02-17-2022 10:57 AM
Currently, one of our VPN clusters uses Certificate for the Authentication Method. The setting to allow users to select connection profile/Group is disabled, so that a User automatically connects using the Anyconnect Client.
Another one of our VPN clusters uses SAML for the Authentication method and a User has the option to select different connection profiles/Group using AnyConnect.
Question:
Instead of using two separate ASA clusters we would like to combine this to one. Is there a way using different Group Policies and Client Profiles that the behavior still operates the same. With Cert they are automatically logged in with that connection profile and with SAML they still have the option to select?
We are currently using ASAs 5545-X but want to implement this when we upgrade our ASAs this year.
Thanks
Solved! Go to Solution.
02-17-2022 02:04 PM
This is exactly what I needed thanks! I already set it up and test it
02-17-2022 12:04 PM
@jackfait1 you should create 2 connection profiles/tunnel-groups, one will use certificate authentication the other SAML. You can use either a group-alias or group-url to select which to connect to.
Push the XML profile to the client computers, to automatically login using certificates.
02-17-2022 02:04 PM
This is exactly what I needed thanks! I already set it up and test it
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide