cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
24644
Views
90
Helpful
16
Replies

HTTP Strict Transport Security on ASA

gchevalley
Level 1
Level 1

Our PCI scan vendor has recently began flagging the outside interfaces of all of our firewalls that have AnyConnect enabled on them.  Does anyone know if there is a way to enable HSTS on AnyConnect / WebVPN or the outside interface?

16 Replies 16

vse
Level 1
Level 1

webvpn
 enable outside
 hsts
  enable
  max-age 31536000
  include-sub-domains
  no preload

gunnar.gud
Level 1
Level 1

Is there any way to prevent users from bypassing security issues (does HSTS work on Anyconnect itself?), such as cert errors or tls errors?