?
Solved

Cisco Clientless VPN SSL issues with ISS

Posted on 2008-10-17
9
Medium Priority
?
904 Views
Last Modified: 2008-10-29
I have a question. Im setting up a server that supports OWA and outlook anywhere.
I have a asas 5505 that i want to set up with SSL vpn so that remote users can launch Remote desktop and access their own computer in the office. When i go to https://asa5505outsideip i go to the iss menu.

Any input?

0
Comment
Question by:daxa78
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
  • 2
  • +2
9 Comments
 
LVL 15

Expert Comment

by:wingatesl
ID: 22745952
Can you post the config from the ASA please
Shawn
0
 
LVL 1

Author Comment

by:daxa78
ID: 22746209
I have not done the modifications to the asa yet but the example from cisco says that i should go to
https://externaipoftheasa when i am finished with the setup to get ssl vpn access-

But when i try to go to that site today i get to IIS and i was wondering how i would work around this?
I still need the OWA to work, so i can disable the entire IIS


0
 
LVL 5

Expert Comment

by:rexxus
ID: 22746245
Do you have a static NAT pointing external traffic to your IIS box?
0
Create the perfect environment for any meeting

You might have a modern environment with all sorts of high-tech equipment, but what makes it worthwhile is how you seamlessly bring together the presentation with audio, video and lighting. The ATEN Control System provides integrated control and system automation.

 
LVL 15

Assisted Solution

by:wingatesl
wingatesl earned 400 total points
ID: 22746257
The best thing would be to configure the ssl vpn on a nonstandard port. I usually use port 1025 for all installations.
0
 
LVL 57

Accepted Solution

by:
Pete Long earned 800 total points
ID: 22746284
>>I still need the OWA to work, so i can disable the entire IIS

publish OWA on the Clientless portal? you should ony have a problem if you need Direct Push EMail or if you need to forward Https - because once you enable webvpn on the outside interface you cannot forward https.

The only way round that problem is to have another external interface (which means having a security plus licensed firewall)

>>so that remote users can launch Remote desktop and access their own computer in the office. When i go to

yeah you can do that as well from the portal - there is a Java RDP applet that you can use to RDP straight from the portal

0
 
LVL 79

Expert Comment

by:lrmoore
ID: 22746666
You can run the VPN on a different port, say 444 and still forward 443 to the OWA server
Then for vpn you access it by https://outsideip:444
0
 
LVL 1

Author Comment

by:daxa78
ID: 22762960
How do i set that to use a diffrent port?

Do i need to purchase a certificate or does the asa box issue one ?
0
 
LVL 79

Assisted Solution

by:lrmoore
lrmoore earned 800 total points
ID: 22763026
You can use the self-signed cert. Users will get warnings, but can either ignore them or install the cert into the trusted root list on their pc.

If using ASDM, under Configuration | Remote Access VPN | Clientless SSL VPN Access | Connection profiles
In the right pane, see  Access Port: [443  ]   <== change the port here


0
 
LVL 57

Expert Comment

by:Pete Long
ID: 22832761
ThanQ
0

Featured Post

Manage your data center from practically anywhere

The KN8164V features HD resolution of 1920 x 1200, FIPS 140-2 with level 1 security standards and virtual media transmissions at twice the speed. Built for reliability, the KN series provides local console and remote over IP access, ensuring 24/7 availability to all servers.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Let’s list some of the technologies that enable smooth teleworking. 
This article explains the fundamentals of industrial networking which ultimately is the backbone network which is providing communications for process devices like robots and other not so interesting stuff.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question