Anyconnect client certificate

Tjandra
Comes here often

Anyconnect client certificate

Hi, I'm trying to set up a client certificate for Anyconnect using Microsoft CA Services. From this topic (https://community.meraki.com/t5/Security-SD-WAN/AnyConnect-with-Certificate-Authentication/m-p/14535...) seems like it's possible.

NOTE: my VPN users are not AD-authorized (because not all of them are AD users)

 

My question: can anyone show me how to create the client certificates? 

 

Thanks

3 Replies 3
alemabrahao
Kind of a big deal
Kind of a big deal

Have you checked these documents?

 

https://documentation.meraki.com/MX/Client_VPN/AnyConnect_on_the_MX_Appliance/Managing_and_Troublesh...

 

How to manually create client certificate on Ca server? - Microsoft Q&A

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Tjandra
Comes here often

I've seen the Meraki doc page, and it doesn't say how to issue the client cert.

 

And thanks for the Microsoft page, however the 3rd step (Request a New Cert) is not the same as what I see on my 2012R2 server... in particular the dialog for "Select Certificate Enrollment Policy" only has "Active Directory Enrollment Policy" (then select Administrator, Basic EFS, EFS Recovery Agent, or User) and "Configured by you" (which requires me to enter "enrollment policy server URI").

 

Thanks

alemabrahao
Kind of a big deal
Kind of a big deal

I suggest you open a ticket with Microsoft so they can help you.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels