Solved

Cisco Clientless VPN SSL issues with ISS

Posted on 2008-10-17
9
893 Views
Last Modified: 2008-10-29
I have a question. Im setting up a server that supports OWA and outlook anywhere.
I have a asas 5505 that i want to set up with SSL vpn so that remote users can launch Remote desktop and access their own computer in the office. When i go to https://asa5505outsideip i go to the iss menu.

Any input?

0
Comment
Question by:daxa78
  • 2
  • 2
  • 2
  • +2
9 Comments
 
LVL 15

Expert Comment

by:wingatesl
ID: 22745952
Can you post the config from the ASA please
Shawn
0
 
LVL 1

Author Comment

by:daxa78
ID: 22746209
I have not done the modifications to the asa yet but the example from cisco says that i should go to
https://externaipoftheasa when i am finished with the setup to get ssl vpn access-

But when i try to go to that site today i get to IIS and i was wondering how i would work around this?
I still need the OWA to work, so i can disable the entire IIS


0
 
LVL 5

Expert Comment

by:rexxus
ID: 22746245
Do you have a static NAT pointing external traffic to your IIS box?
0
Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

 
LVL 15

Assisted Solution

by:wingatesl
wingatesl earned 100 total points
ID: 22746257
The best thing would be to configure the ssl vpn on a nonstandard port. I usually use port 1025 for all installations.
0
 
LVL 57

Accepted Solution

by:
Pete Long earned 200 total points
ID: 22746284
>>I still need the OWA to work, so i can disable the entire IIS

publish OWA on the Clientless portal? you should ony have a problem if you need Direct Push EMail or if you need to forward Https - because once you enable webvpn on the outside interface you cannot forward https.

The only way round that problem is to have another external interface (which means having a security plus licensed firewall)

>>so that remote users can launch Remote desktop and access their own computer in the office. When i go to

yeah you can do that as well from the portal - there is a Java RDP applet that you can use to RDP straight from the portal

0
 
LVL 79

Expert Comment

by:lrmoore
ID: 22746666
You can run the VPN on a different port, say 444 and still forward 443 to the OWA server
Then for vpn you access it by https://outsideip:444
0
 
LVL 1

Author Comment

by:daxa78
ID: 22762960
How do i set that to use a diffrent port?

Do i need to purchase a certificate or does the asa box issue one ?
0
 
LVL 79

Assisted Solution

by:lrmoore
lrmoore earned 200 total points
ID: 22763026
You can use the self-signed cert. Users will get warnings, but can either ignore them or install the cert into the trusted root list on their pc.

If using ASDM, under Configuration | Remote Access VPN | Clientless SSL VPN Access | Connection profiles
In the right pane, see  Access Port: [443  ]   <== change the port here


0
 
LVL 57

Expert Comment

by:Pete Long
ID: 22832761
ThanQ
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

I recently updated from an old PIX platform to the new ASA platform.  While upgrading, I was tremendously confused about how the VPN and AnyConnect licensing works.  It turns out that the ASA has 3 different VPN licensing schemes. "site-to-site" …
This is an article about my experiences with remote access to my clients (so that I may serve them) and eventually to my home office system via Radmin Remote Control. I have been using remote access for over 10 years and have been improving my metho…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now