Solved

Cisco Clientless VPN and Java

Posted on 2014-01-02
2
1,178 Views
Last Modified: 2014-01-13
Hello all,

I am turning a clientless VPN and ran into an issue.  I am able to get to the encripted web page and log in, but unable to launch a program that uses Java (jar files). When launched it just stays at "downloading application".    

I added javaw.exe to the smart tunnel application list, but it still does not launch.


Thank you
0
Comment
Question by:thecookman
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 35

Expert Comment

by:girionis
ID: 39753224
I guess you're talking about a Java applet. What does the Java console say? Have you also looked at the operating system logs?
0
 
LVL 63

Accepted Solution

by:
btan earned 500 total points
ID: 39753689
You may want to check out this

http://www.cisco.com/en/US/docs/security/asdm/6_2/user/guide/vpn_web.html#wp1077336

If JRE 1.4.x is running and the user authenticates with a digital certificate, the application fails to start because JRE cannot access the web browser certificate store.

Because port forwarding requires downloading the Java applet and configuring the local client, and because doing so requires administrator permissions on the local system, it is unlikely that users will be able to use applications when they connect from public remote systems.

Neither port forwarding nor the ASDM Java applet work with user authentication using digital certificates. Java does not have the ability to access the web browser keystore. Therefore Java cannot use certificates that the browser uses to authenticate users, and the application cannot start.

http://www.cisco.com/en/US/docs/security/asdm/6_2/user/guide/vpn_web.html#wp1121595

General Requirements and Limitations
•Smart tunnel auto sign-on supports only Microsoft Internet Explorer on Windows.
•The browser must be enabled with Java, Microsoft ActiveX, or both.
•Smart tunnel supports only proxies placed between computers running Microsoft Windows and the security appliance. Smart tunnel uses the Internet Explorer configuration (that is, the one intended for system-wide use in Windows). If the remote computer requires a proxy server to reach the security appliance, the URL of the terminating end of the connection must be in the list of URLs excluded from proxy services. If the proxy configuration specifies that traffic destined for the ASA goes through a proxy, all smart tunnel traffic goes through the proxy.

Windows Requirements and Limitations
•Users of Microsoft Windows Vista who use smart tunnel or port forwarding must add the URL of the ASA to the Trusted Site zone. To access the Trusted Site zone, they must start Internet Explorer and choose the Tools > Internet Options > Security tab. Vista users can also disable Protected Mode to facilitate smart tunnel access; however, we recommend against this method because it increases vulnerability to attack.

Installing Plug-ins Redistributed by Cisco
To retrieve a plug-in redistributed by Cisco and import it into the security appliance, perform the following steps:
Step 1      Create a temporary directory named plugins on the computer you use to establish ASDM sessions with the security appliance.
Step 2      Download the plug-ins you want from the Cisco website to the plugins directory.
Step 3      Choose Configuration > Remote Access VPN > Clientless SSL VPN Access > Portal > Client-Server Plug-ins.
This pane displays the plug-ins that are available to clientless SSL sessions.
Step 4      Click Import.


Others: Procedures Used to Troubleshoot

http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00806ea271.shtml#veri
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Java 8 to Java 6 8 33
IBM TS2900 (3572) Tape Autoloader Java? 12 61
Cisco SPA525G2 - Stuck on Cisco Screen 3 22
Cisco EAP TLS, ACS and changing Root CA 4 24
This past year has been one of great growth and performance for OnPage. We have added many features and integrations to the product, making 2016 an awesome year. We see these steps forward as the basis for future growth.
Many of the companies I’ve worked with have embraced cloud solutions due to their desire to “get out of the datacenter business.” The ability to achieve better security and availability, and the speed with which they are able to deploy, is far grea…
Viewers will learn about the regular for loop in Java and how to use it. Definition: Break the for loop down into 3 parts: Syntax when using for loops: Example using a for loop:
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

696 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question