<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi m8r-68yphu1, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ssl-vpn-apps-fail-to-connect-using-java-8-update-71-java-8u71/m-p/2790441#M164175</link>
    <description>&lt;P&gt;&lt;SPAN class="fullname" itemprop="author"&gt;Hi&amp;nbsp;&lt;A href="https://supportforums.cisco.com/users/m8r-68yphu1" title="View user profile." class="username" lang="" about="/users/m8r-68yphu1" typeof="sioc:UserAccount" property="foaf:name" datatype=""&gt;m8r-68yphu1&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Based on your description, looks like the problem might be on the client or server end when the java is updated.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The port forwarding works at OSI layer 4 and the Java works on the application layer 7, then is unlikey the ASA is modifying the traffic with a new java version installed on the client side.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Placing a capture on the ASA might gave you &amp;nbsp;a better perspective of problem.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportforums.cisco.com/document/69281/asa-using-packet-capture-troubleshoot-asa-firewall-configuration-and-scenarios" target="_blank"&gt;https://supportforums.cisco.com/document/69281/asa-using-packet-capture-troubleshoot-asa-firewall-configuration-and-scenarios&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/118097-configure-asa-00.html" target="_blank"&gt;http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/118097-configure-asa-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope it helps&lt;/P&gt;
&lt;P&gt;-Randy-&lt;/P&gt;</description>
    <pubDate>Wed, 27 Jan 2016 03:34:25 GMT</pubDate>
    <dc:creator>rvarelac</dc:creator>
    <dc:date>2016-01-27T03:34:25Z</dc:date>
    <item>
      <title>SSL VPN Apps fail to connect using Java 8 update 71 (Java 8u71)</title>
      <link>https://community.cisco.com/t5/network-security/ssl-vpn-apps-fail-to-connect-using-java-8-update-71-java-8u71/m-p/2790440#M164173</link>
      <description>&lt;P&gt;A remote client uses the SSL VPN apps for port forwarding through an ASA 5505 firewall.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Basically no traffic was able to traverse the port forwarded IP addresses.&lt;/P&gt;
&lt;P&gt;Using the web browser in the VPN portal allowed access to servers web front ends.&lt;/P&gt;
&lt;P&gt;Only by rolling back the Java update to 8_66 were the servers accessible by the vpn applications tool&lt;/P&gt;
&lt;P&gt;Can you share any advice about debugging / resolving this issue?&lt;/P&gt;
&lt;P&gt;It is required to run latest java version on the client network.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;Result of the command: "show version"&lt;BR /&gt;Cisco Adaptive Security Appliance Software Version 8.2(5)58 &lt;BR /&gt;Device Manager Version 6.4(5)&lt;/PRE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;Result of the command: "show ssl"&lt;BR /&gt;Accept connections using SSLv2, SSLv3 or TLSv1 and negotiate to TLSv1&lt;BR /&gt;Start connections using TLSv1 and negotiate to TLSv1&lt;BR /&gt;Enabled cipher order: rc4-sha1 aes128-sha1 aes256-sha1 3des-sha1&lt;BR /&gt;Disabled ciphers: des-sha1 rc4-md5 null-sha1&lt;BR /&gt;SSL trust-points:&lt;BR /&gt;outside interface: ASDM_TrustPoint0&lt;BR /&gt;Certificate authentication is not enabled&lt;/PRE&gt;
&lt;P&gt;Connections to servers by ssh on the VPN resulted in this error:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;ssh someuser@127.0.0.1:22222&lt;BR /&gt;&lt;SPAN&gt;"ssh_exchange_identification: Connection closed by remote host"&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;Using ssh -v we saw keys were transferred and right away closed.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:11:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-vpn-apps-fail-to-connect-using-java-8-update-71-java-8u71/m-p/2790440#M164173</guid>
      <dc:creator>m8r-68yphu1</dc:creator>
      <dc:date>2019-03-12T07:11:20Z</dc:date>
    </item>
    <item>
      <title>Hi m8r-68yphu1,</title>
      <link>https://community.cisco.com/t5/network-security/ssl-vpn-apps-fail-to-connect-using-java-8-update-71-java-8u71/m-p/2790441#M164175</link>
      <description>&lt;P&gt;&lt;SPAN class="fullname" itemprop="author"&gt;Hi&amp;nbsp;&lt;A href="https://supportforums.cisco.com/users/m8r-68yphu1" title="View user profile." class="username" lang="" about="/users/m8r-68yphu1" typeof="sioc:UserAccount" property="foaf:name" datatype=""&gt;m8r-68yphu1&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Based on your description, looks like the problem might be on the client or server end when the java is updated.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The port forwarding works at OSI layer 4 and the Java works on the application layer 7, then is unlikey the ASA is modifying the traffic with a new java version installed on the client side.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Placing a capture on the ASA might gave you &amp;nbsp;a better perspective of problem.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportforums.cisco.com/document/69281/asa-using-packet-capture-troubleshoot-asa-firewall-configuration-and-scenarios" target="_blank"&gt;https://supportforums.cisco.com/document/69281/asa-using-packet-capture-troubleshoot-asa-firewall-configuration-and-scenarios&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/118097-configure-asa-00.html" target="_blank"&gt;http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/118097-configure-asa-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope it helps&lt;/P&gt;
&lt;P&gt;-Randy-&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2016 03:34:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-vpn-apps-fail-to-connect-using-java-8-update-71-java-8u71/m-p/2790441#M164175</guid>
      <dc:creator>rvarelac</dc:creator>
      <dc:date>2016-01-27T03:34:25Z</dc:date>
    </item>
  </channel>
</rss>

