlexConfig”:

https://www.cisco.com/c/en/us/td/docs/security/firepower/config_examples/advanced-anyconnect-ftd-fmc/advanced-anyconnect-vpn-ftd-fmc.html

 

Rate if it helps.

 

Regards,

Josue Brenes

TAC - VPN Engineer.

View solution in original post

8 Replies 8

Hi,
If you pre-deploy the GINA module and AnyConnect profile using your software management solution (such as SCCM) to the client computer, SBL will work when connecting to an FTD.

FTD/FMC just doesn't support the deployment of the SBL module, as the ASA currently does.

HTH

Yes, i couldnt find any info about this feature for Firepower 1140 - only for ASA.

 

To get GINA, i need to download the predeploy archive for Windows, unpack it and select the necessary file?

 

 

Yes, If you wish to pre-deploy. download the pre-deploy zip file e.g. "anyconnect-win-4.8.01090-predeploy-k9.zip" and uncompress the files, you will see the msi file "anyconnect-win-4.8.03036-gina-predeploy-k9.msi".

Josue Brenes
Cisco Employee
Cisco Employee

Hi Kapydan88,

I agree with Rob’ reply, the FTD does not work the same way the ASA does for the modules deployment.

However, as a solution for this, the SBL’s module which is named “vpngina” can be enabled on the FTD/FMC by using FlexConfig.

See the following link under “Configure AnyConnect Modules and Profiles Using FlexConfig”:

https://www.cisco.com/c/en/us/td/docs/security/firepower/config_examples/advanced-anyconnect-ftd-fmc/advanced-anyconnect-vpn-ftd-fmc.html

 

Rate if it helps.

 

Regards,

Josue Brenes

TAC - VPN Engineer.

If i understood correctly, i need to use next chapter - "Configure AnyConnect Modules and Profiles Using FlexConfig".

 

And if i want add only gina module i need to add next config in flexconfig for every from policies?

 

webvpn

group-policy <GP_NAME> attributes
webvpn
anyconnect modules value vpngina

That is correct.

 

Rate if it helps.

 

Regards,

Josue Brenes

TAC - VPN Engineer.

But how this feature works with LDAP attribute map? Because several access groups are configured on this device for remote connection.

 

 

Actually, it has nothing to do with the LDAP attribute mapping.

The link I shared just contains some advanced FMC deployments where the LDAP mapping is one of them but it's completely unrelated to the Anyconnect Modules section.

 

Rate if it helps.

 

Regards,

Josue Brenes

TAC - VPN Engineer.