The Meraki Community
Register or Sign in
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • About karls1
karls1

karls1

Conversationalist

Member since Aug 10, 2021

‎11-11-2021
Kudos from
User Count
PhilipDAth
Kind of a big deal PhilipDAth
2
movingonup
movingonup
1
View All
Kudos given to
User Count
JimmyM
JimmyM
1
View All

Community Record

4
Posts
3
Kudos
0
Solutions

Badges

Lift-Off View All
Latest Contributions by karls1
  • Topics karls1 has Participated In
  • Latest Contributions by karls1

Re: AnyConnect with Certificate Authentication, SCEPman CA, Azure & MDM man...

by karls1 in Security / SD-WAN
‎08-12-2021 01:55 AM
2 Kudos
‎08-12-2021 01:55 AM
2 Kudos
Hahaha, that resolved it! I can now confirm it is working with version 16.11 and AnyConnect Client v4.10.00093.    Those that use different CA, you can convert certificates manually with certutil.     certutil -encode filename.cer newfilename.cer       Thanks everyone! ... View more

Re: AnyConnect with Certificate Authentication, SCEPman CA, Azure & MDM man...

by karls1 in Security / SD-WAN
‎08-10-2021 03:19 PM
‎08-10-2021 03:19 PM
I have tried version 16.8, 16.10 and 16.11. I have also disabled and re-enabled AnyConnect between each upgrade, and changed DDNS just in case if there was any issues with that (Meraki support suggested this).   I have never been able to get it to work though, which is why I am unsure on the configuration as per the thread start.  ... View more

Re: AnyConnect with Certificate Authentication, SCEPman CA, Azure & MDM man...

by karls1 in Security / SD-WAN
‎08-10-2021 10:12 AM
‎08-10-2021 10:12 AM
Thank you for the suggestion PhilipDAth and Inderdeep. I checked with certutil on the Windows device, and the certificate and chain is verified and in order.   Just to double check there is no other unknown issues with it, I generated self-signed machine certificate with self-signed root CA signer, uploaded CA certificate to the MX and installed self-signed machine certificate on the device. Unfortunately no change. ... View more

AnyConnect with Certificate Authentication, SCEPman CA, Azure & MDM managed...

by karls1 in Security / SD-WAN
‎08-10-2021 04:42 AM
1 Kudo
‎08-10-2021 04:42 AM
1 Kudo
Hi,   Trying to configure AnyConnect with Certificate Authentication. Since there are no visible logs available from Meraki interface, I am unable to troubleshoot and understand what is really happening here. I have tried to contact Meraki support on several occasion, but have been met by agents without real knowledge or understanding about this, plus 1-2 hours wait time on the telephone with random disconnects. I guess beta features with beta support go hand in hand.   This gives me the opportunity to try and ask the Community to see if there is somebody out there that has a working configuration. I have been told by others that it should work, but they have not given any details about it so not sure. It seems so basic, but I just can't figure it out. Does anybody have some pointers?    I have not tested if {{DeviceName}} should be added to SAN, or that the issue is that I really need a (public) Root CA and issue SCEPman with Intermediate CA Certificate (but Meraki documentation does not really mention the need for it). Anybody knows?   My configuration is as follows:   MX84 with 16.11 (tried 16.8 too) SCEPman CA certificate uploaded to Meraki Machine and User certificate successfully deployed to device, also root added to Trusted AnyConnect Client v4.10.00093 for Windows with Profile below (manual cert selection for testing) <?xml version="1.0" encoding="UTF-8"?> <AnyConnectProfile xmlns="http://schemas.xmlsoap.org/encoding/"> <ClientInitialization> <AuthenticationTimeout>60</AuthenticationTimeout> <AutomaticCertSelection>false</AutomaticCertSelection> </ClientInitialization> <ServerList> <HostEntry> <HostName>AnyConnect</HostName> <HostAddress>***.dynamic-m.com</HostAddress> </HostEntry> </ServerList> </AnyConnectProfile>   When connecting, attempting both Machine and User certificate, gives the following Error: The causing Error in Event Log I assume: Function: ConnectMgr::certAuthHasFailed File: c:\temp\build\thehoff\phoenix_fcs0.660176920511\phoenix_fcs\vpn\api\connectmgr.cpp Line: 16651 Certificate authentication requested from gateway, no valid certs found in users cert store. Here are Event Logs leading to the Error above - User certificate: Certificate authentication requested from gateway, no valid certs found in users cert store. Client certificate requested by peer (via AggAuth) Issuer not found in CA Names from server for cert: /L={{AAD_Device_ID}}/CN={{User_Principal_Name}} Client certificate requested by peer Return success from VerifyServerCertificate User Selected Certificate: *** USER CERT *** Client certificate requested by peer (via AggAuth) Client certificate requested by peer Return success from VerifyServerCertificate And Machine certificate: Certificate authentication requested from gateway, no valid certs found in users cert store. Client certificate requested by peer (via AggAuth) [MCA] One certificate sent at protocol layer Issuer not found in CA Names from server for cert: /CN={{AAD_Device_ID}} Client certificate requested by peer Return success from VerifyServerCertificate User Selected Certificate: *** MACHINE CERT ***       ... View more
Labels:
  • Labels:
  • Other
Kudos from
User Count
PhilipDAth
Kind of a big deal PhilipDAth
2
movingonup
movingonup
1
View All
Kudos given to
User Count
JimmyM
JimmyM
1
View All
My Top Kudoed Posts
Subject Kudos Views

Re: AnyConnect with Certificate Authentication, SCEPman CA, Azure & MDM man...

Security / SD-WAN
2 4392

AnyConnect with Certificate Authentication, SCEPman CA, Azure & MDM managed...

Security / SD-WAN
1 4583
View All
Powered by Khoros
custom.footer.
  • Community Guidelines
  • Cisco Privacy
  • Khoros Privacy
  • Cookies
  • Terms of Use
© 2023 Meraki