Solved

Cisco ASA & AnyConnect

Posted on 2014-04-10
1
305 Views
Last Modified: 2014-11-14
Hi - My questions is, do we need to <enable webvpn> on the outside interface  on a cisco ASA device in order to use AnyConnect SSL vpn from a client pc.

If the answer is yes, why is this the case, and how can we restrict webvpn or tie it down to AnyConnect profile only if we are not using Clientless vpn over a browser.

I always thought that webvpn was only enable if we use or configure Clientless VPN over a browser !

Regards
Adam
0
Comment
Question by:adam_kan2000
1 Comment
 
LVL 12

Accepted Solution

by:
Henk van Achterberg earned 500 total points
ID: 40007384
You probably mean enable outside in the webvpn configuration mode. This is required.

If you do not create a SSL Client Less connection profile, users will only be able to use the anyconnect profile. The https website is present but when you login you will get the java/activex control for connecting with anyconnect.

Restricting users to a profile can be done several ways. If you use certificates you can map those to a profile. When you use radius, you can use radius attributes and mapping. Also local users can be bound to a profile:

username <username> attributes
 vpn-group-policy <group.policy>
 vpn-tunnel-protocol ssl-client
 group-lock value <group.policy>
 service-type remote-access
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Radius Debug Error 16 91
ACL Logging Optimization 7 41
Help with an ACL to isolate our wireless newtork 9 26
Guest Wi-Fi Time out 3 22
Some of you may have heard that SonicWALL has finally released an app for iOS devices giving us long awaited connectivity for our iPhone's, iPod's, and iPad's. This guide is just a quick rundown on how to get up and running quickly using the app. …
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

773 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question