cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3518
Views
5
Helpful
22
Replies

Cisco Secure Desktop on FTD

andypowernet85
Visitor

Afternoon,

When browsing to the public IP of the FTD managed by FMC, I am being  directed to /CACHE/sdesktop/install/start.html and presented with a Cisco Secure Desktop page.  Does anyone know this can be disabled and why it is being presented?

Regards,

22 Replies 22

rschlayer
Level 6
Level 6

Looks like you have AnyConnect VPN enabled, you can disable that portal using FlexConfig: https://bst.cisco.com/bugsearch/bug/CSCvp81746

andypowernet85
Visitor

Thanks, but that would not help if you still wanted to provide access to the web portal to download anyconnect.

@andypowernet85 please see this bugID: https://bst.cisco.com/bugsearch/bug/CSCwi63184?rfs=qvred

Basically, you need to add a Flexconfig to specify "without-csd" in your tunnel-group (aka connection profile)

Thanks for the info! That would be under both defaultwebvpn and the specific RA connection profile?

@andypowernet85 

If they are exposed via your VPN configuration, yes.

Hi Marvin,

The bug to fix ASA/FTD side is CSCwk74566. It is now fixed on ASA, pending fixed FTD release.

The CSCwi63184 is for fixing the CSC side, but that is not related to the browser access.

Are you referring to the CSD page being displayed while DAP is enabled?

Hi Ronnie,

That is correct. To clarify:
DAP is configured, connecting to an ASA DefaultWebvpnGroup with a browser. "Without-csd" is NOT configured.

0. User is asked to authenticate.
1a. Without fix - browser is redirected to CSD install page, which doesn't work.

1b. With fix - browser is redirected to CSC download page.

A fixed FTD version is not yet there.

Thank you very much.  Can you please update when a fix is available for the FTD and what version of upgrade to?  Security team literally gave me a hard time on this for months, even getting our Cisco reps + a Cisco engineer on a group call simply to justify making an exemption for this issue in the Wiz scanner.

This should be fixed in next MRs for FTD. Tentatively planned between end of April and end of June 2026, depending on version.
Please subscribe to bug notifications to get notified when a fixed version is released.

I just noticed FTD v7.2.11-313 got released on 2/11 and we are running on the 7.2x series.  Does v7.2.11-313 fix this issue?

The fixed FTD 7.4.7 is now available.

We've upgraded to v7.7.11 a while back to support geo blocking on the external interface.  Guess we are out of luck again on this one since we can't go backwards to 7.4.7

Review Cisco Networking for a $25 gift card