07-24-2023 09:13 AM
Hi experts,
I have 2 alias published to cisco AnyConnect, group1 is local AAA, and Group2 is SAML, and allow users to select tunnel group is selected, my issue is after connecting to group 2 they automatically connect since they met conditional access requirements, and the idea of choosing group is lost. Is there a way to default the group 1 as default always?
thanks!
07-24-2023 09:16 AM
Config group-policy for each tunnel-group
07-25-2023 06:19 AM
What do you mean by "conditional access requirements"? Is it TND or something else? Last "group-alias" selected is cached in preferences. You can try to put <RestrictPreferenceCaching>all</RestrictPreferenceCaching> into the local policy file. Another option is to put <DefaultGroup>YourDefaultTunnelGroup</DefaultGroup> into the global preferences file or user preferences (takes priority). This may help.
Local Policy: AnyConnectLocalPolicy.xml
Global Preferences: preferences_global.xml
User Preferences: preferences.xml
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide