Windows Server Setup RADIUS for Cisco ASA 5500 Authentication
KB ID 0000685 Problem Note: The procedure is the same for Server 2016 and 2019 This week I was configuring some 2008 R2 RADIUS authentication, so I thought I’d take a look at how Microsoft have changed the process for 2012. The whole thing was surprisingly painless. I will say that Kerberos Authentication is a LOT easier to configure, but I’ve yet to test that with 2012, (watch this space). Solution Step 1 Configure the...
Cisco AnyConnect – Securing with Microsoft Certificate Services
Part 1 (How to Configure Microsoft Certificate Services for AnyConnect) KB ID 0001030 Problem I’ve done a lot of AnyConnect deployments, and I’ve even done them with certificates in the past. I’ve seen plenty of articles and blogs that say ‘It would be better to use a PKI deployment like Microsoft Certificate Services’, but there’s very little info out there on how to set it up. I have a client...
AnyConnect – Using a Windows DHCP Server to Lease IP Addresses to the Remote Clients
KB ID 0001050 Problem I did an AnyConnect design for a client recently, and they asked ‘Instead of using the firewall to lease the DHCP addresses to our remote clients, can we use our Windows DHCP Server?” In the past I’ve used Windows DHCP servers for IPSEC VPN clients, but more recently I’ve tended to just use the firewall. The client had some valid reasons for wanting to do so, and given the complexity of...
AnyConnect Client Fails To Get IP From Windows DHCP Server
KB ID 0001053 Problem A few days ago I did an article on AnyConnect and Windows DHCP. I ran it up on the test bench for a client, and everything worked fine. Doing the install my test ‘remote’ client failed to get an IP address. As you can see the DHCP Server (Windows Server 2012 R2) is on a different network segment to the inside of the ASA. Solution 1. First this to do was debug the connection, ‘debug webvpn...