cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1068
Views
0
Helpful
2
Replies

(Urgent) Clientless VPN - gpupdate

Brad_Shawh
Level 1
Level 1

Hello

 

We have a situation, due to an incorrect GPO update, all the remote users have lost ability to connect to VPN using anyconnect, they get error "Unable to load preferences file', the solution of which is to delete the profiles folder and login to gateway manually, this is fine, but the users do not have local admin access, so they can not delete anything, which means they can not login.

 

Is there is a way to let users login thru clientless VPN and perform a gpupdate (it's fixed now)? I have not worked on clientless VPN so have not much clue!

1 Accepted Solution

Accepted Solutions

Cristian Matei
VIP Alumni
VIP Alumni

Hi,

 

    With clienteles SSLVPN, the ASA acts asa proxy for all sessions, so there is no direct communication between the endhost and the Domain Controller to push a GPO update.

   Configure a new AnyConnect profile, can be the same configuration just give it another name, attach it to your connection-profile/group-policy. Try enabling the group-url functionality and ask the users to connect via their browsers to the group-url, Anyconnect should start and download new profile. At the sam time, GPO should be pushed if connection is successful.

 

Regards,

Cristian Matei.

View solution in original post

2 Replies 2

Cristian Matei
VIP Alumni
VIP Alumni

Hi,

 

    With clienteles SSLVPN, the ASA acts asa proxy for all sessions, so there is no direct communication between the endhost and the Domain Controller to push a GPO update.

   Configure a new AnyConnect profile, can be the same configuration just give it another name, attach it to your connection-profile/group-policy. Try enabling the group-url functionality and ask the users to connect via their browsers to the group-url, Anyconnect should start and download new profile. At the sam time, GPO should be pushed if connection is successful.

 

Regards,

Cristian Matei.

Thank you, Christian.