- Checked "Enable split tunneling" and added other networks
- The configuration was sent successfully to the router, but received an error about the firewall not recognized.
- Added entry to firewall to allow port 443 via the Public IP address of WAN interface.
Tried accessing via web browser remotely and received a Page cannot be displayed, also tried accessing via AnyConnect Client remotely and was unable to connect.
After going back into SSL VPN in CCA (without making any changes in CLI), it told me that the configuration on the device was unrecognized and to continue I had to delete the current SSL VPN config and re-create it. Even after recreating it still did not work.
Here is the configuration:
ip inspect name SDM_MEDIUM https
ip address 220.127.116.11 255.255.255.0
ip address xxx.xxx.xxx.xxx 255.255.255.240
ip access-group 104 in
ip nat outside
ip inspect SDM_MEDIUM out
crypto map SDM_CMAP_1
service-policy input sdmappfwp2p_SDM_MEDIUM
service-policy output sdmappfwp2p_SDM_MEDIUM
interface Virtual-Template3 type serial
ip unnumbered Loopback3
ip nat inside
ip local pool SDM_WEBVPN_POOL_1 192.168.232.10 192.168.232.19
access-list 104 permit tcp any host xxx.xxx.xxx.xxx eq 443
If CCA doesn't recognize the firewall, it is likely the problem. You will probably have to delete the FW settings, the VPN settings, and then readd them. Have you made changes to the FW outside of CCA? If so, you should look at the CCA out of band guide for this.
This UC500 was configured quite a long time ago and before CCA was really used for all the configuration where CLI was necessary for different features. Since there are a lot of customization and it's a production system, we currently do not want to rebuild the system to be "in-band" at this point. I have opened up SSL (port 443) on the existing firewall, is there other ports and/or protocols that need to be opened on the firewall? Can you please send me an example of a firewall configuration that has SSL VPN configured and working?
Configure Multicast Paging on the Cisco IP Phone 7800 Series or 8800 Series Multiplatform Phone
The Cisco IP Phone 7800 and 8800 Series Multiplatform Phones provide voice communication over an Internet Protocol (IP) network...
Add Call Park on a Cisco 7800 or 8800 Series Multiplatform Phone Key Expansion Module
Call park allows the user of the phone to put an incoming call on hold so that the call can be retrieved on another phone. A call is park...