07-22-2020 08:54 PM
ello everyone,
We are undertaking two related projects at the same time. One is the deployment of a new Cisco FTD firewall and the other is the deployment of over 500 new laptops. I need to know if installing/configuring the Cisco Anyconnect client on one laptop and creating a gold image to be used to configure the deployment of the rest of laptops, is that a supported deployment mothed? Pros/Cons?
If I do this will we still be able to update the client software and profile settings in the future via the FTD?
Thank you all in advance for your assistance!
07-22-2020 11:07 PM
Look at the anyconnect supported platforms :
yes, you can deploy the package method to build as per business policy, so users can not upgrade or install unnecessary software into the device for a security reason.
If you have SCCM, you can push the upgrades to clients.
07-23-2020 06:42 AM
07-23-2020 08:16 AM
Thank you very much for the information.
Yes, we are planning on using the additional modules listed below. My thinking is we will need to ensure we configure the modules listed below during the imaging process as FTD does not support configuration profiles for these modules. Would you agree with that approach?
07-23-2020 09:08 AM
07-27-2020 08:27 AM
Yes, I have been reading that documentation for the last three days!
07-24-2020 01:14 PM
You can push the modules and profiles using flexconfig in Firepower 6.6.
Version 6.7 will include the ability to do that from the GUI.
07-27-2020 08:29 AM
Great, thank you for that information.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide