02-19-2025 03:18 AM
Hi,
Just after some information or technical advice on this. I am trying to set up Cisco Secure Client (any connect) on a multi-context firewall in ASA mode but keep getting "Internal Server Error", when visiting the firewall's URL. After reading more on it, I am trying to find out if this is even possible on a multi-context firewall or is this one of the limitations?
We have a previous standalone ASA with this set up on and working fine. Currently we send 3rd party supplier to the website (our firewall URL), which takes them to a page so they can then download the any connect software. Allowing them to then connect.
If it is possible, then there must be something up with my config/setup, but I wanted to make sure I wasn't wasting my time if it wasn't even an option on multi-context firewalls.
Any advice or help would be appreciated. Thank you.
Solved! Go to Solution.
02-19-2025 04:53 AM
AnyConnect VPN is supported in multi-context mode on Cisco ASA firewalls, but with significant limitations. The WebLaunch feature which allows users to download the client from the firewall web interface is not available in multi-context mode Here (CSCuw19758)
Remote Access VPN support in multi-context mode was introduced in ASA version 9.5.2 (if i remember correctly) with Flash virtualization for Remote Access VPN added in version 9.6.26. several VPN features remain unsupported in multi-context mode, including IKEv1, stateful failover, client profile download, and VPN load balancing Here.
To work around the WebLaunch limitation, administrators need to distribute the AnyConnect client software through alternative means, such as email or a separate download portal2. It's important to note that the Secure Client Premier license is required for multiple context mode; the default or legacy license cannot be used Here .
When configuring Remote Access VPN in multi-context mode, administrators should be aware of resource management considerations. By default, VPN resources are disabled and must be explicitly configured to allow VPN tunnels.
have a look on this link and also cisco provided video how to setup a anyconnect/secure cleint Here It will put you in right direction.
02-19-2025 04:53 AM
AnyConnect VPN is supported in multi-context mode on Cisco ASA firewalls, but with significant limitations. The WebLaunch feature which allows users to download the client from the firewall web interface is not available in multi-context mode Here (CSCuw19758)
Remote Access VPN support in multi-context mode was introduced in ASA version 9.5.2 (if i remember correctly) with Flash virtualization for Remote Access VPN added in version 9.6.26. several VPN features remain unsupported in multi-context mode, including IKEv1, stateful failover, client profile download, and VPN load balancing Here.
To work around the WebLaunch limitation, administrators need to distribute the AnyConnect client software through alternative means, such as email or a separate download portal2. It's important to note that the Secure Client Premier license is required for multiple context mode; the default or legacy license cannot be used Here .
When configuring Remote Access VPN in multi-context mode, administrators should be aware of resource management considerations. By default, VPN resources are disabled and must be explicitly configured to allow VPN tunnels.
have a look on this link and also cisco provided video how to setup a anyconnect/secure cleint Here It will put you in right direction.
02-19-2025 07:56 AM
Great reply, exactly the info I needed to know. Thanks.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide