03-08-2012 02:00 AM
Hi,
Is is possible to start an anyconnect vpn session after the system has booted, without any user interaction with the use of certificates?
is it possible to use scep proxy to enroll a device with computer certificates?
Thanks,
Bart
03-14-2012 06:46 PM
Hi Bart,
Thanks for your inquiry. Our response is below:
Is it possible to start an anyconnect vpn session after the system has booted, without any user interaction with the use of certificates?
'The Cisco AnyConnect "Always On" mode with certificates can be used as long as this is post login. However, this mode does not support pre-login at this time.'
Is it possible to use scep proxy to enroll a device with computer certificates?
"You would need administrative privileges to install computer (machine) certificates. Otherwise, SCEP will only install user certificates. More specifically, if the local user is an admin, we will install the certificate on Both stores machine and user machine."
08-19-2013 12:32 PM
ideally you'd wanna do this by pushing an Identity Cert via GPO, then configure either AnyConnect via pre-logon VPN, or alternatively, configure Always-On with certificates, using a Domain-List, or whatever mechanism you'd like to tie the Always On Function to.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide