AnyConnect deploy through SCCM

We need help AnyConnect via Microsoft SCCM deployment. All the world did this and willing to share how they did it. Our AD administrator has not done this before. We deploy 4 msi files, but also a profile folder. We use the SCCM to ensure that users do not uninstall AnyConnect. We want to deploy by using the domain administrator credentials, as some users are not admins and can not install the software. In our first test with the SCCM, we got a message that it was missing a module. Software was on the computer but want to the user permission to run, but no not admin, they couldn't do it.

Thanks for any help.

Here is an example that I used successfully for NAM + module ISE Posture (and no tile VPN). You would of course replace your version for one I've used below:

msiexec /package anyconnect-win-4.2.00096-pre-deploy-k9.msi /norestart /passive PRE_DEPLOY_DISABLE_VPN=1 TRANSFORMS=anyconnect_client_novpn.mst
msiexec /package anyconnect-nam-win-4.2.00096-k9.msi /norestart /passive TRANSFORMS=nam.mst
msiexec /package anyconnect-iseposture-win-4.2.00096-pre-deploy-k9.msi /norestart /passive TRANSFORMS=iseposture.mst
XCopy /Y /F /C /E  "\\\\profile.xml" "c:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\Network Access Manager\newConfigFiles\"

Tags: Cisco Security

Similar Questions

  • From AnyConnect VPN through an RDP Session

    Hello

    We have AnyConnect (ver. 3.1.01065) set up on our ASA5520 boxes. VPN works well from the office, but I also need the ability to establish a VPN connection through a RDP connection (i.e. I use RDP to connect to a PC that has installed AnyConnect, then try to establish a VPN connection).

    I downloaded the Cisco VPN profile editor, chaned the option to 'AllowRemoteUsers '. Then the relevant group policy profile applied. Connected PC (and not via RDP) VPN, so that it downloads the new profile and then disconnected again.

    However, I can't yet start VPN through an RDP connection. (Error is "the ability to set up VPN for remote desktop is disabled.) A VPN connection cannot be established.")

    I checked the file XML on the local PC to confirm the profile was downloaded (and is, and I do not see the option AllowRemoteUsers.)

    This has also happened with the previous AnyConnect version (3.0.xxxx).

    Local routing tables of the PC look good, and I don't see any conflicts that would cause the RDP session to drop.

    Also - if I connect the VPN, then RDP on the PC, the VPN and the RDP sessions work fine.

    Any ideas would be appreciated!

    Thank you

    Tony

    Hi Tony,.

    To do this both the ASA and the client must have the same XML profile.

    I just tested this with AC 3.1 and ASA 8.4 and it works beautifully.

    I included the XML file.

    * BTW, make sure that the profile is assigned to the appropriate group strategy.

    HTH.

    Portu.

    Please note all useful posts

  • admin password to NSX Edge device deployed through vRA

    Help

    Deployment NSX Edge device without vRA, must enter the admin for NSX edge device password according to the following document:

    Add a gateway of on-board service

    However, we don't need to enter the password to NSX edge through vRA appliance admin. So I can't connect in edge device. What is the default password?

    If you really need to get into the console of an edge deployed, you can:

    • Open vSphere Web Client and access networks & security
    • Once there, click on Edges NSX and locate the edge that you need to access
    • Right-click on the edge, then select credentials of Climate change

    WARNING/WARNING: I'm not sure whether or not this can cause problems. I strongly suggest it be tested on a test deployment of not filing confirm that it has no harmful effect.

  • Adobe Creative Enterprise Cloud deployment with SCCM R2 2012 problems

    Hello

    I tried to deploy Adobe Creative Enterprise Cloud to 8.1 of Windows machines that are identical, using SCCM 2012 R2.

    The Adobe package seems well, because it seems to deploy successfully on some machines. SCCM R2 2012 has been configured correctly, that I can deploy other software use, and even once, he deploys Adobe CC successfully on some of the machines.

    I tried to compare the package is downloaded to the computer client/test machine, with the original on the distribution using Beyond Compare, and there is no difference.

    I contacted Adobe Enterprise Support and they asked me to send in the Event Viewer logs, the installer msi and other newspapers from Adobe, the machine failed deployment. However, after Adobe study them, they told me that they could not identify any problem... Strange, because I could have sworn I saw error 1603 pop up more than 20 times on different machines, which indicates that the "Set - up.dat' file had a problem with it."

    After all the tests on more than 20 machines identical (same hardware / software), using the different settings on SCCM 2012 R2 and client machines, I still happen to have a reliable solution for the deployment of Adobe CC.

    The fact that it deploys successfully on the same machine and it fails on another, or sometimes deploy on two machines and fail on another (simultaneously), is something I don't understand.

    Another thing is that, if I try the deployment of 10 to 15 times after she failed the first time, it could pass by...

    Adobe Enterprise Support asked me if they could remote into a machine that doesn't have the deployment to take a look at it and I have agreed to this option, but it seems that my problem was ignored because they never to return for me.

    Someone had this kind of problem or something similar before?

    I need to be able to deploy 100 machines remotely. Manual installation is not an option.

    Any help is appreciated.

    This forum is really more about individuals and the cloud, these are the only links that I...

    Packer links https://forums.adobe.com/thread/1586021

    http://forums.Adobe.com/community/download_install_setup/creative_suite_enterprise_deploym ent

  • AnyConnect FireSight through ISE user

    Hello!

    We installed the ISE 2.1 for AAA process for users VPN to ASA5545x. AnyConnect users authenticate successfully and you can see the username within newspaper at ISE. Also we have modules of firepower in the ASA and the virtual appliance FireSight 6.1. How we can use ISE as a source of identity for FireSight?

    Inspect traffic to the power of fire based on groups of users, or a user.

    Thanks for the help.

    Hello Serge, you can certainly do that by integrating both via PxGrid.

    Thank you for evaluating useful messages!

  • Cisco AnyConnect deployment

    We are currently using Cisco VPN Client.  I'm looking to migrate to Cisco Any Connect.  Our ASA 5520 has 750 IPSec and SSL 2 license.  I also have about 40 IPSec VPN site-to-site on it.  Here's what I want to know?

    1 - anyconnect will interfere with site to site tunnels?

    2 if I place anyconnect with IPSec instead of SSL can I still purchase the license premium or essentials?

    3 lets say if I have to get the permit and I get essentials it will cause problems with the VPN site to site?

    Thank you.

    1 n ° not at all.

    2 Anyconnect Essentials licenses the ASA of the IPSec remote VPN access using w/IKEv2 and SSL VPN AnyConnect client. Premium adds based on a browser (clientless) SSL VPN, Cisco Secure Desktop support, possibility of Advanced endpoint assessment, and use shared pools of license in a cluster of the SAA. Note This Essentials and Premium AnyConnect license cannot coexist on a given ASA. Once you register any AnyConnect Premium feature, it excludes the possibility of also using essential AnyConnect licenses (on the ASA).

    3 see #1.

  • 11.5.2.602 MSI only deployment with SCCM

    I downloaded the msi file and try to install it on our 10,000 stations using sccm.  It works fine normally.  But this time, the program is pushed and all the log files say that it is correctly installed.  But if you go to a Web page that uses shockwave you get a message that you need to install the program...  The executable is correct and in the right place C:\WINDOWS\system32\Macromed\Shockwave 10\SwInit.exe

    If I run the msi file locally it installs without any problem.  So I can't figure why this is happening.  Has anyone else seen elsewhere.  We are running XP with sp3 on all of our stations.

    Thank you

    I use (in a vbscript script)

    WshShell.Run "sw_lic_full_installer.msi TRANSFORMS = settings.mst number! / norestart/l C:\SWP11INST.log ALLUSERS = 1 ", 1, True

    It is a command line that I have inhertitted of the previous versions, the switches have not been chosen by me.  Maybe it's the ALLUSERS = 1 which is implemented?

    The mst is simply by changing a few settings, see http://forums.adobe.com/thread/517867?tstart=0 , but should not be what makes the difference.

  • VMware View 4.5 - number of virtual machines deployment through Virtual Center

    Hello

    After an update to VMware View 4.5 Solution, thanks to an automatic pool sliding the virtual Center creates now six machines at the same time.

    Before this update the VC never fired on two machines at the same time...

    It of Nice to have this indictment, but is it possible for me to configure the number of virtual machines created on same time?

    Thanks for your help

    Kind regards

    If you go into servers and change the login information from vCenter there is an Advanced tab.  Click this tab and you can set the maximum amount of concurrent provisioning operations you want.

    If you have found this device or any other useful post please consider the use of buttons useful/correct to award points

    Twitter: http://twitter.com/mittim12

  • SCCM software update

    In our environment, we will deploy through SCCM security patches. Now, we know we need to disable the option of automatic update via GPO to all customers and if so, how they will be linked with SCCM for the latest patches. Don't we have to specify the name of the SCCM server through GPO so that all customers go to the SCCM server for the latest patches instead of going on the WSUS Microosft internet server by default.

    See you soon,.
    Steve

    Hello

    The question you have posted is related to professional level support. Please visit the below mentioned link to find a community that will support what ask you:

    http://TechNet.Microsoft.com/en-us/SystemCenter/bb507744.aspx

  • Deployment of Camera Raw Photoshop CS6

    Anyone knows how I can deploy through SCCM? Can't find any help here...

    Packer links https://forums.adobe.com/thread/1586021

    http://forums.Adobe.com/community/download_install_setup/creative_suite_enterprise_deploym ent

  • SCCM 2012 detection method

    Hello

    Does anyone know if there is a guide of SCCM 2012 deployment for Adobe CC products?

    I checked this CC guide help | Package from Adobe with SCCM deployment , but it is the old method of package, prefer the SCCM 2012 applications.

    If no guide for SCCM 2012, is it perhaps a list of methods of detection for each adobe application.  (I tried the method of detection of MSI, but it seems that adobe are those wrappers, so do not work.  The only way that I've found so far is to install the application, and search for the appropriate reg key HKLM... Uninstall and use it.  It's a little hassle to go through and install each of them just to get the key "reg" well.  I'll have to do this for all new deployments (cloud creative), I'll be able to use the current system for Creative Suite, so they are not so bad.

    For anyone referring to it later, I get a message "does not meet the minimum requirements" if I use the msi as a method of detection.

    I tested with Photoshop (by installing and accessing the "reg" key) and it solves the problem of "minimum requirements".

    An example of the key "reg" is this for Adobe Web and Design Premium CS6

    HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ {402F6F2E-5683-491C-9-77 d-0CA599A07CAF}


    Hello

    I apologize for the inconvenience. We provide a standard msi installation program of deployment via SCCM. Creative cloud Packager creates a native installer to use via SCCM. The proceedings will remain same as other .msi that you deploy through SCCM.

    You can follow the installation using GUID.or software ID Tag instances. Here is the article itself.

    http://wwwimages.Adobe.com/content/dam/Adobe/en/DevNet/creativesuite/PDFs/Swid-CC-FAQ.PDF

    Thank you
    Ashish

  • Exit Code 19 / silent deployment of CS5 / Skip process check

    Dear people,

    I do not even start talking about how frustrated I am, so here's my problem:

    I want to deploy through SCCM CS5 in silent mode. Our company has licenses for Adobe Creative Suite 5 Standard, so I can't use the enterprise deployment tool. Be it, after that I have spend hours to get silent installation to work, I find myself with an exit code 19, which indicates that the Setup program is a process that disrupts the installation. The process Firefox.exe and I would like to than the installer to ignore the process runs. In CS4, I used the 'SkipProcessCheck = 1' option but CS5 seems to ignore my wish ;-)

    Here my syntax:

    \\server\SMSSoftware\Adobe\Adobe CS5\set - up.exe - DeploymentFiles = "\\server\SMSSoftware\Adobe\Adobe.xml" - overrideFile = "\\server\SMSSoftware\Adobe\Adobe CS5\payloads\AdobeDesignStandard5-mul\application.xml.override" - skipProcessCheck = 1

    In addition, if you use install.xml instead of a full path, either c:/.../install.xml or / / server/.../install.xml, you will get an error message that Setup cannot find file deployment...

    Anone an idea how I can convince Mr set up to ignore the process?

    Thank you and have a great day!

    Hello

    You can try the new business solution that is available. Please visit the following links.

    http://blogs.Adobe.com/OOBE/2010/06/adobe_application_manager_ente.html

    http://www.Adobe.com/devnet/creativesuite/enterprisedeployment.html

  • Creating an MSI package for distribution through a network

    How can I create an msi package adobe reader version 9.2 without the help of Adobe Customization Wizard to deploy the package over the network to a massive installation?

    I tried to generate with the adobe Customization Wizard, but the msi should I modify it is void because it obtained by installing free software (to install is created in program files) and does not.

    I get an MSI for the edition in the Customization Wizard?
    I extracted a reader 9.2 executable?. If so, the free version is available in the site does not give me the possibility to extract to get the msi file.

    Thank you very much.

    Why is it you oppose the use of the generator package? You can use winzip to extract the msi on the exe file. The wizard creates just the file for you allows you to deploy through SCCM or depending on the tool you are using.

  • Setting up command line options Toshiba VAP - Support Button-

    Hello

    I need to configure the button Support drivers for laptops of the Portege series as part of the deployment of Windows 7 x 64 bit Enterprise on the following models: Z830, Z930 and R930.

    I need to install Toshiba value added package with Flash card option only.
    What command line options are present to do that?
    I'm looking for it deploy through SCCM.

    Thank you

    Hello

    My knowledge of the value of added Toshiba contains various simple applications of Toshiba. These applications must be installed one after the other.
    You will need to run the setup.exe / installation.exe for the procedure to start the other options are not known to me

  • Laptop HP Pavilion G4

    One of my office is currently using PC HP laptop Pavilion G4 does anyone know for these machines, you can download the drivers via the HP Softpaq Manager to download. I need to do this is because I have to deploy through SCCM and want to use SSM drivers for these machines.

    Thanks in advance

    Hello..  HP Softpaq Download Manager is designed to work with PC HP customer models. As the model you are talking about (G4 series) which falls as a PC user, I can't guarantee the functionality. Please see the link which gives the list of the supported below products:

    http://auth-hpcom-h20331-hpsub-Pro-SiteBuilder.Houston.HP.com/hpsub/downloads/new%20Client%20Management%20Solution%20Platform%20Support.PDF

    As there is no specific guidelines or information to find out if the G4 series notbooks will work with the Download Manager, the only way is to try it at your own risk. You can try to install the HP Softpaq Download Manager in the G4 series laptop PC and order features at your own risk. The following site has a link to download the application.

    http://h20331.www2.HP.com/Hpsub/cache/509658-0-0-225-121.html

    Personally, I think it should work, but as I said not tried myself, nor I know personally all those who tried. If someone else on this forum it tried earlier, please give your suggestion as well.

Maybe you are looking for