AnyConnect Group Authentication With Cisco ISE and Downloadable ACLs (Part 2)
Feb09

AnyConnect Group Authentication With Cisco ISE and Downloadable ACLs (Part 2)

KB ID 0001156  Problem Carrying on from PART 1 Solution Add  > Create Before. Edit the Policy Giv the policy set a name and description > Create a new condition. Set Description to Device Type. Equals > All Device Types (The Device Group You Created Above). Add attribute value. Set Description to RADIUS. NAS-Port-Type-[61]. Equals  > Virtual. Edit the Authentication Policy. Change the identity source to the the identity...

Read More

AnyConnect Group Authentication With Cisco ISE and Downloadable ACLs (Part 1)

KB ID 0001155 Problem To be honest it’s probably a LOT easier to do this with Dynamic Access Policies, but hey, if you have ISE then why not use it for RADIUS, and let it deploy downloadable ACL’s to your remote clients and give them different levels of access, based on their group membership. I’m going to keep things simple, I will have a group for admins that can access anything, and a group for users that can only...

Read More
Cisco ASA – AnyConnect Authentication via LDAP and Domain User Groups
Feb03

Cisco ASA – AnyConnect Authentication via LDAP and Domain User Groups

KB ID 0001152 Problem When I first started doing Cisco remote VPNs, we had Server 2000/2003 and I used to use RADIUS with IAS. Then Microsoft brought out 2008/2012 and RADIUS via NAP. Because I fear and loath change I swapped to using Kerberos VPN Authentication for a while. I had to put in an ASA5512-X this weekend and the client wanted to allow AnyConnect to a particular Domain Security Group “VPN-Users”, so I thought I...

Read More
Cisco ASDM and Windows 10
Feb01

Cisco ASDM and Windows 10

KB ID 0001150 Problem Most of the time I’m on my mac for work, but sometimes when the ADSM fails, I switch to a windows VM (in VMware Fusion). I recently upgraded to Windows 10, and for the most part that’s been a painless process. I did notice though, that when I try to run the ADSM, it will let me install the software, then sit there doing nothing? Note: Also see, ASDM on Windows 10: ‘Cannot find Javaw.exe?’...

Read More
Cisco ASA – Reverse Route Injection with EIGRP
Jan19

Cisco ASA – Reverse Route Injection with EIGRP

KB ID 0001137  Problem I’ve followed your Reverse Route Injection article and its not working? This email dropped in my mailbox a while back As it turns out the article I had written was for OSPF, and this chap was using EIGRP. So I ran it up with EIGRP as well to test. Heres my topology, I want to inject the route for the remote site, into my internal EIGRP routing table. Solution Assuming EIGRP is already setup between the ASA...

Read More
Cisco ASA – Active / Active Failover
Dec10

Cisco ASA – Active / Active Failover

KB ID 0001114 Usually when I’m asked to setup Active/Active I cringe, not because its difficult, its simply because people assume active/active is better than active/standby. I hear comments like ‘we have paid for both firewalls lets use them’, or ‘I want to sweat both assets’. The only real practical use cases I can think of for Active /Active are; You have a multi-tenancy environment and want to offer...

Read More
Cisco AnyConnect – Adding Multiple VPN Devices to the Client
Nov17

Cisco AnyConnect – Adding Multiple VPN Devices to the Client

KB ID 0001011 Problem If you connect to a lot of different firewalls, then constantly having to change the address you are going to can be a pain. Particularly if some clients don’t have a host name for their device, and you can’t remember everyone’s IP addresses. Solution I do this slightly different to most other people, I create a connection file for every endpoint I want to go to, because a) I can transfer them...

Read More
Cannot Connect to TCP Port 2000 (Even over VPN)
Nov17

Cannot Connect to TCP Port 2000 (Even over VPN)

KB ID 0000027  Problem Note: When going through a Cisco Firewall. Even with all ports open you cannot connect to an application or website that uses TCP Port 2000, TCP Port 2000 allthough above the “well Known” range (i.e. above 1024) is used for SCCP (skinny client control protocol) which is a Cisco voice / phone protocol. If you push web traffic through this port – the firewall gets upset. Solution Option 1 (Via Command...

Read More
BT Business Hub 3 – And Cisco ASA 5500
Nov17

BT Business Hub 3 – And Cisco ASA 5500

KB ID 0000762  Problem Warning: If your ASA is running version 8.3(4) or above you are going to have problems assigning public IP addresses from your allocated BT Range (jump to the bottom of the article for a resolution). You have a pool of public IP addresses and you wish to allocate one of these IP addresses to your Cisco ASA Firewall. Note: This is for customers using BOTH ADSL and BT Infinity Solution For this procedure I was...

Read More
AnyConnect Error: ‘The AnyConnect package on the secure gateway could not be located’
Nov17

AnyConnect Error: ‘The AnyConnect package on the secure gateway could not be located’

KB ID 0000406  Problem While attempting to connect to a Cisco firewall with a Linux client (In my case Ubuntu 10.10,) using AnyConnect you see the following error. Or on MAC OSX Error: Cisco AnyConnect VPN Client The AnyConnect package on the secure gateway could not be located. You may be experiencing network connectivity issues. Please try connecting again. Note: You may also see this error on a Mac OSX, or a Windows CE machine....

Read More