IBM Lotus iNotes 8.5 problem through clientless ssl web vpn - ASA5510 v.8.2(2) OS

Answered Question
Jul 30th, 2010


I am having problems viewing Lotus iNotes running on Domino 8.5 properly through a clientless VPN webpage in my Cisco ASA5510.

One of our clients has implemented Lotus Domino 8.5 and have individual user portals so the users can each access their email, calendar, journals, discussions, etc.  Everything works fine on the internal network, as well as through a full-blown SSL VPN client such as Anyconnect... it is the clientless VPN webpage that gives me an issue.

The issues start occuring when I configure a clientless VPN page for the users to first access, enter in a general username/password, and then they are taken to their first iNotes login page.  The iNotes login page looks fine, and when they log into iNotes everything seems fine.  However, when they start clicking around in different tabs or to open email (all nested within the clientless VPN page), things don't show up, and error message are produced on the iNotes page such as "A problem has occurred which may have caused the current operation to fail".  When I click "Show Console" to get more details, I am presented with:


Domino Release 8.5.1FP3 (Windows NT/Intel)
$HaikuForm - 304.5
Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; InfoPath.2; .NET4.0C)

07/30/2010 12:31:13PM A problem has occurred which may have caused the current operation to fail.
07/30/2010 12:31:13PM 'CSCO_Util.parse_url(...).pathname' is null or not an object
07/30/2010 12:31:13PM https://<IP address of firewall removed for privacy here>/+CSCOL+/cte.js: 9
07/30/2010 12:31:13PM [GBy]- [(token){var ut=HTMLParserUtils;if(this._cur_segment==null){switc]([object Object])
07/30/2010 12:32:08PM [dojo-1.3.2] failed loading with error: [object Error]
07/30/2010 12:32:08PM A problem has occurred which may have caused the current operation to fail.
07/30/2010 12:32:08PM Could not load 'ibm.iNotes.widget.layout.DWASidebarContainer'; last tried '../ibm/iNotes/widget/layout/DWASidebarContainer.js'
07/30/2010 12:32:08PM https://<IP address of firewall removed for privacy here>/+CSCO+00756767633A2F2F7A6E7679312E656E71706E616762612E70627A++/domjs/dojo-1.3.2/dojo/dojo.js: 20
07/30/2010 12:32:08PM [GBy]- [(_51,_52){_52=this._global_omit_module_check||_52;var _53=this._]("ibm.iNotes.widget.layout.DWASidebarContainer")


Users cannot open emails or create new email, nor can they do many other primary functions in iNotes through this clientless VPN.  It looks like the ASA's URL redirection is corrupting what the Domino server is looking for.  This isn't working very well contrary to what Cisco documentation claims is "optimized for Lotus iNotes".

Does anyone have any suggestions? I would like to stay away from using a single SSL cert (losing 2-factor authentication and have to make a firewall exception directly to the server on the network) and stay away from using Anyconnect if I can help it. I would also like to stress that it is iNotes specifically that is giving me this problem, not the full-blown Lotus Notes client that I could make work using Smart Tunnels. 

Troubleshooting steps I have performed:

1.) Proper DNS servers are defined within the firewall

2.) I have tried both full/lite versions of iNotes and both produce the same errors.

3.) I have tried Firefox 3.6.8, IE8, IE6, all on Windows 7 and Windows XP.  I seem to have slightly better results with Firefox than the other browsers, but it is not error free.

4.) I have investigated cookie corruption by deleting all histories and turning off any browser plugins and accelerators

Thank you!

I have this problem too.
0 votes
Correct Answer by Rahul Govindan about 6 years 2 months ago

Have you tried using smart tunnels for the DWA bookmark?Also can u try lite mode with the smart tunnel enabled?

Also in your prob description,  when you say Firefox produces better results than IE, what exactly do you get?

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Rahul Govindan Fri, 07/30/2010 - 17:34

What browser are you using for the clientless ssl connection? There is a known bug with IE6 and 7. Not sure if its the same. Can you try with firefox?

7gtechnologies Sun, 08/01/2010 - 12:26

Thanks for the information about Ie6 and 7.  All of our testing has been primarily from within IE8 and Firefox.  Similar problems as mentioned above in both of these browsers.

Correct Answer
Rahul Govindan Mon, 08/02/2010 - 07:51

Have you tried using smart tunnels for the DWA bookmark?Also can u try lite mode with the smart tunnel enabled?

Also in your prob description,  when you say Firefox produces better results than IE, what exactly do you get?

7gtechnologies Mon, 08/02/2010 - 12:50

Thank you both rahgovin and Todd for pushing me in that direction.  I kept digging through Smart Tunnel documentation and could only find out how to enable smart tunneling on executable files, with no hope of explaining how to only smart tunnel a single bookmark.  It took looking outside of smart tunnels, and taking a closer look at my bookmarks to see that there is a way to enable smart tunnels on the bookmark itself.

Thank you both very much!

martinbornao Tue, 10/19/2010 - 13:00

Hi! I´m having the exact same problem: accessing Lotus Notes 8.5 via web using ASA 5510.

The sad thing is that I have updated IOS to version 8.3.2 and ASDM to version 6.3.4, and the issue still persists.

What I can say is that it works with Google Chrome! (and Java VM 6.22).  Just for testing purposes, give it a try!

From what I have seen so far, It all seems to be an Activex problem... but not so sure :-(

In the meantime, I will keep looking for a solution.

I hope that helps!

Have a great day!


7gtechnologies Tue, 10/19/2010 - 13:21


We ditched this idea and simply bought them an SSL license to use with a domain name.  No ActiveX to worry about, and ultimately slightly more simple for them.  The people that need direct access to anything (ie they need more access than what the Lotus inotes client will give them) use an SSL vpn directly into the ASA.

Good luck!

martinbornao Fri, 10/22/2010 - 05:55

Thanks for the info!

In fact, yesterday I tried that using Anyconnect SSL client, but the Lotus iNotes web interfase is behaving the same way it does with the Clientless option. Did you know if there´s any particular config I should take a look on? Did you use Smart Tunnels? Your help will be very appreciated!

I´m using ASA v.8.3(2) and Anyconnet pkg version 2.5.1025.

Thanks again!

7gtechnologies Fri, 10/22/2010 - 07:15

I used to use Smart tunnels for the clientless VPN, but when we dumped clientless VPNs because we couldn't get them working, I took out the smart tunnels.  Just plain ol' Anyconnect connectivity.  I'm using Anyconnect 2.5.0217 with ASA 8.2(2).  No special settings come to mind.

Another thing to try is make sure you're using an up-to-date version of Java and Adobe Reader on the computers.  We noticed some display problems in addition to problems like Java IE plugins not properly prompting the user to install themselves.

Lastly, to this day we can't get Lotus iNotes to work in Firefox... I would recommend using IE6-8.

Hope this info helps... good luck!

minabi Thu, 11/04/2010 - 14:05

 We don't officially support INotes/DWA 8.5.1. We know that Smart tunnels and 
Clientless Lite mode works. However, Full mode doesn't work correctly  with core native  
Clientless rewriter. Severla issues hav been reported on DQA/Inotes 8.5.x: 

:OWA 2010 is not officially supported. The team is targeting the next major ASA release  

8.4 Release had not yet been Engineering Committed (ECed), so there is no guanteees that  
official 2010 support will be included.


This Discussion

Related Content