VPN Type to use With Windows RDP Client
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-04-2020 07:30 PM
I am using a Cisco ASA5540 firewall, and I would like to know which VPN solution would be the ideal choice for using RDP to remove into a Windows 2019 Server. There are three different types under the VPN Wizard, in the ADSM, and I am not sure which one would be best or appropriate to use. I am thinking that the configuration which uses the AnyConnect Client is the way to go, but need advice. Thank you very much!
- Labels:
-
AnyConnect
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-04-2020 10:16 PM
Hi,
What license do you have your ASA firewall? The license will tell you how many anyconnect peers you can have. If you don't have enough anyconnect, you can use the ipsec vpn.
Thanks
John
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-05-2020 11:06 AM
Hello John,
It appears that I have 10 AnyConnect Premium Peers, so this is plenty for us:
ciscoasa5540(config)# show version
Cisco Adaptive Security Appliance Software Version 9.1(7)32
Device Manager Version 7.8(2)151
Compiled on Tue 04-Sep-18 08:37 by builders
System image file is "disk0:/asa917-32-k8.bin"
Config file at boot was "startup-config"
ciscoasa5540 up 11 days 13 hours
Hardware: ASA5540-K8, 2560 MB RAM, CPU Pentium 4 2000 MHz,
Internal ATA Compact Flash, 256MB
BIOS Flash AT49LW080 @ 0xfff00000, 1024KB
Encryption hardware device : Cisco ASA-55xx on-board accelerator (revision 0x0)
Boot microcode : CN1000-MC-BOOT-2.00
SSL/IKE microcode : CNlite-MC-SSLm-PLUS-2.08
IPSec microcode : CNlite-MC-IPSECm-MAIN-2.09
Number of accelerators: 1
0: Ext: GigabitEthernet0/0 : address is 001a.2f94.4f56, irq 9
1: Ext: GigabitEthernet0/1 : address is 001a.2f94.4f57, irq 9
2: Ext: GigabitEthernet0/2 : address is 001a.2f94.4f58, irq 9
3: Ext: GigabitEthernet0/3 : address is 001a.2f94.4f59, irq 9
4: Ext: Management0/0 : address is 001a.2f94.4f55, irq 11
5: Int: Internal-Data0/0 : address is 0000.0001.0002, irq 11
6: Int: Internal-Control0/0 : address is 0000.0001.0001, irq 5
Licensed features for this platform:
Maximum Physical Interfaces : Unlimited perpetual
Maximum VLANs : 200 perpetual
Inside Hosts : Unlimited perpetual
Failover : Active/Active perpetual
Encryption-DES : Enabled perpetual
Encryption-3DES-AES : Enabled perpetual
Security Contexts : 2 perpetual
GTP/GPRS : Disabled perpetual
AnyConnect Premium Peers : 10 perpetual
AnyConnect Essentials : Disabled perpetual
Other VPN Peers : 5000 perpetual
Total VPN Peers : 5000 perpetual
Shared License : Disabled perpetual
AnyConnect for Mobile : Disabled perpetual
AnyConnect for Cisco VPN Phone : Disabled perpetual
Advanced Endpoint Assessment : Disabled perpetual
UC Phone Proxy Sessions : 2 perpetual
Total UC Proxy Sessions : 2 perpetual
Botnet Traffic Filter : Disabled perpetual
Intercompany Media Engine : Disabled perpetual
Cluster : Enabled perpetual
This platform has an ASA 5540 VPN Premium license.
Serial Number: JMX1112L1JH
Running Permanent Activation Key: 0x133c6c4f 0x3cca370e 0x9882a598 0x897810c8 0x0a2c0289
Configuration register is 0x1
Configuration last modified by enable_15 at 09:33:39.966 UTC Wed Aug 5 2020
ciscoasa5540(config)#
So, you would recommend using the AnyConnect client on the remote Windows 10 desktop where the RDP session is being initiated?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-05-2020 04:08 PM
Hi,
Yes, go ahead and use the anyconnect.
Thanks
John
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-05-2020 09:46 PM
I have preferred ASDM GUI to configure. It can auto-generate AnyConnect VPN Profile in XML format, (such profile feature are auto re-connect, client controlled by remote desktop etc.)
Otherwise using profile editor Cisco AnyConnect Secure Mobility Client Administrator Guide, Release 4.0
Wizard->VPN Wizard->AnyConnect Wizard...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-08-2020 02:13 PM
Okay, so I am having some additional issues with the implementation of VPN on our Cisco 5540 firewall. I tried to locate and download the AnyConnect client for the Windows 10 desktop computers, and I found that there is something offered by Microsoft Store, which I installed on my Windows 10 computer, but have no idea how it works. It literally installed as part of the OS. So I was wondering where I could obtain the actual Cisco AnyConnect client. I cannot seem to be able to find it on the Internet, via Google searches. Any ideas?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-08-2020 06:49 PM
