This document deals with the different types of authentication methods that can be used for AnyConnect VPN on ASA.
Types of authentication
Following is the list of authentication methods available for AnyConnect VPN:
• RADIUS with Password Expiry (MSCHAPv2) to NT LAN Manager (NTLM)
• RADIUS one-time password (OTP) support (state/reply message attributes)
• RSA SecurID (including SoftID integration)
• Active Directory/Kerberos
• Embedded Certificate Authority (CA)
• Digital Certificate/Smartcard (including Machine Certificate support), auto- or user-selected
• Lightweight Directory Access Protocol (LDAP) with Password Expiry and Aging
• Generic LDAP support
• Combined certificate and username/password multifactor authentication (double authentication).
Various encryption methods supported by AnyConnect VPN are listed below:
Strong encryption, including AES-256 and 3DES-168. (The security gateway device must have a strong-crypto license enabled.)
Next-Generation Encryption, including NSA Suite B algorithms, ESPv3 with IKEv2, 4096-bit RSA keys, Diffie-Hellman group 24, and enhanced SHA2 (SHA-256 & SHA-384). (Only applies to IPsec IKEv2 connections. Cisco AnyConnect Premium license required.)
From security standpoint, it does not matter much which Encryption method is being used since IKE will anyway encrypt the traffic between the client and the head end.
I have 2 ASA 5585-X SSP 40 cluster installed with Oldser generation IPS-SSP-40 modules. The IPS modules are used only for their 10 gig interface capability for the data path, without being used for any IPS functionality. The 10Gig Network Interface on the...
Hi,we use 2.3, patch 6 at the customer and the problem is following. The posture checks the update of the AM database and if it is older than 30 days, the PC should be noncompliant. The problem is that the posture updates stopped to download since 09/30/2...
Dear All, Good day, I have cisco Nexus 7000 series switches with VPC configured. I have 3 VDC configured in each nexus switch and the password for 2 VDC in 1 switch and 3 VDC in another switch includes admin VDC password not working. I have to r...
Hi, Can we use Our FTD2120 FWs as proxy. actually we have Symantec Proxy SG and needs to move all its functions to FTD because FTD supports URL/WEB Filtering and can do web filtering. Can we get all types of proxy functio...
Good night all, Been checking up the FTD migration tool as soon we will be migrating cisco ASA active/standby pair to FTD appliances. Based on the Read ME of the Migration Tool (See Link below), it says the following: "The Migration ...