Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

Cisco Clientless VPN SSL issues with ISS

Posted on 2008-10-17
9
Medium Priority
?
910 Views
Last Modified: 2008-10-29
I have a question. Im setting up a server that supports OWA and outlook anywhere.
I have a asas 5505 that i want to set up with SSL vpn so that remote users can launch Remote desktop and access their own computer in the office. When i go to https://asa5505outsideip i go to the iss menu.

Any input?

0
Comment
Question by:daxa78
  • 2
  • 2
  • 2
  • +2
9 Comments
 
LVL 15

Expert Comment

by:wingatesl
ID: 22745952
Can you post the config from the ASA please
Shawn
0
 
LVL 1

Author Comment

by:daxa78
ID: 22746209
I have not done the modifications to the asa yet but the example from cisco says that i should go to
https://externaipoftheasa when i am finished with the setup to get ssl vpn access-

But when i try to go to that site today i get to IIS and i was wondering how i would work around this?
I still need the OWA to work, so i can disable the entire IIS


0
 
LVL 5

Expert Comment

by:rexxus
ID: 22746245
Do you have a static NAT pointing external traffic to your IIS box?
0
Who's Defending Your Organization from Threats?

Protecting against advanced threats requires an IT dream team – a well-oiled machine of people and solutions working together to defend your organization. Download our resource kit today to learn more about the tools you need to build you IT Dream Team!

 
LVL 15

Assisted Solution

by:wingatesl
wingatesl earned 400 total points
ID: 22746257
The best thing would be to configure the ssl vpn on a nonstandard port. I usually use port 1025 for all installations.
0
 
LVL 58

Accepted Solution

by:
Pete Long earned 800 total points
ID: 22746284
>>I still need the OWA to work, so i can disable the entire IIS

publish OWA on the Clientless portal? you should ony have a problem if you need Direct Push EMail or if you need to forward Https - because once you enable webvpn on the outside interface you cannot forward https.

The only way round that problem is to have another external interface (which means having a security plus licensed firewall)

>>so that remote users can launch Remote desktop and access their own computer in the office. When i go to

yeah you can do that as well from the portal - there is a Java RDP applet that you can use to RDP straight from the portal

0
 
LVL 79

Expert Comment

by:lrmoore
ID: 22746666
You can run the VPN on a different port, say 444 and still forward 443 to the OWA server
Then for vpn you access it by https://outsideip:444
0
 
LVL 1

Author Comment

by:daxa78
ID: 22762960
How do i set that to use a diffrent port?

Do i need to purchase a certificate or does the asa box issue one ?
0
 
LVL 79

Assisted Solution

by:lrmoore
lrmoore earned 800 total points
ID: 22763026
You can use the self-signed cert. Users will get warnings, but can either ignore them or install the cert into the trusted root list on their pc.

If using ASDM, under Configuration | Remote Access VPN | Clientless SSL VPN Access | Connection profiles
In the right pane, see  Access Port: [443  ]   <== change the port here


0
 
LVL 58

Expert Comment

by:Pete Long
ID: 22832761
ThanQ
0

Featured Post

Become a Leader in Data Analytics

Gain the power to turn raw data into better business decisions and outcomes in your industry. Transform your career future by earning your MS in Data Analytics. WGU’s MSDA program curriculum features IT certifications from Oracle and SAS.  

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Many of the companies I’ve worked with have embraced cloud solutions due to their desire to “get out of the datacenter business.” The ability to achieve better security and availability, and the speed with which they are able to deploy, is far grea…
As managed cloud service providers, we often get asked to intervene when cloud deployments go awry. Attracted by apparent ease-of-use, flexibility and low computing costs, companies quickly adopt leading public cloud platforms such as Amazon Web Ser…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

564 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question