cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
452
Views
0
Helpful
2
Replies

How to make sure only domain computers connect to anyconnect VPN?

Sheraz_35
Level 1
Level 1

Hi,

I have a remote access Any Connect VPN, at the moment any user is able to connect in with any laptop that has the any connect client installed, they just have to type in their username and password, does anyone know how I can lock this down so that a second authentication occurs and makes sure the laptop they are logging in from is a domain machine. I do have a Radius server setup and an OU with all my domain computers etc. I read Cisco Secure Desktop can do this but can't download it apparently it has been discontinued. 

 

Thanks

2 Replies 2

You can use certificate-based authentication together with username/Password. Or you use hostscan (the component of CSD that is still supported) to search for signs that the PC is company owned. But the second option is not as strong as using certificates.

Hi Karsten,

Thank you for your reply, do you know of any guides showing how to configure secondary authentication with a certificate? Thank you for your help.