cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

1768
Views
0
Helpful
7
Replies
Beginner

TLS1.2 for cisco router webvpn

Hi guys.

 

i'm trying to force router c891 webvpn to use TLS1.2 instead TLS1.0

using followin command:" ip https secure ciphersuite dhe-aes-cbc-sha2"

As per ip http secure ? help cipher above is using TLS1.2 but as far as client connected I can see from client anconnect cipher TLS1.0 in use.

 

Could somebody clarify what's wron?

 

Thank you.

7 REPLIES 7
Hall of Fame Guru

Re: TLS1.2 for cisco router webvpn

Do you have an EC certificate (i.e., Elliptic Curve vs. the more common RSA) on your router?

 

I haven't done it yet with an IOS router but there isd a good writeup below for getting Anyconnect to use TLS 1.2 on an ASA. In the example, it was necessary to have an EC certificate installed and bound to the interface.

 

https://ltlnetworker.wordpress.com/2016/12/18/elliptic-curve-asa/

Beginner

Re: TLS1.2 for cisco router webvpn

Thank you for reply.

 

not yet I don't have ECDSA certificate installed to router but if I'm not mistaked I can use regular RSA certificate with ciphersuite:

--------------

rsa-aes-cbc-sha2  -> Encryption type tls_rsa_with_aes_cbc_sha2 (TLS1.2 & Above) ciphersuite

or
rsa-aes-gcm-sha2 -> Encryption type tls_rsa_with_aes_gcm_sha2 (TLS1.2 & Above) ciphersuite

--------------

These ciphersuites require just RSA certificate to be installed. Is it correct?

 

unfortunately, whenever I tryed them client's anyconnect shows TLS1.0still in use.

Cisco Employee

Re: TLS1.2 for cisco router webvpn

Hi,

Tls1.2 is not yet available for webvpn/anyconnect. it has been added to the secure https server only via:

ENH: Enable support for TLSv1.1 & TLSv1.2 for http secure server/client
CSCuv27265
 
This is for webvpn and not yet implemented. Please wait and see if any update happens to this ENH:
CSCux73159 ENH: TLS1.2 Support for SSLVPN on IOS and IOS-XE
 
HTH
Moh,
Hall of Fame Guru

Re: TLS1.2 for cisco router webvpn

@Mohammad Alhyari,

Thanks for the link to that enhancement request.

 

If one is using an ASA (vs. IOS or IOS-XE), TLS 1.2 has been obesrved to work for AnyConnect when using next generation encryption.

Please refer to the following article:

https://ltlnetworker.wordpress.com/2016/12/18/elliptic-curve-asa/

 

He shows the following outcome from an AnyConnect client establishing a remote access VPN session:

 

Dec 17 2016 17:13:13: %ASA-7-725012: Device chooses cipher ECDHE-ECDSA-AES256-GCM-SHA384 for the SSL session with client outside:89.135.x.x/60831 to a.b.c.d/443

Dec 17 2016 17:13:13: %ASA-6-725016: Device selects trust-point DC1-EC-out for client outside:89.135.x.x/60831 to a.b.c.d/443

Dec 17 2016 17:13:14: %ASA-6-725002: Device completed SSL handshake with client outside:89.135.x.x/60831 to a.b.c.d/443 for TLSv1.2 session

Cisco Employee

Re: TLS1.2 for cisco router webvpn

That is for the ASA not the IOS.

 

Moh,

Hall of Fame Guru

Re: TLS1.2 for cisco router webvpn

Yes - I was editing my reply when you posted. :)

Beginner

Re: TLS1.2 for cisco router webvpn

i see. Thank you Moh.