Windows 7 -How to authenticate to WiFi (home or public) with AnyConnect NAM installed

Hello,
We are deploying ISE and connecting to the company's WiFi using a "machine" login (active directory laptop) works fine on Windows 7 or 8 - both wired and wireless. But, here is a scenario that I can't seem to find a good answer for. All my searches result in answers for corporate wifi; but not what I need.
So, an employee checks out a laptop to use on a trip. It has AnyConnect 4.0.x VPN and NAM installed (SBL - GINA needs to be added). Windows 8 allows a user who has never used a Win8 laptop to connect to WiFi and authenticate before attempting to login and get their desktop. If the Win 7 or 8 laptop is connecting to a corporate AP, ISE automatically authenticates the "machine" so when they enter their user credentials, they will be logging into the Windows domain (GPO's, drive mappings, etc.). Once a Windows 7 laptop has been authenticated with ISE, it doesn't matter which user logs in, the device will already have a connection. Essentially, the user does not have to log in while within the corporate network in order to get their profile created (locally cached credentials).
But, what if the user has no local profile and tries to use a Windows 7 laptop from their home? They need to be able to connect and authenticate to their home WiFi before AnyConnect can automatically bring up the VPN tunnel. The GINA module will do an SBL for a VPN connection but that's not going to work if they don't have a WiFi connection. This scenario is possible in my environment.
So, can AnyConnect GINA also manage a WiFi login before a user tries to get to a desktop for the first time?
The perfect scenario would be where we hand out emergency laptops to first time users, they connect to whatever WiFi they have access to (non-corporate), the VPN tunnel comes up and when they login, they login into the Windows domain, not locally.
Thanks!

Just so everyone knows...
Please take note of the specific processor which is included with your HP Pro 3130 MT.
HP Pro 3130 MT motherboards with specific processors do not have any onboard (integrated) graphics, although they still have the VGA and DVI connectors. This means that although you may remove the PCIe Graphics Card, you will not be able to be able to use a monitor with the onboard VGA or DVI (because there is no integrated graphics).  This also means that you will not be able change your bios to onboard graphics (because there is no integrated graphics).
"NOTE: HP Pro 3130 with Intel Core i5 750 processor or any Intel i7 processor has no integrated
graphics."(1)
(1) Source: http://h18000.www1.hp.com/products/quickspecs/13640_ca/13640_ca.PDF
If you would like to know why, let me know. Thanks!
-Dave

Similar Messages

  • How can i sort PDF's on IBook with the name that starting with numbers

    i import a number of pdf's representing ameeting agenda as the files names (1xxx,1.1xxxx, 2.xxxx,10.xxxx) on ibook , however the files sorted on a diffrent way as file start with 10 on first . so how can i sor the files on the IBook  with its name starting with numbers as1 &1.1 and so on.

    You seem to want a numeric sort but are getting a character sort.
    a number range  would be 0,1,2,3, ... 9,10,11 ...
    sorting like everything else with computers is an algorithm.  Someone needs to define how it works.  When you see a list of files, someone has defined how the list will be sorted. If you compare Windows file sorting to Mac files sorting you will find there are differences.
    In the case of files sorting, the files are sorted on characters from left to right. In file sorting the sorting algorithm does not try to determine that files are numbers.  All files beginning with a 1 will be sorted together becuase the file sorting althorithm doesn't look at the second character position before grouping all the 1's together.
    For what it is worth, there are multple books written on sorting.
    Robert

  • Windows 8.1: Unable to connect to IBSS network with a profile installed manually

    I created an IBSS network, Imported the IBSS profile and trying to connect from my Windows 8.1 machine. It was not connecting to the network for some reason. Is it supported in Windows 8.1?
    I was able to connect to the network from Windows 7 machine using same IBSS profile, But not with Windows 8.1. Is there any known issue related to this?

    Hi,
    Please take a look at the following articles regarding IBSS network:
    Connection Operation Guidelines for Independent BSS Networks
    Please note: IBSS (Ad hoc) and SoftAP are deprecated. Starting with Windows 8.1 and Windows Server 2012 R2, use Wi-Fi Direct.
    Wi-Fi Direct Miniport Initialization and Configuration
    Best regards
    Michael Shao
    TechNet Community Support

  • How to detect the number of marker (cuepoitName) with same name from a list.

    ... it is the second step of my previous question.
    From a sound I take a list of cuepointName with different name, for exemple:
    Mylistcuepoint =  ["reg 01", "reg 2", "name 1, "name 2", "name  3"] etc.
    Which command I must use to detect the cuePointTime only for the cuepointName: "name 1", "name 2" "name 3" ...
    My second question, for a second script is: how can I count how many  cuePointName with "name 1", "name 2", "name ...." I have in "Mylistcuepoint"?
    I can load several sound member so "Mylistcuepoint" can change obviously for the number of marker of "reg ...." and for the number of marker of "name ...." but the first word ("reg" or "name") it will be always the same.
    Tanks

    From a sound I take a list of cuepointName with different name, for exemple:
    Mylistcuepoint =  ["reg 01", "reg 2", "name 1, "name 2", "name  3"] etc.
    Which command I must use to detect the cuePointTime only for the cuepointName: "name 1", "name 2" "name 3" ...
    I already showed you how to do this in response to your last question.
    My second question, for a second script is: how can I count how many  cuePointName with "name 1", "name 2", "name ...." I have in "Mylistcuepoint"?
    It is a list like any other. Iterate through the items looking to see if they match your criterion/criteria and increment your found count (or add indices to a list) as you go:
    tSearch = "name 1"
    tFoundCount = 0
    Mylistcuepoint =  ["reg 01", "reg 2", "name 1, "name 2", "name  3"]
    if Mylistcuepoint.getPos(tSearch) then
      repeat with nn = 1 to count(Mylistcuepoint)
        if ( Mylistcuepoint[nn] = tSearch ) then tFoundCount = tFoundCount +1
      end repeat
    end if

  • TS1314 how can we transfer jpg file to ipad4 with extension name

    how can we transfer jpg file to ipad4 with extension name

    See:
    iOS and iPod: Syncing photos using iTunes
    What do you mean by "with extension name"?

  • How to authenticate a Non domain member laptop with AAA

    Dear all,
    I do have problem in resolving issue for AAA, the scenario is like if a user connect his laptop with a cisco Switch, and the computer is not a member of domain, we do like to allow internet and get an ip from DHCP server only to those users who;s computers are member of active directory. do let me know how is it possible? support will be appreciated.
    Regards
    Ibrahim

    Hi Ibrahim,
    Do you use CiscoSecure ACS?
    If so, this is possible, using AAA/dot1X on the switch and configuring ACS to authenticate against Active Directory.
    There are lots of configuration examples available here:
    http://www.cisco.com/en/US/products/sw/secursw/ps2086/prod_configuration_examples_list.html
    Specifically the wired dot1x; nac: ldap integration with acs; cisco secure acs for windows with eap-tls machine authentication.
    Although some of these are for wireless, I can't see why the principle can not be applied to wired.
    Also there are posts on the learning network:
    https://learningnetwork.cisco.com/thread/2221
    https://learningnetwork.cisco.com/thread/12897
    Regards, Ash.

  • How to authenticate Out of Browser Silverlight application with SharePoint O365 site using SharePoint Web Service (.asmx) ?

    I have Silverlight Out of Browser application which uses SharePoint Lists Service (Lists.asmx). Currently when I trying to communicate to SharePoint O365 site, I am getting  the exception as below -
    Communication Exception -
    The remote server returned an error: NotFound.
    How do I authenticate the user?
    Amol C kadam

    Hi,
    You could follow below article to make sure your application configuration is correct.
    http://www.silverlighthack.com/post/2011/07/19/Office-365-Using-Silverlight-in-the-SharePoint-Team-Site.aspx
    Besides, below article could also give you some help:
    http://www.silverlightshow.net/items/Silverlight-and-Sharepoint-2010-getting-started.aspx
    Best Regards,
    We are trying to better understand customer views on social support experience, so your participation in this interview project would be greatly appreciated if you have time. Thanks for helping make community forums a great place.
    Click
    HERE to participate the survey.

  • How can I disable wifi while playing music with locked ipod touch?

    When I play music and lock the iPod touch, the wifi stays on which drains more battery than is needed. I don't want to turn off wifi in Settings since I like the flexibility to unlock the iPod and quickly check email, browse the web while listing to music (without going into settings, turn it on, browse, go back to settings and turn it off). Once I lock the iPod while playing music, I'd like the wifi to turn off. I know it will stay on while streaming that is expected, but why is the wifi staying on when playing music of the iPod?? Is there a way to do what I am asking? I don't recall having this issue with OS 1.x or 2.x. Also I have seen some posts asking for the opposite (leave the wifi on when not playing music and iPod is locked). These posts acknowledge that wifi stays on while playing music, so it seems to be 'feature' or bug in the OS.

    henry is correct. you can't do that.
    however, for what it's worth, i have found that wifi connection is similar to mobile phone network connection. i.e. if a phone is searching for a network, it takes up huge amounts of battery, but if it is constantly connected, it doesn't. so it is the 'search' procedure which drains the battery. similarly with my iPod touch. if it is connected to my home wifi network, but i am not using the wifi connection, the battery will not drain significantly. it's when i'm away from home and forget to switch it off that the battery drains. or when i am using it constantly (like listening to a 3.5 hr radio show using safari)

  • How to authenticate BPEL process to a PL with Client SSL Cerificate

    Hi,
    I need to invoke a partner link which requires authentication with Client SSL certificate. So, here is the use case:
    - The PL's endpoint is https://some.server.com/web_service;
    - I have a client SSL certificate supplied by the web service provider in the form of PKCS12 (PFX) file. I should use this certificate for authentication.
    I read carefully the BPEL Administration Guide, the part about SSL authentication (http://download.oracle.com/docs/cd/B31017_01/integrate.1013/b28982/security.htm#CHDHIBEG), but in this guide is described how outer services can be authenticated by the BPEL Process Manager with client SSL certificates, not the vice versa.
    So, I completed the following tasks:
    - I imported the server certificate of https://some.server.com/web_service into $ORACLE_HOME/jdk/jre/lib/security/cacerts file;
    - since I didn't find a way to import the client certificate as a PFX file, I converted it PEM file, using OpenSSL utilities and manage to import in cacerts client certificate's public key, but not the private key. Of course this didn't help me in any way to get authenticated.
    I would appreciate any help on this topic!
    Thank you!
    Simeon

    i get this action plan and works for me...
    1. Download the new Client Certificate.
    2. Convert the Client PFX to JKS as per:
    http://www.cb1inc.com/2007/04/30/converting-pfx-certificates-to-java-keystores
    3. Using firefox go to the WSDL site:
    * Add the exception, if Firefox ask for it.
    * Import the server certificate to Firefox following the instructions displayed
    4. Once you imported the certificate on Firefox, go to:
    * Tools -> Options
    * Select Advanced and click on "Encryption" tab
    * Click on View Certificates
    * Go to the Servers tab
    * Select the "servercfa" and click on "Export"
    * Save the certificate adding the .cer extention to the name.
    * Ensure that you select in Save as Type "X.509 Certificate with Chain (PEM)"
    5. Import using keytool the exported certificate from step 4 to the JKS obtained in step
    2:
    * i.e: keytool -import -alias servercert -file servercfa.crt -keystore client.jks -storepass welcome1
    6. Add both keyStore and trustStore properties to the jdev.conf pointing to the same JKS :
    AddVMOption -Djavax.net.ssl.keyStore=C:\jdevstudio10133\jdk\jre\lib\security\client.jks
    AddVMOption -Djavax.net.ssl.keyStorePassword=welcome1
    AddVMOption -Djavax.net.ssl.keyStoreType=JKS
    AddVMOption -Djavax.net.ssl.trustStoreType=JKS
    AddVMOption -Djavax.net.ssl.trustStore=C:\jdevstudio10133\jdk\jre\lib\security\client.jks
    AddVMOption -Djavax.net.ssl.trustStorePassword=welcome1
    7. Open Jdev and retest the issue.
    Tocarli.

  • How to make boot disk for MacBook Pro with Mavericks pre-installed

    Hi -
    I recently bought a new 15" MacBook Pro with Retina Display, which came pre-installed with Mavericks (10.9.0).  I want to make a bootable USB disk of the system software, and have successfly used DiskMaker X (formerly Lion DiskMaker) to make the USB boot disks for Lion and Mountain Lion.  In those cases, however, I was running earlier versions of the OSX, and downloaded the new OSX version -- Lion and Mountain Lion -- from the App Store in order to make to make the disk.  In this case, however, Mavericks was pre-installed, and I was unable to download it from the App Store (an alert said that it couldn't be installed on this computer... presumably because it was already installed).  I would apprecite any suggestions as to how I can create the boot disk without the ability to download Mavericks.  Thanks very much for any help anyone can provide.
    Shelly

    Open App Store and locate the full installer download file (5.29 GBs) for 10.9.1. Download to your computer.
    Make Your Own Mavericks, Mountain/Lion Installer
    After downloading the installer you must first save the Install Mac OS X application. After the installer downloads DO NOT click on the Install button. Go to your Applications folder and make a copy of the installer. Move the copy into your Downloads folder. Now you can click on the Install button. You must do this because the installer deletes itself automatically when it finishes installing.
        2. Get a USB flash drive that is at least 8 GBs. Prep this flash drive as follows:
    Open Disk Utility in your Utilities folder.
    After DU loads select your flash drive (this is the entry with the mfgr.'s ID and size) from the leftside list. Under the Volume Scheme heading set the number of partitions from the drop down menu to one. Set the format type to Mac OS Extended (Journaled.) Click on the Options button, set the partition scheme to GUID then click on the OK button. Click on the Partition button and wait until the process has completed.
    Select the volume you just created (this is the sub-entry under the drive entry) from the left side list.
    Click on the Erase tab in the DU main window.
    Set the format type to Mac OS Extended (Journaled.) Click on the Options button, check the button for Zero Data and click on OK to return to the Erase window.
    Click on the Erase button. The format process can take up to an hour depending upon the flash drive size.
        3. Use DiskMaker X to put your installer clone onto the USB flash drive.
    Make your own Mavericks flash drive installer using the Mavericks tool:
    You can also create a Mavericks flash drive installer via the Terminal. Mavericks has its own built-in installer maker you use via the Terminal:
    You will need a freshly partitioned and formatted USB flash drive with at least 8GBs. Leave the name of the flash drive at the system default, "Untitled." Do not change this name. Open the Terminal in the Utilities folder. Copy this command line after the prompt in the Terminal's window:
    sudo /Applications/Install\ OS\ X\ Mavericks.app/Contents/Resources/createinstallmedia --volume /Volumes/Untitled --applicationpath /Applications/Install\ OS\ X\ Mavericks.app --nointeraction
    Press RETURN. Enter your admin password when prompted. It will not be echoed to the screen so be careful to enter it correctly. Press RETURN, again.
    Wait for the process to complete which will take quite some time.

  • How to add a new server (as shown with "server name" in management studio) and how to delete the old one?

    I am using SQL Express 2008 R2. I have two servers ".\robbysqlexpress" and ".\sqlexpress". The ".\sqlexpress" server is not working. It gives error whenever I try to connect:
    "Cannot connect to (local)\SQLEXPRESS.
    A network-related or instance-specific error occurred while establishing a connection to SQL Server. The server was not found or was not accessible. Verify that the instance name is correct and that SQL Server is configured to allow remote connections.
    (provider: Shared Memory Provider, error: 40 - Could not open a connection to SQL Server) (Microsoft SQL Server, Error: 2)"
    So I want to delete this server and create a server with the same name again. So could you tell me how to do that?
    : Robby

    Hi Robby,
    Can you check that instance of server exists. deleting and recreating will not help you.
    It is really a generic error(and hope your sql server instance exits -> http://community.shavlik.com/docs/DOC-23089).
    please follow this blog post to resolve it -> http://blog.sqlauthority.com/2009/05/21/sql-server-fix-error-provider-named-pipes-provider-error-40-could-not-open-a-connection-to-sql-server-microsoft-sql-server-error/
    Unfortunately, it does not appear to be possible (or at least practical) to only remove certain items.
    However, if you want, you can reset the configuration and start from scratch.
    Make sure Management Studio is closed, then delete or rename this file:
    %APPDATA%\Microsoft\Microsoft SQL Server\100\Tools\Shell\SqlStudio.bin
    Regards Harsh

  • How do i add a header in word with my name with page numbers

    ehdha'da

    In MS Word select View menu -> Header and Footer.
    Type your name.
    Select Insert menu -> Page Numbers...
    In the pop up window select your desired settings and click OK.
    Select 'close' at the bottom of the header area.
    You can edit the header at any time by double clicking on it.

  • How do i insert a signature into emails, with my name address website number etc

    want to do something similar to outlook express where I was able to send a different signature from separate email accts depending on the business I was sending the email from

    This tells you how to use signatures in Thunderbird.
    https://support.mozilla.org/en-US/kb/signatures

  • How to Import pictures in iphoto on ipad with original name

    How to import pictures into iphoto on my ipad air with the original filenames.
    IT now Seems my pictures get a new name.

    When I sync my photo album (from Aperture or iPhoto) to my iPad using iTunes, the filenames remain the same in iPhoto on the iPad, when I browse synced album. Have you tried syncing with iTunes?
    See this link: iTunes: Syncing photos

  • How do I get LR to associate pictures with current PS install

    If I look in an older folder of pictures and choose one that had already been edited in PS and I decide to again edit it Photoshop, it will look to my backup hard drive and start that PS even if I have the current PS from my main HDD running.  How do I get LR to always choose the PS that is on my HDD and not from a backup HDD

    what operating system are you on?

Maybe you are looking for

  • Why won't my apps load to my screen so I can play them after I select them in my App Store

    Tell me how to make the apps come to my screen so I can play with my friends. They show up on my other devises but it ming

  • Process Completion Email flooding Agent Inbox

    Hi Experts, We got a scenario when a user registration process is completed in E-commerce an email will be sent to an agent group. But the agents inbox is flooded with a completion email repetitively for every 2-3 seconds and we checked the following

  • How to determine current state of resource group?

    Good morning! I'm in the process of creating a monitoring policy which would alert if a specific resource group is in a state other than "online". Is there a command line executable available that I could utilize which would return the current status

  • How to Load flash after webpage finished loading

    Hello everyone, I have a problem of running flash on my browser. My flash started to load when my webpage is downloading. I want the browser to completely loaded before the flash starts. Is there a way of solving this problem? My flash file is small

  • Can I store ResultSet in Session

    My resultset contains 2000 records, Is it safe to put the ResultSet in session. Now for 1 user the server contains 2000 records in session, and for 10 users the server will contain 20000 records in session, and so on... This is causing a heavy time d