cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

Archived Security Events

ciscomoderator
Community Manager
Community Manager

 

Welcome to this Cisco Support Community Ask the Expert conversation. This is an opportunity to learn and ask questions about integrating Cisco Cloud Security with integrated services routers with Cisco subject matter experts Kureli Sankar and Umanath S.S.  Additionally, our experts will cover how the ISR G2 works with Cisco CWS and the necessary steps required as well as things to take into consideration when deploying Cisco CWS with Cisco ISR G2. 

This is a continuation of the live webcast.

Kureli Sankar started with Cisco in August 2006 as a TAC engineer in the firewall team in Research Triangle Park, North Carolina. As a TAC engineer she supported Cisco's security products. Since May 6, 2013, she has taken up a new role as a technical marketing engineer with the Enterprise Networking Group responsible for security features on Cisco IOS Software products. She has presented at Cisco Live 2013 and 2014 in San Francisco. She has also done quite a few live webcasts and Ask the Expert events for our forum.

Prior to joining Cisco, Sankar worked for John Morrell Co., Cincinnati, Ohio, where she was the network administrator in charge of the company's enterprise network covering 27 locations in the United States. She also was an adjunct professor at the University of Cincinnati, teaching undergraduate-level networking courses. Sankar holds an engineering degree in electrical and electronics engineering from Regional Engineering College, Trichirappalli, India, and holds CCISP and CCIE security no. 35505 certifications.

Remember to use the rating system to let Kureli and Umanath know if you have received an adequate response.

Because of the volume expected during this event, our experts might not be able to answer every question. Remember that you can continue the conversation in the Security Community, under the subcommunity Web Security, shortly after the event. This event lasts through August 1, 2014. Visit this forum often to view responses to your questions and the questions of other Cisco Support Community members.

ciscomoderator
Community Manager
Community Manager

During the live event, Cisco subject matter expert Kureli Sankar will explain how to integrate Cisco Cloud Web Security (CWS) with the Cisco Integrated Services Router Generation 2 (ISR G2). Additionally, attendees will learn how the ISR G2 works with Cisco CWS and the necessary steps required as well as things to take into consideration when deploying Cisco CWS with Cisco ISR G2. 

Agenda

•              Introduction to CWS

•              Preparation for CWS Adaptive Security Appliance (ASA) deployment

•              Deploying CWS on ASA

•              Verification commands

•              Best practices

  •             Demo

 

Kureli Sankar started with Cisco in August 2006 as a TAC engineer in the firewall team in Research Triangle Park, North Carolina. As a TAC engineer she supported Cisco's security products. Since May 6, 2013, she has taken up a new role as a technical marketing engineer with the Enterprise Networking Group responsible for security features on Cisco IOS Software products. She has presented at Cisco Live 2013 and 2014 in San Francisco. She has also done quite a few live webcasts and Ask the Expert events for our forum.

 

Prior to joining Cisco, Sankar worked for John Morrell Co., Cincinnati, Ohio, where she was the network administrator in charge of the company's enterprise network covering 27 locations in the United States. She also was an adjunct professor at the University of Cincinnati, teaching undergraduate-level networking courses. Sankar holds an engineering degree in electrical and electronics engineering from Regional Engineering College, Trichirappalli, India, and holds CCISP and CCIE security no. 35505 certifications.

In addition to working full time, Sankar volunteers at various organizations such as Citizen School, Durham Performance Learning Center, NC First Robotics, Girl Scouts–Carolina, and Raleigh Rescue Mission and gives back to the community. She is a mentor for Team (3459) PyroTech (Wake Robotics).

Need more information? Have more questions? Our experts are available for the next two weeks to help at https://supportforums.cisco.com/expert-corner/knowledge-sharing.

 

Read the Ask the Expert Discussion

Watch the Presentation

Read the FAQs

ciscomoderator
Community Manager
Community Manager

Welcome to the Cisco Support Community Ask the Expert conversation.  This is an opportunity to learn and ask questions about integrating Cisco Cloud Web Security with Adaptive Security Appliance with Cisco subject matter experts Maite Cadenas and Jennifer Halim.

This is a continuation of the live webcast.

During the live webcast delivered by Maite Cadenas, she explained how to integrate Cisco Cloud Web Security (CWS) with Cisco Adaptive Security Appliance (ASA).  Maite also took the audience through how Cisco ASA works with Cisco CWS and the necessary steps required and things to take into considerations in order to deploy Cisco CWS with Cisco ASA.

 

Agenda

  • Introduction to Cloud Web Security (CWS)
  • Preparation for CWS ASA deployment
  • Deploying CWS on ASA
  • Verifications commands
  • Best Practices
  • Demo

 

Maite Cadenas is a service delivery manager (SDM) for the Cisco Cloud Web Security solution for the EMEAR region. Her work involves helping customers to implement the Cisco CWS solution in their environments, making sure that they have the support needed during the implementation and as a first technical point of contact. Prior this role, she was part of the Brussels Security Team in the Cisco Training Assistance Center (TAC) that helps customers troubleshoot Cisco security technologies. She holds a master's degree in telecommunications engineering and a bachelor's degree in networking technologies from Universitat Enginyeria i Arquitechtura la Salle. She also holds CCIE certification in security (#26075) as well as ITILv3 Foundations. 

Jennifer Halim is also a service deployment manager for the Cisco ScanSafe (Cisco Cloud Web Security) solution for the Asia Pacific and US regions and the team lead. Her work involves implementing the solution within the customer's environment, managing the project and an escalation point of contact for technical account manager team. Prior to her current role, she was part of the Australia Security team in the Technical Assistance Center that helps customers configure and troubleshoot Cisco security technologies. She also served as a mentor to other Technical Assistance Center engineers. Jennifer is also a top contributor in the Cisco Support Community. She has worked in the networking security field for more than 11 years and holds CCIE certification in Security (#16480) as well as CCDP, CISSP and ITILv3 certifications.

 

READ THE Q&A >>

 

Webcast Related Links

View the Video 

Read the FAQ 

Download the Slides

ciscomoderator
Community Manager
Community Manager

 

Welcome to this Cisco Support Community Ask the Expert conversation. This is an opportunity to learn and ask questions about IPsec/Secure Sockets Layer (SSL) VPN technologies with Cisco subject matter expert Jay Young. 

Additionally, you may ask Jay questions regarding Dynamic Multipoint VPN (DMVPN), FlexVPN, Easy VPN, GETVPN, AnyConnect, and Internet Key Exchange (IKE) v2.

Jay Young works on the Technical Leadership Team at Cisco within the Technical Assistance Center (TAC). His focus over the last seven years has been supporting Cisco customers with complex technical problems. Jay has achieved certification in security (CCIE no. 23723), CCNP, CCNA, CCDA, and CCNP and is also a Cisco Security Ninja White Belt. Jay received his BS degree in computer science from Rennselaer Polytechnic Institute in Troy, New York. He is a frequent speaker at Cisco Live!

Remember to use the rating system to let Jay know if you have received an adequate response. 

Because of the volume expected during this event, Jay might not be able to answer every question. Remember that you can continue the conversation in the Security  community, under subcommunity VPN, shortly after the event. This event lasts through July 3, 2014. Visit this forum often to view responses to your questions and the questions of other Cisco Support Community members.

 

 

      

ciscomoderator
Community Manager
Community Manager

 

Welcome to this Cisco Support Community Ask the Expert conversation. This is an opportunity to learn and ask questions about Cisco Identity Service Engine (ISE) with subject matter expert Nicolas Darchis.

Cisco Identity Service Engine is a security policy management and control platform that automates and simplifies access control and security compliance for wired, wireless, and VPN connectivity. It is primarily used to provide secure access and guest access, support BYOD initiatives, and enforce usage policies in conjunction with Cisco TrustSec. 

Nicolas Darchis is a wireless and authentication, authorization, and accounting expert for the Technical Assistance Center at Cisco Europe. He has been troubleshooting wireless networks, wireless management tools, and security products, including Cisco Secure Access Control Server, since 2007. He also focuses on filing technical and documentation bugs. Darchis holds a bachelor's degree in computer networking from the Haute Ecole Rennequin Sualem and a master's degree in computer science from the University of Liege. He also holds CCIE Wireless certification (no. 25344).

Remember to use the rating system to let Nicolas know if you have received an adequate response.

Because of the volume expected during this event, our expert might not be able to answer every question. Remember that you can continue the conversation in the Security community under subcommunity AAA, Identity, and NAC shortly after the event. This event lasts through June 20, 2014. Visit this forum often to view responses to your questions and the questions of other Cisco Support Community members.

 

 

      

ciscomoderator
Community Manager
Community Manager

During the live event, Cisco subject matter expert Maite Cadenas will explain how to integrate Cisco Cloud Web Security (CWS) with Cisco Adaptive Security Appliance (ASA).  Additionally, you will learn how Cisco ASA works with Cisco CWS and the necessary steps required and things to take considerations in order to deploy Cisco CWS with Cisco ASA.

 

AGENDA

•              Introduction to Cisco Cloud Web Security (CWS)

•              Preparation for Cisco ASA deployment (including Cisco SWT Context Delivery Agent (CDA) for user granularity)

•              Configuring Cisco CWS on Cisco ASA (HTTP and HTTPS)                 

•              Testing Cisco CWS using Cisco ASA to redirect web traffic to cloud         

•              Best practices

 

Maite Cadenas is a service delivery manager (SDM) for the Cisco Cloud Web Security solution for the EMEAR region. Her work involves helping customers to implement the Cisco CWS solution in their environments, making sure that they have the support needed during the implementation and as a first technical point of contact. Prior this role, she was part of the Brussels Security Team in the Cisco Training Assistance Center (TAC) that helps customers troubleshoot Cisco security technologies. She holds a master's degree in telecommunications engineering and a bachelor's degree in networking technologies from Universitat Enginyeria i Arquitechtura la Salle. She also holds CCIE certification in security (#26075) as well as ITILv3 Foundations. 

Tuesday, June 24, 2014 at 9 a.m. PDT San Francisco (UTC -7 hours). This corresponds to noon EDT New York (UTC -4 hours), 5 p.m. London (BST UTC +1), or 6 p.m. Paris (CEST UTC +2).

 

Webcast Related Links

Ask the Expert

Download the Slides

View the Video

Read the FAQ (available soon)

cisco_admin1
Level 3
Level 3

Read the bioWith Marcin Latosiewicz

Welcome to the Cisco Support Community Ask the Expert conversation. This is an opportunity to Get an update on IPsec VPN with Cisco expert Marcin Latosiewicz who will answer questions on the topic of best practices when implementing IPsec VPNs on IOS and ASA. Marcin Latosiewicz is a Customer Support Engineer at the Cisco Technical Assistance Center in Belgium, which over four years of experience with Cisco Security products and technologies including IPSec, VPN, internetworking appliances, network and systems security, internet services and Cisco networking equipment.

Remember to use the rating system to let Marcin know if you have received an adequate response. 

Marcin might not be able to answer each question due to the volume expected during this event. Remember that you can continue the conversation on the Security sub-community   discussion forum shortly after the event.   This event lasts through December 9th, 2011. Visit this forum often to view responses to your questions and the questions of other community members.

cisco_admin1
Level 3
Level 3

Read the bio Read the bio

With and


Welcome to the Cisco Support Community Ask the Expert conversation. This is an opportunity to learn how Cisco Security Manager enables deployment of security related configuration to Cisco devices with Cisco experts, Stefano De Crescenzo and Nevena Krsmanovic. Stefano De Crescenzo is working in Cisco’s Product Security Incident Response Team (PSIRT) as an incident manager. Prior to this, he was working in Cisco’s Technical Assistance Center in EMEA as a customer support engineer within the Security and Content team where he specialized in solving high complex Firewall and VPN issues with particular focus on Cisco Security Manager. Nevena Krsmanovic is a customer support engineer in the Firewall and Intrusion Detection System team for the Cisco Technical Assistance Center in Brussels. She specializes in resolving high-severity issues with Cisco Adaptive Security Appliance, Firewall Services Module, Cisco Security Manager, Content Security and Content Module, and the Cisco IOS firewall feature set. Prior to this she supported security (firewall and VPN) and content (Cisco Load Balancers) technologies.

Remember to use the rating system to let Stefano and Nevena know if you have received an adequate response.
 
Stefano and Nevena might not be able to answer each question due to the volume expected during this event. Remember that you can continue the conversation on the discussion forum shortly after the event. This event lasts through May 20, 2011. Visit this forum often to view responses to your questions and the questions of other community members.

cisco_admin1
Level 3
Level 3

Welcome to the Cisco Networking Professionals Ask the Expert conversation. This is an opportunity to learn how to address and troubleshoot common problems with Adaptive Security Appliances, Private Internet Exchange and Firewall Service Modules with Kureli Sankar.  Kureli is an engineer supporting Cisco's firewall team in Research Triangle Park, North Carolina. Her team supports the Cisco Adaptive Security Appliance, Firewall Services Module, Cisco Security Manager, the Content Security and Control module, and the Zone Based Firewall module in Cisco IOS Software.

 

Remember to use the rating system to let Kureli know if you have received an adequate response.

 

Kureli might not be able to answer each question due to the volume expected during this event. Our moderators will post many of the unanswered questions in other discussion forums shortly after the event. This event lasts through January 14, 2011. Visit this forum often to view responses to your questions and the questions of other community members.

cisco_admin1
Level 3
Level 3

Welcome  to the Cisco Networking  Professionals Ask the Expert conversation.  This is an opportunity to learn how to configure and troubleshoot the PIX, Adaptive Security Appliances and Firewall Service Module product lines with Magnus Mortensen.  Magnus is a Technical Assistance Center (TAC) engineer supporting Cisco's firewall security products in Research Triangle Park, North Carolina. He also takes part in the monthly TAC Security Podcast, which covers a wide range of network security related topics as well as troubleshooting and configuration tips and tricks from a TAC engineer's point of view. His specialties include the Cisco ASA Adaptive Security Appliance, Cisco Firewall Services Module, and Cisco IOS Software firewall technologies. He is currently studying for his CCIE Security Lab.

Remember to use the rating system to let Magnus know if you have received an adequate response.

Magnus might not be able to answer each question due to the volume expected   during this event. Our moderators will post many of the  unanswered  questions in other discussion forums shortly after the  event. This  event  lasts through October 8, 2010. Visit this forum  often to view  responses  to your questions and the questions of other  community members.

cisco_admin1
Level 3
Level 3

с Ириной Ильиной-Сидоровой

 

Read the bio

Во время презентации эксперт Cisco TAC Ирина Ильина-Сидорова рассказала о проведении типовой установки ISE в варианте «несколько узлов», рассмотрела основные требования к оборудованию и инфраструктуре сети.  Также Вы узнали о «типовых» вариантах много-узлового решения и рекомендациях по выбору обслуживаемых клиентов.

 

Ирина - инженер центра технической поддержки Cisco в Брюсселе. Ирина работает в группе WLAAAN и занимается поддержкой AAA, Wireless и TrustSec направлений (технологий беспроводного доступа и контроля доступа к сети, а также Cisco TrustSec). Является техническим лидером по продукту Cisco ISE. Ранее в Cisco Ирина работала в российском отделении Advanced Services, где занималась технической поддержкой заказчиков на территории России и стран СНГ.

 

 

Ссылки:

cisco_admin1
Level 3
Level 3

Cisco Adaptive Security Appliance (ASA) Firewalls: Lifeline of Today’s Data Centers - Slides from Webcast with Akhil BehlWith Akhil Behl

These are the slides from the live webcast.

Akhil Behl is a solutions architect with Cisco Advanced Services, focusing on Cisco collaboration and security architectures. He leads collaboration and security projects worldwide for the enterprise segment as well as the collaborative professional services portfolio for the commercial segment. Previously at Cisco, he spent 10 years in various roles at Linksys and the Cisco Technical Assistance Center. He holds CCIE (Voice and Security), PMP, ITIL, VMware VCP, and MCP certifications. He has published several research papers in international journals, including IEEE Xplore. He has been a speaker at prominent industry forums such as Interop, Enterprise Connect, Cloud Connect, Cloud Summit, Cisco SecCon, IT Expo, and Cisco Networkers. He is the author of Securing Cisco IP Telephony Networks by Cisco Press.

During this live event, Cisco subject matter expert Akhil Behl focussed on various new features of the Cisco ASA firewall as a next-generation data center firewall in terms of its capability, scalability, and performance. The emphasis will be on Cisco ASA as a next-generation data center firewall, providing clustering and intelligent threat defense using Cisco ScanSafe technology and access control based on Cisco TrustSec. The essence of the session will revolve around how Cisco ASA 5500 series firewalls can deliver high-class performance with utmost reliability and stakeholder satisfaction in today’s competitive environment.

During the live webcast, following were covered:

  • An introduction to Cisco ASA 5500 and 5500-x series firewalls
  • Cisco ASA next-generation firewall technology for borderless networks
  • Insight into Cisco ASA clustering
  • Overview of Cisco ASA web security (ScanSafe)
  • Overview of Cisco ASA TrustSec

Expert Panelists were Sumanta Bhattacharya and Parminder Pal Singh. They were answering some of your technical questions during this live event.

Webcast  related links:

cisco_admin1
Level 3
Level 3

Welcome to the Cisco Networking Professionals Ask the Expert conversation.

Read the bio

This is an opportunity to get an update on the Physical Security with Cisco expert Gerry Burgess.

Remember to use the rating system to let Gerry know if you have received an adequate response.

Gerry might not be able to answer each question due to the volume expected during this event. Remember that you can continue the conversation on the Security sub-community, shortly after the event. This event lasts through May 6, 2011. Visit this forum often to view responses to your questions and the questions of other community members.

cisco_admin1
Level 3
Level 3

Welcome  to the Cisco Networking  Professionals Ask the Expert conversation.  This is an opportunity to get an update on Dynamic Multipoint VPN with  Mike Sullenberger. Mike has been working with TCP/IP networking for 19  years and has been with Cisco for 14+ years where he is a Distiguished  Support Engineer (DSE) in Customer Advocacy. His technical expertise is  in the areas of TCP/IP, IPsec VPNs, Routing Protocols, NAT and HSRP. He  is the principle architect of the Dynamic Multipoint VPN (DMVPN)  solution, where he works on DMVPN network designs, troubleshooting and  the design of new DMVPN features. Mike has a Bachelors of Science degree  in Mathematics and he is a CCIE in Routing & Switching since 1997.

Remember to use the rating system to let Mike know if you have received an adequate response.

Mike might  not be able to answer each question due to the volume expected  during  this event. Our moderators will post many of the unanswered    questions  in other discussion forums shortly after the event. This   event  lasts  through October 1, 2010. Visit this forum often to view   responses  to  your questions and the questions of other community   member

cisco_admin1
Level 3
Level 3

[toc:faq]

Introduction

Vikas.png

Vikas Saxena is a Customer Support Engineer at the Cisco Technical Assistance Center Security and VPN team in India. He also holds the CCIE Security certification: CCIE #19971.

This document contains the answers provided for the questions asked during the live "Ask the Expert" Webcast session on the Topic - AnyConnect: Configuration and Troubleshooting


The series of Ask The Expert sessions is available in the Ask The Expert section of Cisco Support Community.

The Complete Recording of this live Webcast is present below:

AnyConnect

Q. Under what circumstances (in which topology) we should configure AnyConnect Client?

A. Usage of AnyConnnect Client is generally not Topology specific and it can be used in the scenarios where in one would need to tunnel all traffic via SSL. Any communication to internal network form Outside is a common practice where in one would use AnyConnect.

Q. What is the difference between Cisco VPN Client and AnyConnect VPN Client?

A. The underlying protocol used by the client are different, IPSec client will use IKE where AnyConnect will use SSL encryption. There is difference in the compatibility with OS ( support in vista both 32 and 64 bit, win XP, win 2k, MAC OS X, and RED HAT linux version 9 or higher ) , wherein it is required to install the package initially or pushed from ASA, and no admin privilege are required subsequently, hence less admin overheads required for installing and maintaining IPSec Client.

Q. I have AnyConnect configured but whenever I tried to connect it through web it connect as clientless VPN rather running AnyConnect profile. What could be issue?

A. We will have to check the configuration from the ASA. However, the common issue will be that SVC protocol is not enabled in the group-policy

Q. What is difference between Clientless and AnyConnect VPN client?

A. With clientless there is no ip address assigned from the head end ASA and the traffic is proxied via the ASA, and ip address is assigned from the pool with AnyConnect and hence it has features of IPSec client. Hence AnyConnect will have full tunneling features, unlike clientless vpn. Clientless support both a browser-based (no client) and thin-client (port-forwarding, Smart-Tunnels)

Q. We're running the ASA with IPSec-Client only and are now trying to add SSL Support. The group Policy should be taken upon LDAP-Group names. This should be done by Cisco ACS5.1. Is there any Configuration example on how to combine ASA,ACS and LDAP?

A. I am not able to find end to end config example, Here is the ACS 5.1 user guide that talks about it:- http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.1/user/guide/users_id_stores.html#wp1138165. Basically, we do a lookup for user group and map it to access policies and under the access policy, send the class attribute 25 with the group ppolicy name.

Q. How can we download the identity certificate from certificate server?

A. CA Server normally signs the Certificate Signing Request and same has be to imported or pasted in base64 as identity certificate. If external CA server like godaddy etc is used then they will go ahead and sign the request for you. If your own CA server is been used then, vendor documentation needs to be followed. Following link could be helpful for further understanding. http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00808a61cd.shtml.

Q. What could be the issues when configuring AnyConnect and site to site on same ASA?

A. There should not be any issues while configuring L2L and AnyConnect on a single ASA. We will suggest using different tunnel-group and group-policy to isolate the two.

Q. Do I need a own certificate for each ASA in a A/S Cluster?

A. No, the Certificates are automatically replicated to standby ASA in a A/S setup. Exception:Certificates replicated in PKCS12 format are not replicated due to bug ID CSCsr71150. The workaround is to Issue the command "write standby" on the active ASA and it will sync the configs and certs.

Q. If i want to configure VPN over web what should i need to know?

A. For AnyConnect VPN over Web TCP port 443 should be open (unless changed). If DTLS is used; ISP should also have the DTLS port to be opened on the path. By Default on ASA TLS and DTLS port are configured to 443.

Q. How the vpn acceleration control (vac) using on vpn server side? what are the advantages?

A. VPN acceleration card is for IPSec client, and not for SSL clients. For IPSec client when used with hardware based encryption is used to offload CPU cycles, and faster processing of packets, unlike with software based encryption.

Q. I am getting error for AnyConnect No assigned address?

A. Most probably the IP address pool is not defined under AnyConnect Connection profile > Client address pool. Please check here.

Q. Why is the local CA not supported on ASA Cluster?

A. This issue is being addressed under an Enhancement request. Please contact TAC for more details.

Q. Why LDAP and not RADIUS with a windows NPS policy server?

A. If I understand the question correctly, then AnyConnect to ASA and xauth from Windows NPS using Radius or LDAP. If this is correct then I don't see a reason why RADIUS should not work. Though I don't have a documentation on that right now, but this should work.

Q. SBL won't function?

A. Refer to the following documentation: http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00809f0d75.shtml In case we still face issues with SBL, we will have to look into the DART bundle to identify the issue. Will suggest contacting TAC.

Q. Where can we find information about DART?

A. Here is the url with more info on DART : - http://www.cisco.com/en/US/docs/security/vpn_client/anyconnect/anyconnect24/administration/guide/ac08managemonitortbs.html#wp1055965.

Q. Why is it not possible to use the Essential license and some premium licenses at the same time?

A.  AnyConnect Essential License is for basic AnyConnect functionality, however, Premium license have advanced features (CSD, WebVPN, end point assessment etc) plus it also have base features provided by essential license. Therefore, once you enable premium licenses, essential license is overwritten.

Q. Could you sum up all the VPN Clients with a little bit of history up until now the latest version with differences in capability's?

A. The Cisco IPSec VPN Client version 3.x did not had the virtual adapter in it. This caused the protocols having the IP address configuration information in the payload (example FTP) to face several issues. In version 4.0 virtual adapter was introduced and this caused Split Tunneling to work fine. This also made troubleshooting easier as we were able to capture packets on the virtual adapter. The major advancement was the support for Windows Vista and Windows 7 (both 32 and 64 bit) Operating System. AnyConnect is considered as the major advancement in SSL VPN technology.

Q. Can I enable WebVpn with AnyConnect Essential License?

A.  No. We cannot enable WebVpn with AnyConnect Essential license as the license is specific for AnyConnect only. You need to give the command AnyConnect essential on the WebVpn to disable WebVpn feature on the ASA.

Q. Is Client Authentication supported in SSL VPN?

A. Yes. Client Authentication is supported in SSL VPN including AnyConnect. Client Certificate is also supported. The ASA can check the Client Certificate and you can have the certificate maps as well. Similar to LDAP Map Certificate Map can also be created. The user who belongs to a department called sales will have the certificate with the OU as sales. This user is automatically binded to the sales group.

Q. Can we configure QoS for Remote VPN ,particularly for voice traffic?

A. Qos on ASA is actually not regular QOS as you can't mark the traffic with the DSCP values.There are only 2 queues the Low Latency Queue(LLQ) and the Best Effort Queue(BEQ). We cannot mark traffic but we respect the marking already present on the traffic. Based on marking we can put the traffic to wither the LLQ or the BEQ..

Q. Can I prevent certain users from unknown location or untrusted pc to be connected to a network?

A. Yes this can be done. This is not possible on AnyConnect Essential license but can be done using the Full AnyConnect license. You can also have the flexibility of using the Cisco Secure Desktop(CSD).

Miscellaneous

Q. Will the presentation be available for download or later review?

A. Yes, it will be available so that you can review and download. It will be on the Cisco Support Community https://supportforums.cisco.com

.

Related  Information

Content for Community-Ad