cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

Welcome to Cisco Firewalls Community


306
Views
5
Helpful
1
Replies
Participant

ASA DTLSV1.2 asa9101 issue

Hello,

 

I recently upgraded our asa 5516-x to firmware 9.10 to get the dtlsv1.2 feature for anyconnect. After upgrading the firmware I noticed the clients were still not connecting using dtlsv1.2 but dtlsv1.0. I also had installed the latest version of anyconnect.

 

I then went into the asdm tool and went to device manager->advanced->ssl setup and you can see there is a bubble box next to "The minimum ssl version for the security applieance to negotiate as a "Server"." and it was set to DTLSV1 I changed it to 1.2 and it errors out

 

[ERROR] ssl server-version tlsv1.2 dtlsv1.2

ssl server-version tlsv1.2 dtlsv1.2
^
ERROR: % Invalid input detected at '^' marker.

 

Any advice or ideas?

 

Thanks

1 REPLY 1
Highlighted
Cisco Employee

Re: ASA DTLSV1.2 asa9101 issue

Hi jkay18041,

 

Considering the release notes of ASA 9.10 seems like this is not supported on some specific hardware:

DTLS 1.2 support for AnyConnect VPN remote access connections.

DTLS 1.2, as defined in RFC- 6347, is now supported for AnyConnect remote access in addition to the currently supported DTLS 1.0 (1.1 version number is not used for DTLS.) This applies to all ASA models except the 5506-X, 5508-X, and 5516-X; and applies when the ASA is acting as a server only, not a client. DTLS 1.2 supports additional ciphers, as well as all current TLS/DTLS cyphers, and a larger cookie size.

 

https://www.cisco.com/c/en/us/td/docs/security/asa/asa910/release/notes/asarn910.html#id_25471

 

Hope this info helps!!

 

Rate if helps you!! 

 

-JP-