cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1947
Views
0
Helpful
5
Replies

Any Connect VPN Security concern Issue.

MOHAMMAD RAZA
Level 1
Level 1

Hi Guys,

I have Configured Any Connect VPN on Cisco ASA & our  mobility users are able to connect VPN successfully and access my LAN environment But our senior management is saying it's provide less security & any hacker can easily hack it. 

Can anyone help on this, how can provide more security in Anyconnect VPN, i am thinking about host checking features in Anyconnect but i think it  works only with secure desktop.

 

 

 

Regards,

Nafis Ashique  

1 Accepted Solution

Accepted Solutions

In short, you have only some steps:

  1. enroll the root-certificate of your PKI to the clients and to the ASA (if not already done).
  2. enroll the client-certificates to the clients. It will be most easy if they are in the user-store. As far as I know, you can't use the certs that are stored in the IPsec VPN client store.
  3. reconfigure the ASA to use certificate authentication

A little bit more detailed way is shown in this document.

View solution in original post

5 Replies 5

First you should ask your management, which concerns they have. And if they say it provides less security, to what do they compare it?

Of course it has to be setup correctly. Correctly means crypto-settings on the ASA, AnyConnect-config on the client and so on.

Checking the host is only one part of the security and can also be done. For that, nowadays you don't use the secure desktop any more. There is an individual host-scan package for that. But you need the AnyConnect Premium license or the Apex license on AnyConnect 4 for that.

But first lets clear out what the concerns are.

Actually they are compare with cisco IPsec client base VPN , which have certificate base authentication and in Anyconnect no have any Certificate base authentication features.

 

Regards,

Nafis

AnyConnect is even more flexible in authentication then the legacy VPN client. And you can also do certificate-based authentication with AnyConnect.

on ASA i can use certificate authentication in tunnel  ipsec attributes but how can use certificate at Client end.

 

 

Regards,

Nafis 

In short, you have only some steps:

  1. enroll the root-certificate of your PKI to the clients and to the ASA (if not already done).
  2. enroll the client-certificates to the clients. It will be most easy if they are in the user-store. As far as I know, you can't use the certs that are stored in the IPsec VPN client store.
  3. reconfigure the ASA to use certificate authentication

A little bit more detailed way is shown in this document.