04-03-2020
05:28 PM
- last edited on
04-27-2020
09:00 AM
by
Hilda Arteaga
Español | Português | Français | Русский | 日本語 | 简体中文 |
This event continues the conversation of our recent Community Ask Me Anything event "Secure Remote Workers".
Here’s your chance to discuss more about the configuration, troubleshooting and best practices for AnyConnect secure mobility client on a Cisco Adaptive Security Appliances (ASA) and Firepower Threat Defense (FTD) and its integration with other Cisco security portfolio devices and technologies like ISE and Duo.
This session provides an opportunity to learn and ask questions about various aspects of AnyConnect implementation (using SSL and Ikev2) including (but not limited to) emergency licenses, configuration, deployment and troubleshooting AnyConnect that provides the security necessary to help ensure that your organization is safe and protected in such critical situation.
To participate in this event, please use the button below to ask your questions
Ask questions from Monday 6 to Friday, April 17, 2020
**Helpful votes Encourage Participation! **
Please be sure to rate the Answers to Questions
Solved! Go to Solution.
04-08-2020 03:52 AM
this is a question from Chinese community member fengbofeng2224
I am reviewing the firepower product sheet,would like to know which value should I refer to regarding ssl vpn throughput?
Tls?
Thanks.
04-08-2020 04:19 AM
04-08-2020 06:06 AM
Hey guys, thanks for doing this. Lots of good info so far.
We still occasionally have trouble distributing a profile for anyconnect to new users to fix the 12 second authen timeout issue. This is an issue because our users can still choose to have their two-factor method be a phone call or to reply back to a text message. Also, we have clientless SSL turned off but allow users to login and download the latest client from the firewall through this portal.
My question is, can I somehow attach the default vpn profile to this client download, even though we have clientless vpn turned off?
04-08-2020 06:22 AM
There is no practical way to push out the xml file with the downloads from a clientless connection. The best approach to push this xml profile out, if users are having issues connecting because of the timeout, would be to push this xml profile out with a GPO if you have that option. Additionally, you could just create a seperate tunnel-group, that only has user/pass login, that users can use to download the modified profile. This could then map them to the correct tunnel-group and group-policy after the timeout has been modified.
04-08-2020 06:29 AM
Hello @david.haughn
Once your users download the Anyconnect client, the first time they connect they will download the profile. There are different options for deployments like yours:
Regards,
Gustavo
04-08-2020 09:10 AM
I have bandwidth related question
when I am not on the VPN I can get the full speed of the bandwidth provided from my ISP , when I connect to SSL VPN ( anyconnect ) I am not getting even half of it . I understand for the overhead of the packet but how you can solve this or what are most of the solutions
04-08-2020 09:36 AM
04-08-2020 09:14 AM
how would you integrate WSA with ASA for webvpn users ( full vpn tunnel )
Would you prefer umbrella integration with anyconnect
04-08-2020 12:15 PM
Hi @antonkolev ,
Just replied this on the following discussion:
https://community.cisco.com/t5/web-security/cisco-anyconnect-wsa-wccp/td-p/2611624
Let me know if you want to expand further.
04-08-2020 09:54 AM
Hi!
Is there any option to configure a web vpn ssl on a FTD with FMC?
Thanks
04-08-2020 10:11 AM
04-08-2020 10:42 AM
Hi Team,
we don't have AMP for endpoints implemented in our network, but if I still want to use AMP with anyconnect VPN what are the license I should have, right now we have AnyCconnect apex license and implemented AnyConnect with FTD and all working fine
looking for options with Anyconnect with AMP?
Thanks/Basavaraj
04-08-2020 12:26 PM
AMP4E is based on the amount of Endpoints you want to protect. Besides the Anyconnect licenses you need the AMP4E licenses. For deployment, you can use the AnyConnect AMP Enabler which is used as a medium for deploying Advanced Malware Protection (AMP) for endpoints. It pushes the AMP for Endpoints software to a subset of endpoints from a server hosted locally within the enterprise and installs AMP services to its existing user base.
Here is the ordering guide.
AMP4E was recently added to our Remote Secure Worker Offer for COVID-19 as you can read here:
https://blogs.cisco.com/security/expanding-free-security-offers-into-customers-endpoints
With this new addition, existing customers can exceed their device limit by two times to support an increase in remote workers. To take advantage of this offer, they simply install AMP for Endpoints Connectors on extra devices, and no other action is required. As with our AnyConnect, Umbrella and Duo offers, this will be available until July 1, 2020
-Gustavo
04-09-2020 04:14 AM
Hi,
First of all thank you for this initiative, I am personally gathering a lot of information indirectly and I have surely bookmarked this discussions, I am sure that it will be among my top 10 bookmarks for a long time :)
Question :
We use SBL (Start before logon) module for remote workers as all of them inherited from on-premises no cached credentials for their workstations in windows.
Everything is working fine but even when an agent has a profile in anyconnect they can select during the windows logon screen they end up in anyconnect to have a generic FQDN of the profile along with the profile name.
This causes some confusion to our users as if for any reason they have to reconnect they have the profile name listed and also the FQDN and I haven't find yet a way to prevent this.
Is it possible to prevent the FQDN to be listed in anyconnect and have only the profile name?
04-09-2020 05:14 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide