08-12-2021 02:36 AM
I'm starting to look at providing different policies from our Remote Access VPN to users. Using ASA 5555-X running 9.14(2)15.
Setting a connection alias works fine, I get a dropdown list in the AnyConnect client and the different tunnel policies work when logged in.
But I also wanted to look at the URL aliases. I've set one on each of the profiles that have aliases. But if I try going to it in the browser it returns a page saying "Wrong URL." Trying from the AnyConnect client I get "Connection attempt has failed."
Any pointers for what to look at?
08-12-2021 03:59 AM
08-13-2021 05:03 AM
08-13-2021 08:16 AM
Yes, tunnel-group-list enable is in the config of both boxes.
08-14-2021 12:01 PM
08-14-2021 12:05 PM
URL http: Name IP address/group name
or
URL http: ASA Name/group name
so please can you make URL contain the IP address of outside ASA and hence remove the case that DNS give error or cannot resolve the name.
connection attempt failed I think because the local username for this group BUT this group need URL.
08-16-2021 12:59 AM
I've checked and there aren't backslashes at the end of the urls, so I don't believe that bug applies.
I tried changing the url to an IP address in the config. That doesn't seem to help, visiting in a web browser still gives Wrong Url. Trying to use it in AnyConnect gives a certificate error as the cert doesn't contain the IP address so no longer matches.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide