NAC In-Band for AnyConnect Clients are not put in-band
I am trying desperately to get this working and I know I am VERY close. The problem is AnyConnect users logon the ASA. They get authenticated through the CAS. They open a web page on the CAS. They get a redirect to the agent download. The agent installs. And thats it. Nothing else happens.
In my lab after the agent installs, then the user gets the NAC Agent GUI pop-up and they have to logon again to get to the network they want to get to.
That does not happen in my case. Here is a drawing of the setup. These users are ultimately trying to get to the Terminal Server Farm.
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...