cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
803
Views
10
Helpful
3
Replies

How does Anyconnect work from a TCP Layer 4 Perspective?

Hawk
Level 1
Level 1

So from what I understand the ASA uses TCP port 443 by default for Anyconnect SSL VPN.  With this in mind say that a remote user sitting on their home internet connection  wants to connect to their office using anyconnect to look at some files.  If I were to run a capture on that remote computer would it look exactly the same as if the remote computer was going to https://cnn.com?  I know the source & destination would change but as far as everything else.

1 Accepted Solution

Accepted Solutions

Rahul Govindan
VIP Alumni
VIP Alumni

The Anyconnect enables a virtual adapter on the client machine. On your wireless/Wired adapter, you should see tcp/udp 443 traffic to the ASA headend. If you run a packet capture on the virtual adapter, you should see the actual data. Newer versions on Wireshark don't seem to capture this traffic well as far as I remember. 

All allowed vpn traffic on the client is sourced from Virtual adapter after a successful vpn connection. Once encapsulated and encrypted, this is then routed through your physical adapter. 

View solution in original post

3 Replies 3

gbekmezi-DD
Level 5
Level 5
It would be more chatty, but pretty much. All SSL encrypted.

Rahul Govindan
VIP Alumni
VIP Alumni

The Anyconnect enables a virtual adapter on the client machine. On your wireless/Wired adapter, you should see tcp/udp 443 traffic to the ASA headend. If you run a packet capture on the virtual adapter, you should see the actual data. Newer versions on Wireshark don't seem to capture this traffic well as far as I remember. 

All allowed vpn traffic on the client is sourced from Virtual adapter after a successful vpn connection. Once encapsulated and encrypted, this is then routed through your physical adapter. 

Dennis Mink
VIP Alumni
VIP Alumni

funny you mention cnn.com

 

i did a post on tls and wreshark a while a go

 

 

https://ciscoshizzle.blogspot.com/search?q=TLS

 

 

any connect would not be much different

Please remember to rate useful posts, by clicking on the stars below.