03-18-2013 07:51 AM - edited 02-21-2020 06:46 PM
I already successfully configure asa site to site vpn.
Now I want to create asa ssl AnyConnectVPN.
Please help me for configuration for Any Connect VPN?
Clienless SSL VPN configuration already on our asa
if I try to access , the error is "
| |||
Login denied. Your environment does not meet the access criteria defined by your administrator. |
Please advise for me this error. I changed the user name and password also cannot.
Thanks
Aung
Solved! Go to Solution.
03-18-2013 08:01 AM
Hi Aung,
This is the easiest way to get rid of this message:
webvpn
no csd enabled
!
dynamic-access-policy-record DfltAccessPolicy
action continue
The reason why you are seeing the message is because you have a Dynamic Access Policy denying your connection, because your system does not meet the requirements.
HTH.
Portu.
03-18-2013 08:28 AM
Aung,
Thanks for the update.
So, now you CAN connect with AnyConnect, but you are unable to access internal resources, correct?
Are you trying by IP address or name?
Thanks.
03-18-2013 07:52 AM
ASA 5510
Licesse - Security Plus
Software version : 8.2 (5)
Thanks
03-18-2013 08:01 AM
Hi Aung,
This is the easiest way to get rid of this message:
webvpn
no csd enabled
!
dynamic-access-policy-record DfltAccessPolicy
action continue
The reason why you are seeing the message is because you have a Dynamic Access Policy denying your connection, because your system does not meet the requirements.
HTH.
Portu.
03-18-2013 08:02 AM
03-18-2013 08:23 AM
Thanks Portu,
But I cannot access to share folder even I allow full permission for ntfs permission and share perssion.
Need to changes any thing on asa.
Pls share me for SSL Any Connect VPN.
Thanks,
Aung
03-18-2013 08:28 AM
Aung,
Thanks for the update.
So, now you CAN connect with AnyConnect, but you are unable to access internal resources, correct?
Are you trying by IP address or name?
Thanks.
03-18-2013 08:40 AM
Correct, now I can connect from browser to asa , I can login but i cannot access to server.
I trying both server name and IP address.
Thanks,
Aung
03-18-2013 09:03 AM
Aung,
Please do the following:
#1
capture capin_web match ip host inside_ip host inside_ip_server
Then try to access it via WebVPN, open a new browser and go to:
#2
https://asa_ip/capture/capin_web/pcap
Please attach:
1- show capture capin_web
2- The capture that you just downloaded in step #2.
Thanks.
Portu.
03-19-2013 12:53 AM
Hi Portu,,
Do you want to test from internal network or external network?
Thanks,
Aung
03-19-2013 01:20 AM
Hi Portu,
Below is download link :
https://dl-web.dropbox.com/get/pcap%20%281%29?w=AADmZ5E5XFpvXuggHAp8pYtUXkrahe9iv7oBEjDhyeJpjA
Thanks,
Aung
09-06-2024 01:55 PM
Where do I run this to make the changes? Do I need to delete all the DAP policies and rebuild? This just started today.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide