10-04-2019 12:17 AM - edited 10-04-2019 12:20 AM
Hi,
We have configured anyconnect vpn on our Firepower 4k firewall running on ASA OS 9.8 and we are able to connect the VPN successfuly through Cisco Anyconnect Client.
We have a requirement to push the anyconnect vpn client to our customers through the Firewall which is configured with multicontext specifically for the customers.
However, we get "Internal Server Error" when we try to do HTTPS to the Anyconnect VPN IP of Firewall. Same VPN is working fine and getting connected when use secure anyconnect client explicitly.
We checked several forums and learned that Web launch or Web services for Anyconnect VPN was not supported on the firewall with multicontext mode. However would like to re-validate whether this feature is currently supported on multicontext mode for a particular OS version or not yet ? If yes then what is the road map.
Thank you.
Solved! Go to Solution.
10-07-2019 03:54 AM
There is AnyConnect support and AnyConnect image download support with ASA multiple context mode.
However, there is not (to my knowledge) currently support for the Web UI as a means to login and get the initial AnyConnect image. That's as of the current ASA 9.13(1) release.
Cisco doesn't publish feature roadmap information publicly.
10-04-2019 02:28 AM
Hi,
I tested this myself recently on my ASA running 9.9, I receive the same error message. Debug confirms the error "Clientless access has been blocked because it is not supported in Multi-context mode". There is an open bug here with no fix yet available.
I've checked the recent release notes and there is no mention of this feature being supported yet either.
HTH
10-04-2019 03:43 AM
Documentation would suggest AnyConnect RA VPN is supported in multiple context mode starting with ASA 9.5.2
Note: From 9.5.2 multi-context based virtualization support for VPN Remote Access (RA) connections to the ASA.
From 9.6.2 we have support for Flash Virtulaization which means we can have Anyconnect image per context.
Check this link for further information and configuration:
10-04-2019 03:47 AM
More documentation: https://www.cisco.com/c/en/us/td/docs/security/asa/asa95/release/notes/asarn95.html#ID-2172-00000128
10-04-2019 04:20 AM
10-07-2019 03:54 AM
There is AnyConnect support and AnyConnect image download support with ASA multiple context mode.
However, there is not (to my knowledge) currently support for the Web UI as a means to login and get the initial AnyConnect image. That's as of the current ASA 9.13(1) release.
Cisco doesn't publish feature roadmap information publicly.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide