cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2307
Views
0
Helpful
2
Replies

Anyconnect - Start vpn after boot

bartbruninx
Level 4
Level 4

Hi,

Is is possible to start an anyconnect vpn session after the system has booted, without any user interaction with the use of certificates?

is it possible to use scep proxy to enroll a device with computer certificates?

Thanks,

Bart

2 Replies 2

jooh2
Level 1
Level 1

    Hi Bart,

Thanks for your inquiry.  Our response is below:

  Is it possible to start an anyconnect vpn session after the system has booted, without any user interaction with the use of certificates?

'The Cisco AnyConnect "Always On" mode with certificates can be used as long as this is post login. However, this mode does not support pre-login at this time.'

      Is it possible to use scep proxy to enroll a device with computer certificates?

"You would need administrative privileges to install computer (machine) certificates. Otherwise, SCEP will only install user certificates.  More specifically, if the local user is an admin, we will install the certificate on Both stores machine and user machine."

leciscokid
Level 1
Level 1

ideally you'd wanna do this by pushing an Identity Cert via GPO, then configure either AnyConnect via pre-logon VPN, or alternatively, configure Always-On with certificates, using a Domain-List, or whatever mechanism you'd like to tie the Always On Function to.