- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Secure Client AnyConnect on an MX64
Good morning all,
I'm trying to configure my company's network to allow 'Always On' for the VPN profiles, but clients can't connect to the VPN when inside the network. We are hosting the AnyConnect on our MX64 device. Any thoughts or resources about configuration?
EDIT: If not possible, is there a way to push "Always On" when Connected to networks other than the corporate LAN?
Solved! Go to solution.
- Labels:
-
Client VPN
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Take a look at this: https://documentation.meraki.com/MX/Client_VPN/AnyConnect_on_the_MX_Appliance/Client_deployment#Alwa...
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I am almost 100% sure that it is not possible to connect to Client VPN with either Anyconnect or L2TP when it is on the same network as the MX.
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That's unfortunate.
Edit: Is there a way to enable "Always On" when connecting to a network that is not our corporate LAN?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Take a look at this: https://documentation.meraki.com/MX/Client_VPN/AnyConnect_on_the_MX_Appliance/Client_deployment#Alwa...
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Normally you enable "Trusted Access". You say when on the outside of the network enable the VPN, and when on the inside of the network disable it.
Read "Trusted network detection".
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks! This looks like it will help!
I got it to automatically connect when connected to my phone, but not to auto disconnect when connecting to the corporate network.
The profile editor keeps giving me this error when trying to list my DC. I did not add port 443, which makes me think that its asking for our VPN server rather than the DC, but we use an MX64 firewall.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The "Trusted Servers" list are servers inside of your own network (and if it can talk to them - it considers the network "trusted").
I wouldn't use this option. Configure it to check the DNS servers. If it sees your internal DNS servers, then consider the network trusted.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I configured it to check out only DC, and it seems to not be able to.
