cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
187
Views
0
Helpful
7
Replies

SSL VPN still has problems

eoncablewire
Level 3
Level 3

I tried version .34 tonight and I am still unable to upload a client package. I looked for logs and there were none. For some reason CCA does not always make logs for me. I have had this problem with 2.01, 2.1, 2.1 .33, 2.1 .34

I wanted to try the suggested SSL vpn fix with the IOS as recommened by TAC.

Any idea when this is going to be fixed?

Thanks

7 Replies 7

eoncablewire
Level 3
Level 3

I also requested long ago that when adding a client package that CCA allow you to choose from a package located in flash, otherwise you have to re-download it everytime you create the SSL vpn.

Do you have the exact recommendation that TAC suggested?

I will be looking into this.


Thanks,

Marcos

Hi,


I received the following comment from development:

If the customer is referring to anyconnect, we recently tested anyconnect-win-2.3.2016-k9.pkg.

I realize there is a pkg for every platform (mac, linux, pocketpc, etc) but we only tried the windows version.
Can you find out which pkg he is using?
E.g
anyconnect-win-2.3.2016-k9.pkg

I tried anyconnect-win-2.3.0254-k9.pkg, anyconnect-no-dart-win-2.3.0254-k9.pkg.

So what DID work for them?

Please provide the default config they used, the IOS version, the package ( I have it now) and the CCA version so that I can get a successful config.

Thanks

Here is the last email I got from them:

Last you had sent me some configuration lines that you said the
PM gave you and you had asked me about this.  I had replied that all
that configuration is for the ZBF only.  Also, we were waiting to hear
back concerning trying to add "ip unnumbered Vlan75" under the virtual
template interface.  Were you able to add this? 

Also, what version are you at now for IOS image?

As there is a bug concerning ZBF and SSLVPN: 

CSCsr41631 - SSLVPN does not interoperate with IP features - FW, NAT and PBR

and is resolved in 12.4(24)T0


I tried the image above with the .0254 anyconnect package with no success.

So you are talking about a SR520 and not the UC500 right?

Marcos

Yes