Never had to one of these before - and foolishly I just followed the Wizard and
http://www.cisco.com/en/US/docs/security/asa/asa80/getting_started/asa5505/quick/guide/ssl_vpn.html After completion of the Wizard it says...
"Please make sure to add the right nat exemption rul for the above selected pool to the firewall > Nat Rules Panel"
Well I manually added it and tried it in both directions and it maked no difference :(
I can get to the portal and launch the client it gets all the way to the end and goes (screenshot attached)
config
: Saved
:
ASA Version 8.0(4)
!
hostname ciscoasa
domain-name xxxxxxx.net
enable password 6F9WTj1TxzG5ntGC encrypted
passwd 6F9WTj1TxzG5ntGC encrypted
names
name 172.16.40.0 vpn
dns-guard
!
interface Ethernet0/0
nameif outside
security-level 0
ip address 217.22.123.123 255.255.255.248
!
interface Ethernet0/1
nameif inside
security-level 100
ip address 172.16.254.250 255.255.255.0
!
interface Ethernet0/2
shutdown
no nameif
no security-level
no ip address
!
interface Ethernet0/3
shutdown
no nameif
no security-level
no ip address
!
interface Management0/0
nameif management
security-level 100
ip address 192.168.1.1 255.255.255.0
management-only
!
boot system disk0:/asa804-k8.bin
ftp mode passive
dns server-group DefaultDNS
domain-name coniston-it.net
access-list inside_nat0_outbound extended permit ip 172.16.254.0 255.255.255.0 vpn 255.255.255.0
pager lines 24
logging asdm informational
mtu outside 1500
mtu inside 1500
mtu management 1500
ip local pool pool456 172.16.40.1-172.16.40.254 mask 255.255.255.0
icmp unreachable rate-limit 1 burst-size 1
asdm image disk0:/asdm-613.bin
no asdm history enable
arp timeout 14400
global (outside) 1 interface
nat (inside) 0 access-list inside_nat0_outbound outside
nat (inside) 1 0.0.0.0 0.0.0.0
route outside 0.0.0.0 0.0.0.0 217.22.123.126 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
dynamic-access-policy-reco
rd DfltAccessPolicy
http server enable
http 172.16.254.0 255.255.255.0 inside
http 192.168.1.0 255.255.255.0 management
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
crypto ipsec security-association lifetime seconds 28800
crypto ipsec security-association lifetime kilobytes 4608000
telnet 172.16.254.0 255.255.255.0 inside
telnet timeout 30
ssh timeout 5
console timeout 0
dhcpd address 192.168.1.2-192.168.1.254 management
dhcpd enable management
!
threat-detection basic-threat
threat-detection statistics access-list
no threat-detection statistics tcp-intercept
webvpn
enable outside
svc image disk0:/anyconnect-win-2.2.
0136-k9.pk
g 1
svc enable
group-policy 456 internal
group-policy 456 attributes
vpn-tunnel-protocol svc
username petelong password xxxxxxxxxxxxxx encrypted privilege 0
username petelong attributes
vpn-group-policy 456
tunnel-group 123 type remote-access
tunnel-group 123 general-attributes
address-pool pool456
default-group-policy 456
!
class-map inspection_default
match default-inspection-traffic
!
!
policy-map type inspect dns migrated_dns_map_1
parameters
message-length maximum 512
policy-map global_policy
class inspection_default
inspect dns migrated_dns_map_1
inspect ftp
inspect h323 h225
inspect h323 ras
inspect rsh
inspect rtsp
inspect esmtp
inspect sqlnet
inspect skinny
inspect sunrpc
inspect xdmcp
inspect sip
inspect netbios
inspect tftp
inspect icmp
!
service-policy global_policy global
prompt hostname context
Cryptochecksum:2830b494d40
5fee3548f7
6c82231f64
2
: end
asdm image disk0:/asdm-613.bin
asdm location vpn 255.255.255.0 inside
no asdm history enable
Start Free Trial