cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
960
Views
0
Helpful
3
Replies

Clientless VPN login attempts fail on ASA 5505 8.2

nsalaam01
Level 1
Level 1

I have a ASA5505 with a Security Plus license.  I setup a clientless VPN to allow connections from remote users.  I followed the wizard for the setup and everything seemed fine.  When I test the connection; I do get the SSL VPNB Service login screen.  However, once I input the username and password it does not give me access.   I went to the ASDM and filtered logging to VPN to see what happens when I try to connect.  The error message says "WebVPN session terminated: Client type not supported."  It give no recommended action I guess because it is informational.  Could someone give me some ideas here.  Here is the webvpn config on the ASA:

webvpn

enable outside

tunnel-group-list enable

group-policy GroupPolicy1 internal

group-policy GroupPolicy1 attributes

vpn-tunnel-protocol l2tp-ipsec

username admin password tH.bebrI5Pliz2L8 encrypted

username Itops01 password iahF0pbp9qw1PO3D encrypted

username Itops01 attributes

group-lock value ITOPS

tunnel-group ITOPS type remote-access

tunnel-group ITOPS general-attributes

default-group-policy GroupPolicy1

tunnel-group ITOPS webvpn-attributes

group-alias ITOPS enable

group-url https://192.168.1.3/ITOPS enable

 

 

License info:

Licensed features for this platform:

Maximum Physical Interfaces : 8

VLANs : 20, DMZ Unrestricted

Inside Hosts : Unlimited

Failover : Active/Standby

VPN-DES : Enabled

VPN-3DES-AES : Enabled

SSL VPN Peers : 2

Total VPN Peers : 25

Dual ISPs : Enabled

VLAN Trunk Ports : 8

Shared License : Disabled

AnyConnect for Mobile : Disabled

AnyConnect for Cisco VPN Phone : Disabled

AnyConnect Essentials : Disabled

Advanced Endpoint Assessment : Disabled

UC Phone Proxy Sessions : 2

Total UC Proxy Sessions : 2

Botnet Traffic Filter : Disabled

This platform has an ASA 5505 Security Plus license.

 

 

3 Replies 3

Marvin Rhoads
Hall of Fame
Hall of Fame

What client type are you trying to use? The license you have won't support iOS or Android (mobile) clients.

Hello Marvin,

       We will just be using web browsers such as IE11 and Firefox.  No mobile devices yet.

Shakti Kumar
Cisco Employee
Cisco Employee

 

 

The group-policy that you have defined will not allow the webvpn or client based vpn , as it is not defined under the vpn-tunnel-protocol , add ssl-clientless , as a vpn-tunnel-protocol , to login to WEBVPN