Solved

IP Phone SSL VPN through ASA

Posted on 2011-02-16
3
1,278 Views
Last Modified: 2012-05-11
Im in the middle of configuring Ip Phone SSL VPN through ASA, got stuck on authentication.. When I enter username and password on the phone screen, i get "Username and password failed" message on the screen. However, in ASA logs I see the following line

 

Feb 16 2011    15:12:57    725002    85.132.43.67    52684            Device completed SSL handshake with client vpn:85.132.*.*/52684

Feb 16 2011    15:17:26    725007    85.132.43.67    52745            SSL session with client vpn:85.132.*.*/52745 terminated.

 

What does it mean?  How can I turn on debugging to see what is going on?

 

Thank you in advance!
0
Comment
Question by:fgasimzade
  • 2
3 Comments
 
LVL 33

Expert Comment

by:MikeKane
ID: 34909745
Is this the Cisco Deskphone VPN solution?    I set this up and It took no less than 5 calls with TAC and about 15 hours of troubleshooting.  

What are you using for Auth?   Local AAA or ldap passthorugh perhaps?  

For testing, you can turn on debug logging to a syslog server to get a complete picture....
0
 
LVL 18

Accepted Solution

by:
fgasimzade earned 0 total points
ID: 34950745
Thank you for your reply, it was routing problem, after successful VPN handshake the phone was unable to contact Call Manager
0
 
LVL 18

Author Closing Comment

by:fgasimzade
ID: 34990701
Managed to find solution myself
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

OpenVPN is a great open source VPN server that is capable of providing quick and easy VPN access to your network on the cheap.  By default the software is configured to allow open access to your network.  But what if you want to restrict users to on…
For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

860 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question