03-20-2020 10:10 PM - last edited on 03-24-2020 10:06 AM by Monica Lluis
You can ask your question on your own language:
Español | Português | Français | Русский | 日本語 | 简体中文 |
Here’s your chance to discuss Cisco Secure Remote Working technologies such as AnyConnect, ASA, FTD, Duo, and Umbrella. In this session, the experts will answer questions about emergency licenses, design, configuration, and troubleshooting. Our experts span more than 12 time zones. Also, we’ll be translating the session into multiple languages to provide you with the best experience possible.
This forum event works well as an introduction for those who are not familiar with these security solutions and/or have recently started using them.
To participate in this event, please use the button below to ask your questions
Ask questions from Friday, March 20 to Friday, April 3, 2020
Divya Nair is a Technical Marketing Engineer with the Security Business Group in Raleigh, North Carolina. She has more than 10 years of experience in Cisco network security technologies, including firewalls, IPS, VPN, and AAA; and is currently focusing on VPN and firewall management platforms. Divya holds a Bachelor's degree in Computer Science and Engineering.
**Helpful votes Encourage Participation! **
Please be sure to rate the Answers to Questions
03-25-2020 03:35 PM
I have 24-hour cisco HW replacement support, will a Cisco Tech come onsite to do the replacement during the COVID-19 "stay at home" policies that are emerging? Just concerned if a drive fails, etc that we can get a replacement.
Thank you
03-26-2020 05:51 AM
We have two interconnected enclaves, where the outer enclave is using AnyConnect for access from the Internet.
My enclave is behind an ASA-5585-X, and I need to give a very small set of user access to this enclave. My first thought was nesting one AnyConnect session within another session, creating a tunnel-within-a-tunnel, but it appears that isn't working.
If I had the admins of the outer enclave create a NAT that exposed the outside interface of my firewall, could end-users connect to a different IP address and bypass the outer firewall for a VPN session?
Conceptual layout
Internet ====>> Outside firewall ====>> Outer enclave ====>> Inside firewall (my ASA) ====>> Inner enclave
I need this:
Internet ========================>> VPN ===================================>>Inner enclave
somehow.
Suggestions?
Thanks,
Gregg
03-26-2020 06:56 AM
You can create a Static NAT for the users to access the resources behind the inside Firewall.
Internet ========================>> VPN ===================================>>Inner enclave
Or you can allow the specific Inner enclave subnet on the VPN policy and then to restrict the outside (small set of users) configure an ingress ACL on the Inside FW.
Assuming the Anyconnect VPN is going to terminate on the outside FW and after that everything would be in cleartext.
HTH,
Aditya
03-26-2020 07:45 AM
Assuming the inner enclave subnet information is published to the outer enclave, which it isn't.
I can't use an IP-based restriction, as some of the users who need access to the inner enclave are within the outer enclave.
Is there any way to use the Windows 10 VPN adapter to connect to the ASA?
Gregg
03-26-2020 08:32 AM
Hi,
Is there an issue in using the outer VPN to terminate all connections and have different tunnel-groups/connection profile/group-policy for the outer and inner users? The reason I ask is because using the L2TP client will still be tunnel-in-a-tunnel.
03-27-2020 10:39 AM
03-27-2020 12:10 PM
Hi Monica,
Thank you for sharing that important document.
Our global VPN experts recently delivered a podcast focused on RAVPN and how to optimize AnyConnect performance. The show notes include links to the document you referenced and more:
Bill
03-27-2020 11:03 PM - edited 03-27-2020 11:04 PM
In the case where we are using no-split-tunnel or tunnel-all-DNS for our remote access VPN and combining those features with Umbrella, we have an issue for unmanaged endpoints hitting the Umbrella block page for https sites and getting the certificate error. Given that https is used for 80% (or more) of all web traffic this is increasingly a problem.
For managed endpoints this is not much of a problem as we can push the certificate into local certificate stores via GPO (or other EMM software) as described in the Umbrella documentation:
https://docs.umbrella.com/deployment-umbrella/docs/install-cisco-umbrella-root-certificate
For unmanaged endpoints, telling end users to download and trust the Umbrella certificate is unwieldy. Is there any best practice we can adopt in order to avoid having to do this?
03-28-2020 09:15 AM
Hello Marvin. In case of unmanaged devices, the best practice is to split them into a different network (or identity in Umbrella dashboard) and apply a separate policy to them.
In that separate policy you should not enable the intelligent proxy (no file file inspection and hence no HTTPS decryption), and by keeping all security enforcement only at the DNS layer you will not encounter these issues.
While I understand that this split of traffic is easier when on a corporate network (i.e. guest traffic or unmanaged devices go via separate vlans or separate SSIDs), in your case right now it sounds like you're referring to remote workers who are connecting to VPN and this is the same connection type for managed and unmanaged devices.
In this case you would need to disable the file inspection in all Umbrella policies that cover identities where unmanaged devices are going to be included.
03-29-2020 03:55 AM
Thanks @jonnoble - I was afraid that would be the answer. Good to have it confirmed though.
03-30-2020 08:52 PM
Hi,
when I want to config router from CCP, I get an error :
'Security component has failed. Inorder to work on Router or Security features, do the following. Goto Java Control panel -> Advanced tab -> Java Plug-in tree Entry. Uncheck the check box for Enable next-generation Java Plug-in. Relaunch CiscoCP after this.'
I was trying to uncheck NGN java plug-in but cannot find the plug-in option in the advanced tab. Could you please help.
03-30-2020 11:40 PM
03-31-2020 02:31 PM
I have found and been pointed to step by step for split but I don't want split. Can anyone point me to NOT split tunnel step by step?
03-31-2020 10:10 PM
Hi,
Could you please elaborate on the requirement?
Do you want to disable the Split tunnel? If yes, then you can use TunnelAll option.
Please share the config if possible and what is the use case?
04-01-2020 01:07 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide