09-22-2025 04:03 AM
Hi All
We are using FTD managed by SCC, we do not have ISE
Is it possible to use the hostscan module to check for a machine certificate when connecting to our remote access VPN? Is so where do you do it?
Cheers
09-22-2025 04:19 AM
@carl_townshend edit the Dynamic Access Policy and then the DAP record, define the criteria and select certificate.
Or you could just use double authentication and authenticate using the machine certificate aswell as the existing method.
09-22-2025 04:54 AM
Hi Rob
We seem to have the following options, it says multiple certificate authentication?
09-22-2025 05:01 AM
@carl_townshend ok seems like you have to use multiple certficates then with DAP.
Can you not reconfigure authentication to use certificates in addition to your primary method, that will ensure only devices with a machine certificate can authenticate.
09-22-2025 08:21 AM
Hi, we already use MFA on authentication, I dont really want to change the authentication piece, I just wanted to check that the machine has the certificate installed.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide