cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6871
Views
0
Helpful
10
Replies

ASA SSL AnyConnect VPN

aung.htwe
Level 1
Level 1

I already successfully configure asa site to site vpn.

Now I want to create asa ssl AnyConnectVPN.

Please help me for configuration for Any Connect VPN?

Clienless SSL VPN configuration already on our asa

if  I try to access , the error is "

Login
Login denied. Your environment does not meet the access criteria defined by your administrator.

Please advise for me this error. I changed the user name and password also cannot.

Thanks

Aung

2 Accepted Solutions

Accepted Solutions

Hi Aung,

This is the easiest way to get rid of this message:

webvpn

     no csd enabled

!

dynamic-access-policy-record DfltAccessPolicy

     action continue

The reason why you are seeing the message is because you have a Dynamic Access Policy denying your connection, because your system does not meet the requirements.

HTH.

Portu.

View solution in original post

Aung,

Thanks for the update.

So, now you CAN connect with AnyConnect, but you are unable to access internal resources, correct?

Are you trying by IP address or name?

Thanks.

View solution in original post

10 Replies 10

aung.htwe
Level 1
Level 1

ASA 5510

Licesse - Security Plus

Software version : 8.2 (5)

Thanks

Hi Aung,

This is the easiest way to get rid of this message:

webvpn

     no csd enabled

!

dynamic-access-policy-record DfltAccessPolicy

     action continue

The reason why you are seeing the message is because you have a Dynamic Access Policy denying your connection, because your system does not meet the requirements.

HTH.

Portu.

Thanks Portu,

But I cannot access to share folder even I allow full permission for ntfs permission and share perssion.

Need to changes any thing on asa.

Pls share me for SSL Any Connect VPN.

Thanks,

Aung

Aung,

Thanks for the update.

So, now you CAN connect with AnyConnect, but you are unable to access internal resources, correct?

Are you trying by IP address or name?

Thanks.

Correct, now I can connect from browser to asa , I can login but i cannot access to server.

I trying both server name and IP address.

Thanks,

Aung

Aung,

Please do the following:

#1

capture capin_web match ip host inside_ip host inside_ip_server

Then try to access it via WebVPN, open a new browser and go to:

#2

https://asa_ip/capture/capin_web/pcap

Please attach:

1- show capture capin_web

2- The capture that you just downloaded in step #2.

Thanks.

Portu.



Hi Portu,,

Do you want to test from internal network or external network?

Thanks,

Aung

Where do I run this to make the changes? Do I need to delete all the DAP policies and rebuild? This just started today.