01-10-2025 07:30 AM
I would like to know the possibilities of Integrating the Cisco AnyConnect with Cisco ISE and recommendations for configurations. And would like to know in case of any cons and challenges. Would be great if I get the details of the step by step integration. Thank you in advance.
Solved! Go to Solution.
01-10-2025 08:35 AM
@SandeepNaga it's pretty straight forward integrating ASA/FTD Remote Access VPN with ISE.
Examples:-
https://integratingit.wordpress.com/2018/03/11/ccnp-simos-asa-anyconnect-ssl-vpn/
01-10-2025 09:01 AM
@SandeepNaga the most secure Remote Access VPN authentication is using Two Factor authentication. One factor can be RADIUS (ISE) which can authenticate the users against AD and the second factor using either certificate or MFA (i.e., Cisco DUO).
01-10-2025 09:07 AM
01-10-2025 08:35 AM
@SandeepNaga it's pretty straight forward integrating ASA/FTD Remote Access VPN with ISE.
Examples:-
https://integratingit.wordpress.com/2018/03/11/ccnp-simos-asa-anyconnect-ssl-vpn/
01-10-2025 08:56 AM
@SandeepNaga here are some videos that might help too
https://www.youtube.com/watch?v=UjCqI-WUzWA
https://www.youtube.com/watch?v=L5UgP-jw0es
From an ISE perspective the configuration is the same whether the VPN headend is an ASA or FTD.
01-10-2025 08:56 AM
That's very helpful. Thank you Rob.
And would like to know any challenges in case of using RADIUS as authentication, just wanted to know to be on safer side, in case of any known issues. Thank you.
Much Appreciated for your help. Thank you.
01-10-2025 09:01 AM
@SandeepNaga the most secure Remote Access VPN authentication is using Two Factor authentication. One factor can be RADIUS (ISE) which can authenticate the users against AD and the second factor using either certificate or MFA (i.e., Cisco DUO).
01-10-2025 09:02 AM
@Rob Ingram Thank you very much Rob.
01-10-2025 09:04 AM
Any configuration article or Video for enabling two suggested two factor authentication ?
01-10-2025 09:07 AM
01-27-2025 11:21 AM
Hello @Rob Ingram Hope you are doign well,
After we integrate Cisco Anyconnect with ISE, am using Certficate & Azure AD as authentication, can we add the Microsoft Authenticator as MFA ? if so, can you help me with the detailed configuration to acheive it. Thank you.
01-27-2025 11:30 AM
@SandeepNaga You configure Azure AD integration on the FTD (via FMC), so the client authenticates using certficate to the FTD and then the FTD authenticates to Azure AD via SAML https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221659-configure-ravpn-with-saml-authentication.html
If you want to integrate into ISE, you can setup authorise-only to the ISE servers.
01-27-2025 12:09 PM
MFA as Microsoft Authenticator?
01-27-2025 12:13 PM
@SandeepNaga MFA = Multi Factor Authentication.
01-27-2025 12:51 PM
Hello Rob, yes MFA is Multifactor Authentication, I mean like we wanted to add Microsoft Authenticator as a MFA for the anyconnect VPN that was integrated with Cisco ISE, (along with the current authentication is with Certificate and Azure AD is configured in Cisco ISE),
01-27-2025 01:16 PM
@SandeepNaga no I don't think you can use Microsoft Authenticator for AnyConnect VPN - I see no guides of information on that this is possible.
01-10-2025 09:08 AM
Thank you @Rob Ingram and Kudos to your expertise.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide