cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
365
Views
0
Helpful
1
Replies

Can't get SSL to work for WebVPN

mattdeemer
Level 1
Level 1

Hi all,

I'm trying to get webvpn setup, and have it all configured correctly.... but there seems to be a problem with the SSL part.

I can connect on port 80, it redirects to port 443... but never shows the login box, just keeps trying to load.

I can telnet to port 443 fine and i've disabled all other services using port 443 (like http secure-server).

The status is UP for the gateway and context. I've no idea what to do next. It appears to be trying, but not succeeding. I've tried different IPs, on different sides of the NAT. I've tried with loopback ip, ips on the VLAN, the public IP etc.

Please please help, here's some info...

MD1#sh webvpn gate MD

Admin Status: up

Operation Status: up

Error and Event Logging: Disabled

IP: 192.168.2.199, port: 443

SSL Trustpoint: SSLVPN

FVRF Name not configured

MD1#sh webvpn cont MD

Admin Status: up

Operation Status: up

Error and Event Logging: Disabled

CSD Status: Disabled

Certificate authentication type: All attributes (like CRL) are verified

AAA Authentication List: default

AAA Authentication Domain not configured

Default Group Policy not configured

Associated WebVPN Gateway: MD

Domain Name and Virtual Host not configured

Maximum Users Allowed: 25

NAT Address not configured

VRF Name not configured

MD1#sh webvpn install st svc

SSLVPN Package SSL-VPN-Client version installed:

CISCO STC win2k+ 1.0.0

1,1,3,173

Mon 12/11/2006 18:41:54.43

MD1#sh webvpn install st csd

SSLVPN Package Cisco-Secure-Desktop version installed:

CISCO CSD IOS

3,1,1,45

Mon 10/23/2006 11:18:00.42

Thanks

~Matt

1 Reply 1

mattdeemer
Level 1
Level 1

PS: I've tried recreating the SSL certificate to no avail.

If i enable the https server for SDM etc, the SSL certificate works fine.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: