Cisco ASA – Enable Split Tunnel for Remote Clients
Nov17

Cisco ASA – Enable Split Tunnel for Remote Clients

KB ID 0000066 Problem This is a simple job to do from command line, however the world is full of people who would rather spend an hour in the ASDM working out how to do it! So I’ve included both methods. What is split tunneling? This is the process of letting a remote VPN user browse the web, and access local resources etc, from their location whilst connected to your VPN in this case via SSLVPN, but also from WebVPN or IPSEC...

Read More
Cisco ASA: ‘Received an un-encrypted INVALID_COOKIE notify message, dropping’
Apr06

Cisco ASA: ‘Received an un-encrypted INVALID_COOKIE notify message, dropping’

KB ID 0001421 Problem Saw this in a forum today, and knew what it was straight away! While attempting to get a VPN tunnel up from a Cisco ASA (5508-x) to a Sonicwall firewall this was there debug output; Apr 06 00:45:21 [IKEv1]IP = x.x.x.x, IKE Initiator: New Phase 1, Intf Lan, IKE Peer x.x.x.x local Proxy Address 192.168.90.150, remote Proxy Address 10.252.1.1, Crypto map (Internet_map) Apr 06 00:45:21 [IKEv1 DEBUG]IP = x.x.x.x,...

Read More
Windows ‘Always On’ VPN Part 2 (NPS, RAS, and Clients)
Feb18

Windows ‘Always On’ VPN Part 2 (NPS, RAS, and Clients)

KB ID 0001403 Problem Back in Part One, we setup the AD (Groups,) and the Certificate services that will knit everything together. Now we need to configure an NPS server that acts as a RADIUS server for our remote clients, And a RAS Server that our remote clients will connect to. Step1: Network Setup Microsoft have an alarming habit of telling you to connect DMZ assets to the LAN. In their defence I’ve seen some documentation...

Read More
AnyConnect Error – ‘Failed To Get Configuration From Secure Gateway’
Oct19

AnyConnect Error – ‘Failed To Get Configuration From Secure Gateway’

KB ID 0001354 Problem Saw this while attempting to connect to my ASA this week. AnyConnect Secure Mobility Downloader Failed to get configuration from secure gateway. Contact your system administrator Solution Well luckily I’d just made a change so I could focus on the right area straight away. I’d been messing around with the profile xml file associated with my AnyConnect GroupPolicy. If you take a look at my profile...

Read More
Cisco AnyConnect – Running ‘Logon Scripts / OnConnection Scripts’
Oct18

Cisco AnyConnect – Running ‘Logon Scripts / OnConnection Scripts’

KB ID 0001353 Problem I’ve seen this asked a lot in forums, and it came up on EE again today. I’ve never had to set this up in the past, but I’ve posted the links to the correct Cisco articles when people have asked.  After the question was asked again today, I thought I’d take the time to write a decent article on how to do it. Why would you want to do this? You might want to map/reconnect a mapped drive, or...

Read More