cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1915
Views
0
Helpful
2
Replies

anyconnect secure mobility client support for server name indication

ippolito
Level 3
Level 3

Hi,

I'm trying to configure an ASA running 9.5.2.2 to use SNI (server name indication), so that I can have multiple certs on it.

It works if I connect to the device in the browser, but I get a certificate mismatch error with the Cisco AnyConnect Secure Mobility Client v4.2.01022.

I see this link indicating that SNI was submitted as an enhancement request prior to Anyconnect Client v3.1, but I'm wondering if it was ever implemented.

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCue35947/?referring_site=bugquickviewclick

Thanks in advance,

Mike

2 Replies 2

When looking at a wireshark dump of an AnyConnect 4.2.03013 under MacOS and 4.2.01022 under Win 8.1 connection attempt, there is no SNI-extention visible. Doesn't seem to be implemented yet.

--
If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.

Thanks for confirming. Is there a Cisco rep listening in that can tell me if it's on the radar for a future release?

Thanks,

Mike