12-02-2013 11:26 AM
Hello Everyone,
I have some questions aboult webvpn configuration.
Question 1:
How i can configure web vpn on Cisco ASA version 9.1(3)?
Question 2:
Its possible to configure a plugin to publish a remote desktop application in version 9.1(3)?
If yes, how i can configure this?
Thanks,
Rafael
12-03-2013 04:34 AM
Rafael,
Looks like you're just beginning your journey.
My suggestion is to read the configuration guide and utilize ASDM wizards to help you with basic configuration.
Start here:
http://www.cisco.com/en/US/docs/security/asa/asa91/asdm71/vpn/webvpn-overview.html
It should conicidentally answer both of your questions.
M.
12-03-2013 05:16 AM
Hi Marcin,
Thank you for the links.
I use the Wizard "Clientless SSl VPN Wizard" for configuring webvpn on interface outside and i upload the rdp plugin from Cisco.
The SSL VPN web page appear over internet, but, when i try to log in i receive the error "
AnyConnect is not enabled on the VPN server".
12-03-2013 05:28 AM
Rafael,
I guess you're forcing somewhere Anyconnect startup, check allowed VPN protocols make sure that clientless is allowed.
Make sure also AC is not being forced during startup.
(Those setting are typically in your tunnel group or group policy)
group-policy MY_webvpn attributes
(...)
vpn-tunnel-protocol ssl-clientless
webvpn
anyconnect ask none default anyconnect
The example above starts AC directly.
You can refer to ASA command reference if you need to know what each command does.
M.
12-03-2013 09:20 AM
Marcin,
The problem still persists.
Configuration:
webvpn
enable outside-gvt
anyconnect enable
group-policy SSLVPNGrpPolicy internal
group-policy SSLVPNGrpPolicy attributes
vpn-tunnel-protocol ssl-clientless
webvpn
url-list none
anyconnect ask none default anyconnect
tunnel-group SSLVPN type remote-access
tunnel-group SSLVPN general-attributes
default-group-policy SSLVPNGrpPolicy
12-03-2013 10:35 AM
Rafael,
You didn't read what I wrote
http://www.cisco.com/en/US/docs/security/asa/command-reference/a2.html#wp1743347
Are you using a group-url or some other means to land on tunnel group SSLVPN?
M.
12-03-2013 10:42 AM
Now its working.
I testing with a user linked to an group policy, i create a default user(with no group policy linked) and now the authentication is working, i can use the RDP plug-in for access the internal machines.
But, its not totaly clear for me, i have more some questions:
1 - I can disable the other services in the home?
Actualy i have web applications, browsw networks and terminal servers, i need only terminal servers, its possible to exclude or hide the other applications?
2 - I test using a local user, but i need to configure this for authenticate using a AD environment, i have a group "VPNSSL_USERS" and only users in this group can authenticate in SSL VPN portal, its possible?
Thank you for the patience.
12-03-2013 05:21 AM
Hi Marcin,
unfortunally I've got the same problem but I haven't the correct ASDM for the ASA-OS 9.1(3) version.
I'm not neither able to download the correct ASDM version.
May you post a working configuration example using CLI?
I'm reading this configuration guide:
http://www.cisco.com/en/US/docs/security/asa/asa91/configuration/vpn/vpn_groups.html
but It's very complicated!
thank you very much
giorgio
12-03-2013 05:29 AM
Giorgio,
webvpn
enable "outside interface"
group-policy "GroupPolicy name" internal
group-policy "GroupPolicy name" attributes
vpn-tunnel-protocol ssl-clientless
webvpn
url-list none
exit
exit
tunnel-group "tunnel group name" type remote-access
tunnel-group "tunnel group name" general-attributes
default-group-policy "GroupPolicy name"
12-03-2013 05:43 AM
thank you but I forgot to tell you that I need the support for AnyConnect!
my bad!
giorgio
12-03-2013 05:30 AM
Giorgio,
Can't promise it will answer all your questions, ASDM is definetely a NEED for advanced webvpn config, but have a look at:
http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00806ea271.shtml
It contains both ASDM and CLI config. Some of the configuration changed since that time, but with a bit of pateince and command reference you will find it.
M.
12-03-2013 05:45 AM
Hi Marcin,
thank you for your answer.
As I said to Rafael I forgot to tell that I need the support for AnyConnect too.
My My bad!
thank you
giorgio
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide