09-20-2013 01:42 PM
Hi All,
The following is my setup: on my ASA5525 with 9.1 I have clientless ssl VPN access configured which works fine while the webpage in the bookmark is http. But once the bookmark is changed to https I always got the connection failed, server xxx unavailable. DNS part is fine since the same server works with http, https part is ok since without vpn from internal network it works fine. Cert on the internal server was issued by our internal CA, actually our ASA has the root CA of this cert as well and also the ASA has identity cert as well (other VPN uses cert based authentication). I tried to play with client ssl version command on ASA side but it didn't help (tlsv1, sslv3, auto) always same issue. There is cert validation option in 9.1 but it is set to permit even if the cert can't be validated. Is there any other thing what can affect this https site proxy? Next one what I want to do is to capture the traffic flow and see what's going in. And also I am wondering that maybe the ssl encryption which is set to aes128 causes the issue.
But in advance I would appreciate if someone could give a hint.
Thanks,
Csaba