Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
naveda
Employee
Employee

AD user should connect to RA VPN automatically

Jump to solution

I have a query when RA VPN users log in to the system with AD credentials, they also should get connected to VPN automatically. The client should not ask them to put a username and password to connect to VPN same AD credentials should be used. 

Is there a way to achieve this with AD username and passwords or is any other way which can work?

 

I tried enabling password caching and connect mode to always but that is also not working.

 

 

6-0003276070_1653298530964_Global_Settings (1).PNG

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

Secure Domain Login can bring up the VPN when the user logs in, but this requires credentials to be entered.
Certificates could be used for the VPN portion of the authentication in this case, particularly ones stored in the Windows Certificate Store (particularly one that cannot be exported).

View solution in original post

0 Kudos
15 Replies
naveda
Employee
Employee

@PhoneBoy  could you please guide me on this?

0 Kudos
PhoneBoy
Admin
Admin

Secure Domain Login can bring up the VPN when the user logs in, but this requires credentials to be entered.
Certificates could be used for the VPN portion of the authentication in this case, particularly ones stored in the Windows Certificate Store (particularly one that cannot be exported).

0 Kudos
naveda
Employee
Employee

@PhoneBoy  Thanks for the response, could you please clarify which certificate I can use, in order to achieve the requirement.

0 Kudos
PhoneBoy
Admin
Admin

You can use any certs for this, including ones from the ICA.

0 Kudos
naveda
Employee
Employee

@PhoneBoy  Could you please confirm if we can go with CAPI certificate? 

0 Kudos
PhoneBoy
Admin
Admin

I don’t see why not.

0 Kudos
the_rock
Champion
Champion

I have client where this works perfectly fine. Just as a test, can you have them delete/re-create the site?

0 Kudos
naveda
Employee
Employee

@the_rock  I would like to know how it works perfectly fine. I tried to recreate the site but it's same.

0 Kudos
the_rock
Champion
Champion

I dont know what to tell you...we configured IA blade while ago, integrated with access roles and AD server and VPN works fine as auto connect/cashed creds.

0 Kudos
skandshus
Collaborator

is there a chance back in the day when you did it, you had to edit the trac to allow cached credentials in the VPN clients?
i even think it might be required to edit the trac file on the gateway to "allow it" and also edit it on the Endpoint client.

0 Kudos
the_rock
Champion
Champion

Yes, we did do that on both, correct.

0 Kudos
naveda
Employee
Employee

@skandshus @the_rock What I have to edit? I don't see anything related to password caching trac.ttm file

0 Kudos
the_rock
Champion
Champion

If you send me the files, I can check, but its been some time, so cant remember now.

0 Kudos
naveda
Employee
Employee
 
0 Kudos
the_rock
Champion
Champion

I think we may have changed default auth method to username-password.

0 Kudos