12-29-2020 05:43 AM
Hi Cisco VPN/Anyconnect Community,
I hope you could help me on what I am trying to achieve. My goal is to force users to login/use Anyconnect so that their laptops will be patched/updated by our GPO. Below are the things we have tried but seems not workable on our current setup.
1. SBL - my colleagues mentioned to me that they tried this but cannot work because we have MFA
2. Always-On VPN - I tried this but it appears it is deleting/removing our SAML cert (this cause connection issue from Anyconnect users to the vpn server (e.g vpn.domain.com)
Now, what I am thinking is a batch file script that can be used so that I can apply it on our Anyconnect Client Profile and then once a user logs in to the vpn server (vpn.domain.com) this batch file will be deployed on the user machine and will take care of the future automatic login of the users to the Anyconnect.
Is there such thing like this? Or is there anything that you could suggest that could fit my goal?
Thank you,
John
Solved! Go to Solution.
01-04-2021 02:59 AM
Ok so TND is working correclty.
You need the password to identify the user and it wouldn't be Multi Factor Authentication if you skipped the password.
Youc could setup a new connection profile that doesn't require a password, you'd still need to enter a username otherwise how would you know the MFA passcode is correct?
12-29-2020 05:55 AM
If you just want to patch/update the computers you could deploy the management VPN tunnel. This will establish a VPN tunnel without the user explicitly authenticating. This relies on a computer certificate (no MFA) to authenticate and would be transparent to the user.
More information on management tunnel:
12-30-2020 01:02 AM
Hi Rob,
Thank you so much for your response to my question! I will check the link you provided and will revert to you for other questions I may encounter.
12-30-2020 01:51 AM
Hi Rob,
I've gone through the link guide and looks like this is a good approach to achieve our goal, however, yes, it is only relying on certificate only (no MFA). I just doubt this will pass our security setup since we are using SAML for authentication.
Is there's any other you can suggest or advice?
Thank you!
12-30-2020 02:04 AM
Ok, then you could use trusted network detection (TND). This will have anyconnect establish a VPN tunnel automatically (it will open the login prompt for the users to login using MFA) when it detects the user is outside of the corporate network. When the user is connected to the local corporate network, the VPN will disconnect.
Reference
12-30-2020 03:13 AM - edited 12-30-2020 03:30 AM
Hi Rob, thank you thank you so much for your responses!
I've gone through the guide for the Use TND and I am honestly confused as to what to put in the following sections highlighted in my attachment. On the "Trusted DNS Servers" I think I will just need to put the two DNS servers that I am seeing on my ipconfig/all result. But the other two, I don't know what should I put and what are they doing.
Sorry, I am really still a newb and hope you won't get tired to give an advice.
Thank you!
12-30-2020 03:29 AM
You don't need to fill in all those sections. You should at least define your internal corporate DNS name space and internal DNS servers, this is how AnyConnect determines when it is connected to a trusted network.
So in your scenario if you connect to your home network, it won't receive your corporate DNS servers/DNS name space, so anyconnect will determine it's on an untrusted network and attempt to establish a VPN.
12-30-2020 05:49 AM
Thank you, Rob! I will try this out. I remember I configured this Automatic VPN also together with the Always-On but I was not able to make it working.
This time I will just try the TND only and let you know.
Once I have configured this and I applied it to the Profile, then I connected to that Profile, this TND should automatically apply on my client profile in my laptop, correct? Then if I restarted my laptop and login again to my laptop from my home wifi, I should be expecting that the Anyconnect will prompt me to login with MFA right? (Automatic means the Anyconnect login Page will just appear on my screen suddenly after login on my laptop).
01-04-2021 02:38 AM
Hi @Rob Ingram ,
I was able to configure the Automatic VPN and the TNDs. I restarted my laptop the the AnyConnect automatically prompted me, however, it still requires me to login my username and password, then the MFA.
Is there a way that it bypass the username and password and just go directly to MFA?
Thank you!
01-04-2021 02:59 AM
Ok so TND is working correclty.
You need the password to identify the user and it wouldn't be Multi Factor Authentication if you skipped the password.
Youc could setup a new connection profile that doesn't require a password, you'd still need to enter a username otherwise how would you know the MFA passcode is correct?
01-04-2021 03:41 AM
Rob! Thank you for your explanation! That really make sense to me now!
Thank you so much!!!
02-15-2021 04:33 AM
Hi @Rob Ingram ,
I just learned from my Teammate that this is not 100% working. My teammate went to our office and connected his laptop to the domain network. He still got prompted to login to the Anyconnect app automatically where it should not be as I understand because he is already inside the domain network/trusted network.
Is there anything that I am missing? Thank you and I hope you could still give some advice.
02-15-2021 11:37 AM
What DNS/domain name did he receive on that network? Is it correct as per the configuration you've applied in the policy?
Does it work correctly on other networks?
02-16-2021 01:25 AM
Hi @Rob Ingram ,
Thank you for your response.
My teammate got the domain name that I have also put in the Anyconnect. He connected via our Wireless LAN, and I am sure that he cannot be wrong as he is my Senior and also been long managing the company's Network. He just informed my last night that it looks like it is not working as expected when inside the domain network.
Please see attached on how I configured it. Not sure if the comma and spacing has anything to do.
Thank you!
05-11-2021 09:55 AM
Hi @Rob Ingram, how can I prevent the AnyConnect VPN to prompt the user to login when they are inside the office Network?
Thank you!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide