On an ASA 5510 running 9.1(3), the asdm_media_termination address, which is different than the interface address, is answering https traffic as if though it was the interface address and offers to run ASDM download/launcher.
Is there a way to prevent this from happening? It came up during a penetration test by a third party.
Note, the users' remote phones may only be on networks that use dynamic public addresses.
BenefitsDocumentationPrerequisiteImage Download LinksLimitationsSupported PlatformsLicense RequirementsTopologyStep-By-Step ConfigurationConfigure Virtual ServiceActivate the virtual service and configure guest IPsConfiguring UTD (Service Plane)Configurin...
Login to the FXOS chassis manager.
Direct your browser to https://hostname/, and log-in using the user-name and password.
Go to Help > About and check the current version:
Check the current version availa...
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...