cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2485
Views
5
Helpful
3
Replies

Clientless VPN and https internal website

farkascsgy
Level 4
Level 4

Hi All,

The following is my setup: on my ASA5525 with 9.1 I have clientless ssl VPN access configured which works fine while the webpage in the bookmark is http. But once the bookmark is changed to https I always got the connection failed, server xxx unavailable. DNS part is fine since the same server works with http, https part is ok since without vpn from internal network it works fine. Cert on the internal server was issued by our internal CA,  actually our ASA has the root CA of this cert as well and also the ASA has identity cert as well (other VPN uses cert based authentication). I tried to play with client ssl version command on ASA side but it didn't help (tlsv1, sslv3, auto) always same issue. There is cert validation option in 9.1 but it is set to permit even if the cert can't be validated. Is there any other thing what can affect this https site proxy? Next one what I want to do is to capture the traffic flow and see what's going in. And also I am wondering that maybe the ssl encryption which is set to aes128 causes the issue.

But in advance I would appreciate if someone could give a hint.

Thanks,

Csaba

3 Replies 3

malshbou
Level 1
Level 1

Hi Csaba,

Please get the captures between the ASA and the server while a VPN client is trying to open the https bookmark.

Did you try to connect from different browsers (Firefox, IE,..) ?

Few more:

- Please describe the error/response you get on the browser, and the bookmark you configured for https.

- Test the https transport between the ASA and the server by TCP ping:

     ASA# ping tcp   443

HTH

------------------
Mashal Shboul

------------------ Mashal Shboul

semin_a_a
Level 1
Level 1

Hello Everyone!

I had the same problem, till I read farkascsgy message, which took me a clue.

I added all of available encryption algorithms and problem had gone. My OWA site became available!

ssl encryption aes256-sha1 aes128-sha1 3des-sha1 rc4-sha1 rc4-md5 des-sha1 dhe-aes128-sha1 dhe-aes256-sha1 null-sha1

Hi,

 

I have Cisco ASA 5540 with IOS asa917-32-k8.bin. I have setup SSL web VPN and having same issue with https internal server unable to access.

I have adding all ssl encryption as above mentioned but same issue. 

 

Please advise if someone fixed it.