02-17-2016 10:40 PM - edited 02-21-2020 05:44 AM
i am using cisco anyconnect with IKEv2 (ios 9.5,anyconnect 4.2) .this configuration will support hotscan and CSD.
02-18-2016 07:47 AM
Hello,
You can refer to this documentations:
http://www.cisco.com/c/en/us/products/collateral/security/anyconnect-secure-mobility-client/qa_c67-712937.html
02-19-2016 03:05 AM
as per this HostScan and client policy will be port 443
02-19-2016 08:15 AM
Yes hostscan will still use SSL on port 443.
03-08-2016 02:45 PM
Hello Akhil,
To add to what my peer just told you, the IKEv2 tunnel will be working just fine for the users and the way how they connect will use IKEv2, but the XML profile updates(Download of the updates from the Server to the client) hostScan posture module and so on will be performed over a SSL connection, but it should work just fine!
Please proceed to rate and mark as correct the helpful posts! keep me posted if something comes up!
Regards,
David Castro,
03-09-2016 03:35 AM
i configured ,any connect ipsec is working . i blocked 443 firewall level .After that anyconnect ipsec is not connecting to firewall even.
03-09-2016 04:41 AM
If you block port 443, the AnyConnect XML profile wont be able to update its components, how did you block it? as control plane?
03-09-2016 09:00 AM
topology
internet -> router->firewall
router inbound acl(traffic towards firewall) we blocked only 443 and 80 ,allow all other traffic.before asking password error will popup(connection attempt was timeout ).can conform this is due certificate or not.after entering credential product will update.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide