<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problems enabling WEBVPN on 871W in VPN</title>
    <link>https://community.cisco.com/t5/vpn/problems-enabling-webvpn-on-871w/m-p/2336487#M87627</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hey MB,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My certifcate output is below.&amp;nbsp; I really appreciate you helping me with this becuase I have no idea where to luck.&amp;nbsp; It seems that I followed all the commands correctly but when I try to connect to the firewall using my iphone app "anyconnect" , I cannot form a VPN connection.&amp;nbsp; Maybe you have some more troubleshooting steps I can perform.&amp;nbsp; Were you able to get this working on your 871W?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My871W#sh crypto pki certificates&lt;/P&gt;&lt;P&gt;Router Self-Signed Certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp; Status: Available&lt;/P&gt;&lt;P&gt;&amp;nbsp; Certificate Serial Number: 02&lt;/P&gt;&lt;P&gt;&amp;nbsp; Certificate Usage: General Purpose&lt;/P&gt;&lt;P&gt;&amp;nbsp; Issuer: &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serialNumber=FHK100850LZ+hostname=My871W.LAKEVIEW&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cn=firewallcx-certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp; Subject:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Name: My871W.LAKEVIEW&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Serial Number: FHK100850LZ&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serialNumber=FHK100850LZ+hostname=My871W.LAKEVIEW&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cn=firewallcx-certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp; Validity Date: &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; start date: 04:34:42 UTC Nov 5 2002&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; end&amp;nbsp;&amp;nbsp; date: 00:00:00 UTC Jan 1 2020&lt;/P&gt;&lt;P&gt;&amp;nbsp; Associated Trustpoints: my-trustpoint &lt;/P&gt;&lt;P&gt;&amp;nbsp; Storage: nvram:FHK100850LZh#5702.cer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 13 Sep 2013 03:47:44 GMT</pubDate>
    <dc:creator>Illini79</dc:creator>
    <dc:date>2013-09-13T03:47:44Z</dc:date>
    <item>
      <title>Problems enabling WEBVPN on 871W</title>
      <link>https://community.cisco.com/t5/vpn/problems-enabling-webvpn-on-871w/m-p/2336481#M87621</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am experiencing issues configuring WebVPN on a cisco 871W.&amp;nbsp; Would someone be able to point out the problems in my configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login sslvpn local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip domain name LAKEVIEW&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto pki trustpoint my-trustpoint&lt;/P&gt;&lt;P&gt;enrollment selfsigned&lt;/P&gt;&lt;P&gt;serial-number&lt;/P&gt;&lt;P&gt;subject-name CN=firewallcx-certificate&lt;/P&gt;&lt;P&gt;revocation-check crl&lt;/P&gt;&lt;P&gt;rsakeypair my-rsa-keys&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;webvpn gateway MY-CISCO-WEBVPN-GATEWAY&lt;/P&gt;&lt;P&gt;ip address 192.168.0.1 port 443 &lt;/P&gt;&lt;P&gt;ssl encryption aes-sha1&lt;/P&gt;&lt;P&gt;ssl trustpoint my-trustpoint&lt;/P&gt;&lt;P&gt;inservice&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;webvpn install svc usbflash0:/webvpn/svc.pkg&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;webvpn context Cisco-WebVPN&lt;/P&gt;&lt;P&gt;title "Tyson's home VPN"&lt;/P&gt;&lt;P&gt;ssl authenticate verify all&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;login-message "Cisco Secure Login WebVPN"&lt;/P&gt;&lt;P&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;policy group WEBVPNPOLICY&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; functions svc-enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; svc address-pool "webvpn-pool"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; svc rekey method new-tunnel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; svc split include 192.168.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;default-group-policy WEBVPNPOLICY&lt;/P&gt;&lt;P&gt;aaa authentication list sslvpn&lt;/P&gt;&lt;P&gt;gateway MY-CISCO-WEBVPN-GATEWAY domain webvpn&lt;/P&gt;&lt;P&gt;inservice&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;webvpn gateway MY-CISCO-WEBVPN-GATEWAY&lt;BR /&gt;ip address 50.174.58.233 port 443 &lt;BR /&gt;ssl encryption aes-sha1&lt;BR /&gt;ssl trustpoint my-trustpoint&lt;BR /&gt;inservice&lt;BR /&gt;!&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2013 06:08:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/problems-enabling-webvpn-on-871w/m-p/2336481#M87621</guid>
      <dc:creator>Illini79</dc:creator>
      <dc:date>2013-09-09T06:08:42Z</dc:date>
    </item>
    <item>
      <title>Re: Problems enabling WEBVPN on 871W</title>
      <link>https://community.cisco.com/t5/vpn/problems-enabling-webvpn-on-871w/m-p/2336482#M87622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;1.&lt;/STRONG&gt; You have to enable SSL on this router.&lt;/P&gt;&lt;P&gt;Check it.&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;ip http secure-server&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2.&lt;/STRONG&gt; I have verified your configuration. You have entered the two defined webvpn gateways with the same name?&lt;/P&gt;&lt;P&gt;In my opinion, correct configuration should look like this: &lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;crypto pki trustpoint my-trustpoint&lt;/P&gt;&lt;P&gt;enrollment selfsigned&lt;/P&gt;&lt;P&gt;serial-number&lt;/P&gt;&lt;P&gt;subject-name CN=firewallcx-certificate&lt;/P&gt;&lt;P&gt;revocation-check crl&lt;/P&gt;&lt;P&gt;rsakeypair my-rsa-keys&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;webvpn gateway MY-CISCO-WEBVPN-GATEWAY&lt;/P&gt;&lt;P&gt;ip address 50.174.58.233 port 443&lt;/P&gt;&lt;P&gt;ssl encryption aes-sha1&lt;/P&gt;&lt;P&gt;ssl trustpoint my-trustpoint&lt;/P&gt;&lt;P&gt;inservice&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;webvpn install svc usbflash0:/webvpn/svc.pkg&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;webvpn context Cisco-WebVPN&lt;/P&gt;&lt;P&gt;title "Tyson's home VPN"&lt;/P&gt;&lt;P&gt;ssl authenticate verify all&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;login-message "Cisco Secure Login WebVPN"&lt;/P&gt;&lt;P&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;policy group WEBVPNPOLICY&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; functions svc-enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; svc address-pool "webvpn-pool"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; svc rekey method new-tunnel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; svc split include 192.168.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;default-group-policy WEBVPNPOLICY&lt;/P&gt;&lt;P&gt;aaa authentication list sslvpn&lt;/P&gt;&lt;P&gt;gateway MY-CISCO-WEBVPN-GATEWAY&lt;/P&gt;&lt;P&gt;domain webvpn&lt;/P&gt;&lt;P&gt;inservice&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try it out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;3. &lt;/STRONG&gt;Put the results of the commands:&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;show webvpn gateway&lt;/P&gt;&lt;P&gt;show webvpn install status svc&lt;/P&gt;&lt;P&gt;show webvpn context&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;________________ &lt;BR /&gt; &lt;BR /&gt;Best regards, &lt;BR /&gt;MB&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Sep 2013 13:27:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/problems-enabling-webvpn-on-871w/m-p/2336482#M87622</guid>
      <dc:creator>czaja0000</dc:creator>
      <dc:date>2013-09-10T13:27:17Z</dc:date>
    </item>
    <item>
      <title>Problems enabling WEBVPN on 871W</title>
      <link>https://community.cisco.com/t5/vpn/problems-enabling-webvpn-on-871w/m-p/2336483#M87623</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey MB thanks for the reply!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I get home I will try this in about 8 hours. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was also wondering if you know where I can find documentation to implement this feature. I have actually just been scrouging through various internet sites to find information, but I really don't have a solid idea what all the commands are actually doing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, I am really blurry about what the following commands are accomplishing: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto pki trustpoint my-trustpoint&lt;/P&gt;&lt;P&gt;enrollment selfsigned&lt;/P&gt;&lt;P&gt;serial-number&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;subject-name CN=firewallcx-certificate&amp;nbsp; = = = &amp;gt; What is this line doing?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;revocation-check crl&lt;/P&gt;&lt;P&gt;rsakeypair my-rsa-keys&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Sep 2013 21:06:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/problems-enabling-webvpn-on-871w/m-p/2336483#M87623</guid>
      <dc:creator>Illini79</dc:creator>
      <dc:date>2013-09-10T21:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: Problems enabling WEBVPN on 871W</title>
      <link>https://community.cisco.com/t5/vpn/problems-enabling-webvpn-on-871w/m-p/2336484#M87624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interesting article (you have read it already&amp;nbsp; &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; )&lt;/P&gt;&lt;P&gt; &lt;IMG ___jive_emoticon_name="happy" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif" /&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.firewall.cx/cisco-technical-knowledgebase/cisco-routers/904-cisco-router-anyconnect-webvpn.html" rel="nofollow"&gt;http://www.firewall.cx/cisco-technical-knowledgebase/cisco-routers/904-cisco-router-anyconnect-webvpn.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;IMG ___jive_emoticon_name="happy" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif" /&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;D'Juan Tyson napisano:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;For example, I am really blurry about what the following commands are accomplishing: &lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto pki trustpoint my-trustpoint&lt;/P&gt;&lt;P&gt;enrollment selfsigned&lt;/P&gt;&lt;P&gt;serial-number&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;subject-name CN=firewallcx-certificate&amp;nbsp; = = = &amp;gt; What is this line doing?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;revocation-check crl&lt;/P&gt;&lt;P&gt;rsakeypair my-rsa-keys&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The subject-name subcommand allows you to specify other options in the certificate.&lt;/P&gt;&lt;P&gt;For example, you can sets the fields:&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;C=&amp;nbsp; (Country)&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;CA= (Certificate authority)&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;CN= (Common Name)&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;O=&amp;nbsp; (Organization)&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;OU= (Organizational Unit)&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;ST= (State)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the subject-name subcommand is not used, by default, the router Fully Qualified Domain Name (FQDN) is used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P style="padding-left: 60px;"&gt;ip hostname&lt;STRONG&gt; webvpn&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;ip domain-name &lt;STRONG&gt;company.com&lt;/STRONG&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the FQDN in the certificate will be:&lt;STRONG&gt; webvpn.company.com&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.&lt;/P&gt;&lt;P&gt;If https is already running on the router - it means that the self-signed certificate is created, because the router generates it automatically.&lt;/P&gt;&lt;P&gt;Or you can generate it now (enter the command: ip http secure-server)&lt;/P&gt;&lt;P&gt;You can use this certificate, read below article:&lt;/P&gt;&lt;P&gt;&lt;A href="http://tekcert.com/blog/2011/08/05/configuring-clientless-ssl-vpn-webvpn-cisco-ios-routers" rel="nofollow"&gt;http://tekcert.com/blog/2011/08/05/configuring-clientless-ssl-vpn-webvpn-cisco-ios-routers&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At section:&lt;EM&gt; "A key point to make here is that enabling http secure-server (https) forces the router to create a self-signed certificate if it hasn't already done so."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;________________ &lt;BR /&gt; &lt;BR /&gt;Best regards, &lt;BR /&gt;MB&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Sep 2013 10:38:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/problems-enabling-webvpn-on-871w/m-p/2336484#M87624</guid>
      <dc:creator>czaja0000</dc:creator>
      <dc:date>2013-09-11T10:38:23Z</dc:date>
    </item>
    <item>
      <title>Problems enabling WEBVPN on 871W</title>
      <link>https://community.cisco.com/t5/vpn/problems-enabling-webvpn-on-871w/m-p/2336485#M87625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hey MB,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The output you request is below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My871W#show webvpn context &lt;/P&gt;&lt;P&gt;Codes: AS - Admin Status, OS - Operation Status&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VHost - Virtual Host&lt;/P&gt;&lt;P&gt;Context Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Gateway&amp;nbsp; Domain/VHost&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VRF&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AS&amp;nbsp;&amp;nbsp;&amp;nbsp; OS&lt;BR /&gt;------------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -------&amp;nbsp; ------------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -------&amp;nbsp; ----&amp;nbsp; --------&lt;BR /&gt;Cisco-WebVPN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MY-CISCO webvpn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&amp;nbsp;&amp;nbsp;&amp;nbsp; up&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My871W#show webvpn install status svc &lt;/P&gt;&lt;P&gt;SSLVPN Package SSL-VPN-Client version installed:&lt;/P&gt;&lt;P&gt;CISCO STC win2k+ &lt;/P&gt;&lt;P&gt;3,1,03103&lt;/P&gt;&lt;P&gt;Hostscan Version 3.1.03103 &lt;/P&gt;&lt;P&gt;Tue 03/26/2013&amp;nbsp; 8:55:10.17 J&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My871W#show webvpn gateway &lt;/P&gt;&lt;P&gt;Gateway Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Admin&amp;nbsp; Operation&lt;BR /&gt;------------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -----&amp;nbsp; ---------&lt;BR /&gt;MY-CISCO-WEBVPN-GATEWAY&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Sep 2013 06:47:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/problems-enabling-webvpn-on-871w/m-p/2336485#M87625</guid>
      <dc:creator>Illini79</dc:creator>
      <dc:date>2013-09-12T06:47:42Z</dc:date>
    </item>
    <item>
      <title>Re: Problems enabling WEBVPN on 871W</title>
      <link>https://community.cisco.com/t5/vpn/problems-enabling-webvpn-on-871w/m-p/2336486#M87626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The results - here everything looks fine.&amp;nbsp; &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To verify if the certificate is correctly installed on the router, paste the output:&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;sh crypto pki certificates&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So what is the issue?&lt;/P&gt;&lt;P&gt;Please explain it or provide more information.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Sep 2013 09:11:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/problems-enabling-webvpn-on-871w/m-p/2336486#M87626</guid>
      <dc:creator>czaja0000</dc:creator>
      <dc:date>2013-09-12T09:11:47Z</dc:date>
    </item>
    <item>
      <title>Problems enabling WEBVPN on 871W</title>
      <link>https://community.cisco.com/t5/vpn/problems-enabling-webvpn-on-871w/m-p/2336487#M87627</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hey MB,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My certifcate output is below.&amp;nbsp; I really appreciate you helping me with this becuase I have no idea where to luck.&amp;nbsp; It seems that I followed all the commands correctly but when I try to connect to the firewall using my iphone app "anyconnect" , I cannot form a VPN connection.&amp;nbsp; Maybe you have some more troubleshooting steps I can perform.&amp;nbsp; Were you able to get this working on your 871W?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My871W#sh crypto pki certificates&lt;/P&gt;&lt;P&gt;Router Self-Signed Certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp; Status: Available&lt;/P&gt;&lt;P&gt;&amp;nbsp; Certificate Serial Number: 02&lt;/P&gt;&lt;P&gt;&amp;nbsp; Certificate Usage: General Purpose&lt;/P&gt;&lt;P&gt;&amp;nbsp; Issuer: &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serialNumber=FHK100850LZ+hostname=My871W.LAKEVIEW&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cn=firewallcx-certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp; Subject:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Name: My871W.LAKEVIEW&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Serial Number: FHK100850LZ&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serialNumber=FHK100850LZ+hostname=My871W.LAKEVIEW&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cn=firewallcx-certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp; Validity Date: &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; start date: 04:34:42 UTC Nov 5 2002&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; end&amp;nbsp;&amp;nbsp; date: 00:00:00 UTC Jan 1 2020&lt;/P&gt;&lt;P&gt;&amp;nbsp; Associated Trustpoints: my-trustpoint &lt;/P&gt;&lt;P&gt;&amp;nbsp; Storage: nvram:FHK100850LZh#5702.cer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Sep 2013 03:47:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/problems-enabling-webvpn-on-871w/m-p/2336487#M87627</guid>
      <dc:creator>Illini79</dc:creator>
      <dc:date>2013-09-13T03:47:44Z</dc:date>
    </item>
    <item>
      <title>Problems enabling WEBVPN on 871W</title>
      <link>https://community.cisco.com/t5/vpn/problems-enabling-webvpn-on-871w/m-p/2336488#M87628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;MB,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I try to connect to the VPN the anyconnect app says that it cannot verify the certificate?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Sep 2013 03:53:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/problems-enabling-webvpn-on-871w/m-p/2336488#M87628</guid>
      <dc:creator>Illini79</dc:creator>
      <dc:date>2013-09-13T03:53:35Z</dc:date>
    </item>
    <item>
      <title>Re: Problems enabling WEBVPN on 871W</title>
      <link>https://community.cisco.com/t5/vpn/problems-enabling-webvpn-on-871w/m-p/2336489#M87629</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey DT,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure if this is the problem.&lt;/P&gt;&lt;P&gt;Not enough information. Maybe this?&lt;/P&gt;&lt;P&gt;"Untrusted VPN Server Certificate!,&amp;nbsp; AnyConnect cannot verify the VPN server: ........"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;H3&gt; Server Certificates &lt;/H3&gt;&lt;BR /&gt;&lt;P&gt; A valid, trusted server certificate configured on the secure gateway provides an easy and safe VPN connection for the user. &lt;/P&gt;&lt;BR /&gt;&lt;P&gt;AnyConnect on mobile devices provides improved security protection when&amp;nbsp; accessing a secure gateway by blocking the VPN connection if the&amp;nbsp; certificate presented by the secure gateway is invalid or untrusted, or&amp;nbsp; both. &lt;/P&gt;&lt;BR /&gt;&lt;P&gt;A new &lt;STRONG&gt;Block Untrusted Servers &lt;/STRONG&gt; application setting determines how AnyConnect blocks connections if it&amp;nbsp; cannot identify the secure gateway. This protection is ON by default; it&amp;nbsp; can be turned OFF by the user, but this is not recommended. &lt;/P&gt;&lt;BR /&gt;&lt;P&gt;AnyConnect uses the digital certificate received from the server to&amp;nbsp; verify its identify. If the certificate is invalid (there is a&amp;nbsp; certificate error due to an expired or invalid date, wrong key usage, or&amp;nbsp; a name mismatch), or if it is untrusted (the certificate cannot be&amp;nbsp; verified by a Certificate Authority), or both, the connection is&amp;nbsp; blocked. A blocking message displays, and the user must choose how to&amp;nbsp; proceed. &lt;/P&gt;&lt;BR /&gt;&lt;P&gt;When Block Untrusted Servers is ON, a blocking Untrusted VPN Server notification alerts the user to this security threat. The user can choose: &lt;/P&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;&lt;STRONG&gt;Keep Me Safe &lt;/STRONG&gt;to terminate this connection and remain safe. &lt;BR /&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;Change Settings&lt;/STRONG&gt; to turn the &lt;STRONG&gt;Block Untrusted Servers&lt;/STRONG&gt;&amp;nbsp; application preference &lt;STRONG&gt;OFF&lt;/STRONG&gt;&lt;/SPAN&gt;, but this is not recommended. After the user&amp;nbsp; disables this security protection, they must reinitiate the VPN&amp;nbsp; connection. 

&lt;BR /&gt;&lt;P&gt;When Block Untrusted Servers is OFF, a nonblocking Untrusted VPN Server notification alerts the user to this security threat. The user can choose to: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;Cancel the connection and remain safe. &lt;BR /&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;&lt;STRONG&gt;Continue&lt;/STRONG&gt; the connection, but this is not recommended. 

&lt;P&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;&lt;STRONG&gt;View Details&lt;/STRONG&gt; of the certificate. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the certificate that the user is viewing is valid but untrusted, the user can: 
&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;–&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="17" /&gt;Import the server certificate into the AnyConnect certificate store for future use and continue the connection by selecting &lt;STRONG&gt;Import and Continue&lt;/STRONG&gt;.&amp;nbsp; Once this certificate is imported into the AnyConnect store, subsequent&amp;nbsp; connections made to the server using this digital certificate are&amp;nbsp; automatically accepted. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;–&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="17" /&gt;Go back to the previous screen and choose Cancel or Continue. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the certificate is invalid, for any reason, the user can only return to the previous screen and choose Cancel or Continue. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Leaving the Block Untrusted Servers&amp;nbsp; setting ON, having a valid, trusted server certificate configured on&amp;nbsp; your secure gateway, and instructing your mobile users to always choose Keep Me Safe is the safest configuration for VPN connectivity to your network. &lt;/P&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try it, and reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Please, enter the full error message or attach example (screen) from the Internet.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;________________&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;MB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate all helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Sep 2013 09:00:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/problems-enabling-webvpn-on-871w/m-p/2336489#M87629</guid>
      <dc:creator>czaja0000</dc:creator>
      <dc:date>2013-09-13T09:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: Problems enabling WEBVPN on 871W</title>
      <link>https://community.cisco.com/t5/vpn/problems-enabling-webvpn-on-871w/m-p/2336490#M87630</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Specify your IOS version.&lt;/P&gt;&lt;P&gt;Cisco IOS recommendation:&lt;EM&gt; "An advanced image of Cisco IOS Software Release 12.4(6)T or later"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Troubleshooting:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;1.&lt;/STRONG&gt; Check the SSL VPN clientless mode&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Open the web portal: "&lt;STRONG&gt;&lt;A class="jive-link-external-small" href="https://IP_of_your_WebVPN_gateway" rel="nofollow"&gt;https://IP_of_your_WebVPN_gateway&lt;/A&gt;&lt;/STRONG&gt;" and verify that you can log.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2.&lt;/STRONG&gt; SSL VPN Debug Commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is available one command with many options.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We'll use it without options:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;- enable debugging&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;debug webvpn&lt;/PRE&gt;&lt;P style="padding-left: 30px;"&gt;- do try connect from AnyConnect and collect the logs&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;- turn off debugging&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;no debug all&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do analize the logs or paste here &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;________________&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;MB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate all helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Sep 2013 10:49:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/problems-enabling-webvpn-on-871w/m-p/2336490#M87630</guid>
      <dc:creator>czaja0000</dc:creator>
      <dc:date>2013-09-13T10:49:50Z</dc:date>
    </item>
  </channel>
</rss>

