You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows下通过CLI使用带DUO MFA的Cisco AnyConnect登录VPN问题

Cisco AnyConnect CLI 自动登录DUO MFA失败的解决方法

问题背景

通过AnyConnect UI可正常登录VPN,计划用Windows CLI结合C#实现自动化登录。采用常见命令 vpncli.exe -s < vpn.creds,但因端点需DUO MFA,按服务商要求在creds文件中加入"push"指令触发移动端确认时,登录始终失败。当前vpn.creds文件内容:

connect <hostname>
<user>
<pass>
push

排查与解决步骤

  • 指定vpncli完整路径:命令中需使用vpncli.exe的绝对路径,例如 "C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpncli.exe",避免系统无法定位程序。
  • 匹配交互流程调整creds顺序:部分VPN端点会在密码后单独询问MFA验证,需先手动执行 vpncli.exe -s,观察每一步的输入提示,确保creds文件的每一行对应一个交互请求。比如手动交互流程为:
    vpncli.exe -s
    connect <hostname>
    Enter Username: <user>
    Enter Password: <pass>
    Enter Second Password: push
    
    则creds文件需严格遵循该顺序,保证输入与提示一一对应。
  • 修正文件编码:Windows CLI对编码敏感,需将vpn.creds保存为UTF-8无BOM格式,避免换行符或字符识别错误。
  • C#程序直接写入输入(替代文件重定向):在C#中调用时,通过进程的StandardInput直接写入登录指令,比文件重定向更可控,示例代码:
    var psi = new ProcessStartInfo
    {
        FileName = @"C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpncli.exe",
        Arguments = "-s",
        RedirectStandardInput = true,
        UseShellExecute = false,
        CreateNoWindow = true
    };
    
    using (var process = Process.Start(psi))
    {
        if (process != null)
        {
            var loginCommands = $"connect <hostname>\n<user>\n<pass>\npush\n";
            process.StandardInput.Write(loginCommands);
            process.StandardInput.Close();
            process.WaitForExit();
        }
    }
    
  • 确认DUO权限配置:联系企业管理员,确认你的账号是否被授权使用"push"方式进行MFA验证,部分场景下该验证方式可能被限制。

内容的提问来源于stack exchange,提问作者xRavisher

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 16:35:07