cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
479
Views
3
Helpful
2
Replies

A little vpn question

cnrs-dsi
Level 1
Level 1

Hi

We have an asa 5550 and we must give access to a server in our datacenter.

We don't need to authentificate the client ( the application has an internal authetification process).

The goal is to crypt data anf certify the destination server for the client. We must use anyconnect SSL vpn.

What is the best configuration solution for you ?

Thanks a lot

2 Replies 2

rahgovin
Level 4
Level 4

As you already stated, the solution is to use the Anyconnect client so that a user once connected has full tunnel access to the server. This means basically setting up an ssl tunnel between the user and the ASA. And make sure to use the split tunneling option so that the user has internet access as the same time.

You can configure the same using the guide below.

http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00808efbd2.shtml

Thanks for your answer.

But the doc explain how to use anyconnect with client authentification.

I only need "a sort of" anonymous connection without client authentification. The goal his only to prevent a "man in the middle attack"

by verify that the cleint connects to the "good" server. (just like an https webserver with a valid certificate)

@+