03-10-2025 07:01 AM
Afternoon,
When browsing to the public IP of the FTD managed by FMC, I am being directed to /CACHE/sdesktop/install/start.html and presented with a Cisco Secure Desktop page. Does anyone know this can be disabled and why it is being presented?
Regards,
03-10-2025 07:20 AM
Looks like you have AnyConnect VPN enabled, you can disable that portal using FlexConfig: https://bst.cisco.com/bugsearch/bug/CSCvp81746
03-10-2025 08:15 AM
Thanks, but that would not help if you still wanted to provide access to the web portal to download anyconnect.
03-10-2025 08:29 AM
@andypowernet85 please see this bugID: https://bst.cisco.com/bugsearch/bug/CSCwi63184?rfs=qvred
Basically, you need to add a Flexconfig to specify "without-csd" in your tunnel-group (aka connection profile)
03-10-2025 09:37 AM
Thanks for the info! That would be under both defaultwebvpn and the specific RA connection profile?
03-10-2025 08:28 PM
If they are exposed via your VPN configuration, yes.
02-16-2026 05:30 AM
Hi Marvin,
The bug to fix ASA/FTD side is CSCwk74566. It is now fixed on ASA, pending fixed FTD release.
The CSCwi63184 is for fixing the CSC side, but that is not related to the browser access.
02-16-2026 05:38 AM
Are you referring to the CSD page being displayed while DAP is enabled?
02-16-2026 07:36 AM
Hi Ronnie,
That is correct. To clarify:
DAP is configured, connecting to an ASA DefaultWebvpnGroup with a browser. "Without-csd" is NOT configured.
0. User is asked to authenticate.
1a. Without fix - browser is redirected to CSD install page, which doesn't work.
1b. With fix - browser is redirected to CSC download page.
A fixed FTD version is not yet there.
02-16-2026 08:00 AM
Thank you very much. Can you please update when a fix is available for the FTD and what version of upgrade to? Security team literally gave me a hard time on this for months, even getting our Cisco reps + a Cisco engineer on a group call simply to justify making an exemption for this issue in the Wiz scanner.
02-17-2026 02:40 AM - edited 02-17-2026 04:02 AM
This should be fixed in next MRs for FTD. Tentatively planned between end of April and end of June 2026, depending on version.
Please subscribe to bug notifications to get notified when a fixed version is released.
02-20-2026 10:53 AM
I just noticed FTD v7.2.11-313 got released on 2/11 and we are running on the 7.2x series. Does v7.2.11-313 fix this issue?
02-24-2026 07:16 AM
You should be able to use flexconfig with the "portal-access-rule" as of 7.2.11.
It fixes this bug: https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwk14657
04-21-2026 11:32 PM
The fixed FTD 7.4.7 is now available.
04-22-2026 05:25 AM
We've upgraded to v7.7.11 a while back to support geo blocking on the external interface. Guess we are out of luck again on this one since we can't go backwards to 7.4.7
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide