Document preview
Connect to the VPN on a new laptop · Knowledge Article
Connect to the VPN on a new laptop · Knowledge Article
Knowledge Article

Connect to the VPN on a new laptop

Install and configure Cisco AnyConnect so a newly issued or re-imaged laptop can reach internal systems (NetSuite, Coupa, file shares) from outside the office network.


Article IDKB-IT-0067
Version1.4
EffectiveJul 4, 2026
Document TypeKnowledge Article
Document OwnerSam Reyes — Service Desk Analyst II
DepartmentInformation Technology
Approver(s)Joelle Park — IAM Manager
Review CycleJul 4, 2026 → Jul 4, 2027
ClassificationInternal · All Employees
Connect to the VPN on a new laptop · Knowledge Article
01

Article details

At a glance
TitleConnect to the VPN on a new laptop
Article IDKB-IT-0067
Version / release1.4
StatusPublished
OwnerSam Reyes — Service Desk Analyst II
AudienceAll employees and contractors issued a new or re-imaged laptop
Last reviewed2026-07-04
Review cadenceEvery 12 months
Discovery
Article type: How-to · Setup
Category: Remote Access
Subcategory: New device setup
Tags: vpn, anyconnect, new laptop, remote access, zscaler, setup
Governance
Created date: 2024-11-14
Related tickets: INC-24410, INC-24618, PRB-0201
Affected system: Cisco AnyConnect, Microsoft Entra ID (MFA), Zscaler Client Connector
Module / area: Network Access
02

Revision history

Version Date Author Summary
1.42026-07-04Sam ReyesAdded Zscaler Client Connector step, now bundled with AnyConnect on all new images.
1.22025-06-01Sam ReyesUpdated screenshots for AnyConnect 4.10; added MFA push troubleshooting.
1.02024-11-14Joelle ParkInitial publication.
Connect to the VPN on a new laptop · Knowledge Article
03

Issue summary

New and re-imaged laptops ship with Cisco AnyConnect and Zscaler Client Connector pre-installed but not configured. Employees working remotely or from a non-Nexstream network need to complete a one-time connection setup — entering the VPN gateway address and authenticating with Entra ID MFA — before internal systems like NetSuite, Coupa, and file shares become reachable.

04

Symptoms / how to identify

Exact error message(s)"Connection attempt has failed" — Cisco AnyConnect "This server address is not in the profile" — AnyConnect "Unable to reach server" — internal file share / NetSuite
Observed behaviorAnyConnect opens but the connect box is empty or shows a placeholder gateway. Internal-only sites time out. Wi-Fi/Ethernet shows connected to the internet, but nothing internal resolves.
Affected users / conditionsAny employee or contractor on a laptop that has never completed first-time VPN setup — most commonly new hires and anyone who just received a replacement or re-imaged device.
05

Resolution narrative

Prerequisites• Laptop has completed initial Okta/Entra sign-in and is enrolled in Intune. • You have Microsoft Authenticator set up on your phone (see KB-IT-0041). • You know your Nexstream network username (same as email, without the domain).
Expected output at completionAnyConnect shows "Connected" with a green padlock, Zscaler Client Connector shows "Protected," and the user can reach NetSuite, Coupa, and \\files.acmelogistics.net without further prompts.
Connect to the VPN on a new laptop · Knowledge Article
06

Resolution steps

01 Open Cisco AnyConnect and enter the Acme gateway address.

Launch AnyConnect from the system tray (Windows) or menu bar (macOS). If the connect box is empty, type vpn.acmelogistics.com and click Connect. AnyConnect will download the connection profile automatically on first use — this can take up to a minute.

AnyConnect Secure Mobility Client
Cisco AnyConnect
Connect to a corporate network
VPN gateway
vpn.acmelogistics.com
Connect
Fig 1 — First-time connection screen. The gateway address only needs to be typed once.
02 Sign in with your Acme username and password.

Use the same username and password as Windows/macOS sign-in — do not add the "@acmelogistics.com" suffix here, AnyConnect adds it automatically. This is the identity check before MFA.

Note: If your password recently changed (see KB-IT-0042), give it up to five minutes to propagate before trying AnyConnect.
03 Approve the MFA push on your phone.

Within a few seconds you'll get a Microsoft Authenticator push notification. Tap it, confirm the two-digit number matches what's shown in AnyConnect, and approve. AnyConnect will then show "Connected."

Suspicious push: If you get a push you didn't request, deny it and call the Service Desk at x4357 immediately — do not approve "just to make it stop."
04 Confirm Zscaler Client Connector shows "Protected."

Zscaler runs alongside AnyConnect and handles web traffic filtering. Click the Zscaler icon in the system tray/menu bar — it should read Protected within about 15 seconds of the VPN connecting. If it instead shows "Not Enrolled," restart the laptop once; this is the most common fix.

Connect to the VPN on a new laptop · Knowledge Article
07

Workaround

WorkaroundDocumented (see fields below)
Tracked inKB-IT-0067-WA1
Workaround stepsIf AnyConnect cannot download the connection profile (common on very restrictive home/hotel Wi-Fi), tether to a phone hotspot for the first-time setup only. Once the profile is cached locally, subsequent connections work on any network.
Limitations / risksThis is a one-time workaround for initial setup — it does not fix ongoing connectivity issues on restrictive networks. Persistent failures should be escalated (see below) rather than repeatedly tethering.
08

Verification / confirmation

Verification stepsAsk the user to open a browser and navigate to an internal-only page, such as the NetSuite login. A successful page load with no timeout confirms the VPN tunnel and Zscaler policy are both active.
User confirmation requiredNo — Service Desk can confirm via the Cisco ASA session log if remote-assisting.
09

Escalation

Escalate toNetwork Engineering — netops@acmelogistics.com (group manager: Dev Patel)
Assignment groupNET-OPS (ServiceNow)
Include in ticketLaptop asset tag; AnyConnect version (Help → About); exact error text; whether MFA push arrived at all; network type (home Wi-Fi, hotel, mobile hotspot).
10

Exception Handling

If… Then…
AnyConnect installs but shows "No valid certificates"Enroll the device in Jamf/Intune first (follow KB-IT-0082), then reinstall AnyConnect and retry.
MFA push never arrives after 3 attemptsCheck mobile data/Wi-Fi on the authenticator device; if the issue persists, call IT at x4357 to reset your MFA profile.
VPN connects but internal resources are unreachableDisconnect, run Zscaler checks per KB-IT-0071, then reconnect — split-tunnel misconfiguration is the most common cause.
11

Notes and Tips

Note: If AnyConnect prompts for a "secondary password" instead of an Authenticator push, your device may be enrolled in a legacy MFA profile. Open a ticket with IT (tag: vpn-mfa-migration) before proceeding — approving the wrong prompt can lock the account.
  • Connecting via a mobile hotspot? Enable Allow VPN on cellular in AnyConnect → Preferences — it is off by default and causes silent drops.
  • Reboot AnyConnect (quit from the menu bar, then reopen) before calling the Service Desk — the majority of first-call issues resolve with a clean restart.
  • Once connected, bookmark intranet.acmelogistics.com/it/vpn-status to confirm your session is active without opening a full support ticket.
12

Related articles & references

ReferencesKB-IT-0041 — Set up Microsoft Authenticator on a new phone KB-IT-0042 — Reset your Nexstream network password KB-IT-0071 — Zscaler shows "Not Enrolled" after a Windows update POL-IT-009 — Nexstream remote access & VPN standard