Is there any feature in Cisco Anyconnect or other software to allow Domain users to connect only to their
corporate VPN. We don't want domain users to connect any other VPN rather than corporate VPN.
VPN users are authenticating with ISE. Is there any workaround for this.
I think you can use the Always-ON and Auto connect on start feature of the XML profile to accomplish this.
Make sure to uncheck the "user controllable" and "allow vpn disconnect" to avoid the end user to start another VPN session.
See more information about those features:
Hope it helps
- Randy -
I would suggest using a DAP policy and check for a certificate or a register key on corporate machines. This action requires host-scan. You can learn more about DAP policies following this link:
Also an LDAP mapping would be a good option to prevent users to connect to a tunnel-group they are not supposed to connect on.
Please check those links out and if you have any questions please let me know.