We currently have a VPN solution with an ASA5510 and the client PC's using the Cisco VPN Client V5.0.07.0410. This works for both Windows XP SP3 and Windows 7, however, Windows 7 will not allow Enable Start Before Logon or Disconnect VPN Connection When Logging Off (i.e. Windows Logon Properties are missing in the client configuration options). Is there a fix for this VPN client? What VPN upgrade options are available that will allow these options?
Thank you for your suggestions!
Solved! Go to Solution.
All you have to do is to run the vpn client in XP SP3 compatability mode and the windows properties box reappears in the options menu, allowing you to keep the vpn connected during logoff.
That will not work - you will find that the machine with either blue screen, or the client will not run - and report an error about the sub system or no network connectivity, when you do have a good connection.
The XP compatibility mode will not work for my situation. There is no prompt to connect to VPN before you log into the desktop allowing all of your startup scripts to execute from the domain controller. As this connect before login didn't work, I did not need to test if the vpn connection remained connected after logging off the desktop.
That is very interesting as I found the below from this link:- http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00809f0d75.shtml#dfgh
The procedures to enable SBL differ slightly on Windows Vista and Windows 7 systems. Pre-Vista systems use a component called virtual private network graphical identification and authentication (VPNGINA) to implement SBL. Vista and Windows 7 systems use a component called PLAP to implement SBL.
In the AnyConnect client, the Windows Vista Start Before Logon feature is known as the Pre-Login Access Provider (PLAP), which is a connectable credential provider. This feature lets network administrators perform specific tasks, such as the collection of credentials or connection to network resources, prior to login. PLAP provides Start Before Logon functions on Windows Vista, Windows 7 and the Windows 2008 server. PLAP supports 32-bit and 64-bit versions of the operating system with vpnplap.dll and vpnplap64.dll, respectively. The PLAP function supports Windows Vista x86 and x64 versions.
Note: In this section, VPNGINA refers to the Start Before Logon feature for pre-Vista platforms, and PLAP refers to the Start Before Logon feature for Windows Vista and Windows 7 systems.
In pre-Vista systems, Start Before Logon uses a component known as the VPN Graphical Identification and Authentication Dynamic Link Library (vpngina.dll) to provide Start Before Logon capabilities. The Windows PLAP component, which is part of Windows Vista, replaces the Windows GINA component.
A GINA is activated when a user presses the Ctrl+Alt+Del key combination. With PLAP, the Ctrl+Alt+Del key combination opens a window where the user can choose either to log in to the system or activate any Network Connections (PLAP components) with the
Network Connect button in the lower-right corner of the window.
The sections that immediately follow describe the settings and procedures for both VPNGINA and PLAP SBL. For a complete description of enablement and use of the SBL feature (PLAP) on a Windows Vista platform, refer to Configuring Start Before Logon (PLAP) on Windows Vista Systems.
How do your users login??