Install and configure Cisco AnyConnect so a newly issued or re-imaged laptop can reach internal systems (NetSuite, Coupa, file shares) from outside the office network.
| Title | Connect to the VPN on a new laptop |
| Article ID | KB-IT-0067 |
| Version / release | 1.4 |
| Status | Published |
| Owner | Sam Reyes — Service Desk Analyst II |
| Audience | All employees and contractors issued a new or re-imaged laptop |
| Last reviewed | 2026-07-04 |
| Review cadence | Every 12 months |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.4 | 2026-07-04 | Sam Reyes | Added Zscaler Client Connector step, now bundled with AnyConnect on all new images. |
| 1.2 | 2025-06-01 | Sam Reyes | Updated screenshots for AnyConnect 4.10; added MFA push troubleshooting. |
| 1.0 | 2024-11-14 | Joelle Park | Initial publication. |
New and re-imaged laptops ship with Cisco AnyConnect and Zscaler Client Connector pre-installed but not configured. Employees working remotely or from a non-Nexstream network need to complete a one-time connection setup — entering the VPN gateway address and authenticating with Entra ID MFA — before internal systems like NetSuite, Coupa, and file shares become reachable.
| Exact error message(s) | "Connection attempt has failed" — Cisco AnyConnect "This server address is not in the profile" — AnyConnect "Unable to reach server" — internal file share / NetSuite |
| Observed behavior | AnyConnect opens but the connect box is empty or shows a placeholder gateway. Internal-only sites time out. Wi-Fi/Ethernet shows connected to the internet, but nothing internal resolves. |
| Affected users / conditions | Any employee or contractor on a laptop that has never completed first-time VPN setup — most commonly new hires and anyone who just received a replacement or re-imaged device. |
| Prerequisites | • Laptop has completed initial Okta/Entra sign-in and is enrolled in Intune. • You have Microsoft Authenticator set up on your phone (see KB-IT-0041). • You know your Nexstream network username (same as email, without the domain). |
| Expected output at completion | AnyConnect shows "Connected" with a green padlock, Zscaler Client Connector shows "Protected," and the user can reach NetSuite, Coupa, and \\files.acmelogistics.net without further prompts. |
Launch AnyConnect from the system tray (Windows) or menu bar (macOS). If the connect box is empty, type vpn.acmelogistics.com and click Connect. AnyConnect will download the connection profile automatically on first use — this can take up to a minute.
Use the same username and password as Windows/macOS sign-in — do not add the "@acmelogistics.com" suffix here, AnyConnect adds it automatically. This is the identity check before MFA.
Within a few seconds you'll get a Microsoft Authenticator push notification. Tap it, confirm the two-digit number matches what's shown in AnyConnect, and approve. AnyConnect will then show "Connected."
Zscaler runs alongside AnyConnect and handles web traffic filtering. Click the Zscaler icon in the system tray/menu bar — it should read Protected within about 15 seconds of the VPN connecting. If it instead shows "Not Enrolled," restart the laptop once; this is the most common fix.
| Workaround | Documented (see fields below) |
| Tracked in | KB-IT-0067-WA1 |
| Workaround steps | If AnyConnect cannot download the connection profile (common on very restrictive home/hotel Wi-Fi), tether to a phone hotspot for the first-time setup only. Once the profile is cached locally, subsequent connections work on any network. |
| Limitations / risks | This is a one-time workaround for initial setup — it does not fix ongoing connectivity issues on restrictive networks. Persistent failures should be escalated (see below) rather than repeatedly tethering. |
| Verification steps | Ask the user to open a browser and navigate to an internal-only page, such as the NetSuite login. A successful page load with no timeout confirms the VPN tunnel and Zscaler policy are both active. |
| User confirmation required | No — Service Desk can confirm via the Cisco ASA session log if remote-assisting. |
| Escalate to | Network Engineering — netops@acmelogistics.com (group manager: Dev Patel) |
| Assignment group | NET-OPS (ServiceNow) |
| Include in ticket | Laptop asset tag; AnyConnect version (Help → About); exact error text; whether MFA push arrived at all; network type (home Wi-Fi, hotel, mobile hotspot). |
| If… | Then… |
|---|---|
| AnyConnect installs but shows "No valid certificates" | Enroll the device in Jamf/Intune first (follow KB-IT-0082), then reinstall AnyConnect and retry. |
| MFA push never arrives after 3 attempts | Check mobile data/Wi-Fi on the authenticator device; if the issue persists, call IT at x4357 to reset your MFA profile. |
| VPN connects but internal resources are unreachable | Disconnect, run Zscaler checks per KB-IT-0071, then reconnect — split-tunnel misconfiguration is the most common cause. |
| References | KB-IT-0041 — Set up Microsoft Authenticator on a new phone KB-IT-0042 — Reset your Nexstream network password KB-IT-0071 — Zscaler shows "Not Enrolled" after a Windows update POL-IT-009 — Nexstream remote access & VPN standard |