Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

Silver

Clientless VPN and https internal website

Hi All,

The following is my setup: on my ASA5525 with 9.1 I have clientless ssl VPN access configured which works fine while the webpage in the bookmark is http. But once the bookmark is changed to https I always got the connection failed, server xxx unavailable. DNS part is fine since the same server works with http, https part is ok since without vpn from internal network it works fine. Cert on the internal server was issued by our internal CA,  actually our ASA has the root CA of this cert as well and also the ASA has identity cert as well (other VPN uses cert based authentication). I tried to play with client ssl version command on ASA side but it didn't help (tlsv1, sslv3, auto) always same issue. There is cert validation option in 9.1 but it is set to permit even if the cert can't be validated. Is there any other thing what can affect this https site proxy? Next one what I want to do is to capture the traffic flow and see what's going in. And also I am wondering that maybe the ssl encryption which is set to aes128 causes the issue.

But in advance I would appreciate if someone could give a hint.

Thanks,

Csaba

2 REPLIES
Bronze

Clientless VPN and https internal website

Hi Csaba,

Please get the captures between the ASA and the server while a VPN client is trying to open the https bookmark.

Did you try to connect from different browsers (Firefox, IE,..) ?

Few more:

- Please describe the error/response you get on the browser, and the bookmark you configured for https.

- Test the https transport between the ASA and the server by TCP ping:

     ASA# ping tcp   443

HTH

------------------
Mashal Shboul

------------------ Mashal Shboul
New Member

Re: Clientless VPN and https internal website

Hello Everyone!

I had the same problem, till I read farkascsgy message, which took me a clue.

I added all of available encryption algorithms and problem had gone. My OWA site became available!

ssl encryption aes256-sha1 aes128-sha1 3des-sha1 rc4-sha1 rc4-md5 des-sha1 dhe-aes128-sha1 dhe-aes256-sha1 null-sha1

561
Views
0
Helpful
2
Replies