cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
604
Views
0
Helpful
4
Replies

Configuring Cisco Anyconnect to Authenticate with both Username/Password and Self-Signed Certificate

jerryblack143
Level 1
Level 1

Hello,

I am trying to figure out how to configure Cisco Anyconnect to authenticate any VPN connection with both the username/password and a self-signed certificate.

The reason why i am trying to implement this is because we want to prevent any user who does not have a company provided device from downloading the Anyconnect application and logging into the network with his personal device.

I am trying to achieve this without buying an SSL certificate from a trusted CA. The goal is to use self signed certificate to achieve this 

4 Replies 4

Rahul Govindan
VIP Alumni
VIP Alumni

Are you talking about each user having their own self-signed certificate? This would mean you would need to upload the self-signed cert of each user on the ASA. An easier method would be to leverage the CA server capability of the ASA for SSLVPN session and have users enrolled for a certificate from the ASA.

Thank you Rahul for your response.

Do you happen to have any resource or material that can help me implement this 

I would reference these 2 documents: One for double authentication with AAA and certificate and one for Anyconnect with Local CA.

http://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/116111-11611-config-double-authen-00.html

www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-firewalls/200602-Configure-ASA-as-a-Local-CA-Server-and-A.html

Thank you. I will try these and update