Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Firefox ignores Anyconnect certificate

I've configured my IOS router for anyconnect SSL connections with the configuration below.  Whenever I try to connect to the SSL gateway with the any connect VPN client my firefox browser terminates the session after the certificate is not trusted even though the SSL gateway url has been added to trusted certificates.  Are there any steps I'm missing in my configuration or browser settings?

 

webvpn gateway MY-CISCO-WEBVPN-GATEWAY
 hostname My871W
 ip address 50.174.58.234 port 443 
 ssl encryption aes-sha1
 ssl trustpoint my-trustpoint
 inservice
 !
webvpn install svc flash:/webvpn/anyconnect-win-2.5.6005-k9.pkg sequence 1
 !
webvpn context HudsonHome
 secondary-color white
 title-color #CCCC66
 text-color black
 ssl authenticate verify all
 !
 url-list "BUFFALO2T"
   heading "HOME SECURE INTRANET"
   url-text "STORAGE" url-value "http://192.168.4.10"
 !
 !
 policy group policy_1
   url-list "BUFFALO2T"
   functions svc-enabled
   mask-urls
   svc address-pool "SSLPOOL"
   svc keep-client-installed
   svc dns-server primary 75.75.75.75
   svc dns-server secondary 75.75.76.76
 default-group-policy policy_1
 aaa authentication list sdm_vpn_xauth_ml_1
 gateway MY-CISCO-WEBVPN-GATEWAY domain cisco
 inservice

 

 

 

 

crypto pki trustpoint my-trustpoint
 enrollment selfsigned
 serial-number
 subject-name CN=firewallcx-certificate
 revocation-check crl
 rsakeypair my-rsa-keys
!
!
crypto pki certificate chain my-trustpoint
 certificate self-signed 02
  3082020A 308201B4 A0030201 02020102 300D0609 2A864886 F70D0101 04050030
  55311F30 1D060355 04031316 66697265 77616C6C 63782D63 65727469 66696361
  74653132 30120603 55040513 0B46484B 31303038 35304C5A 301C0609 2A864886
  F70D0109 02160F4D 79383731 572E4C41 4B455649 4557301E 170D3032 31313035
  30343334 34325A17 0D323030 31303130 30303030 305A3055 311F301D 06035504
  03131666 69726577 616C6C63 782D6365 72746966 69636174 65313230 12060355
  0405130B 46484B31 30303835 304C5A30 1C06092A 864886F7 0D010902 160F4D79
  38373157 2E4C414B 45564945 57305C30 0D06092A 864886F7 0D010101 0500034B
  00304802 4100D0BA 6F9E3E2B 0ACCE7A0 B07754C0 4BAE78B4 165E21E7 69BDC4A8
  3167E3CA E58B8C2C CE6D2C62 12DF19A4 D94E998D ECE355A2 3A78D135 ABE434E7
  3DF36022 90AD0203 010001A3 6F306D30 0F060355 1D130101 FF040530 030101FF
  301A0603 551D1104 13301182 0F4D7938 3731572E 4C414B45 56494557 301F0603
  551D2304 18301680 14FA2184 EA08A50D 96D9DE21 A82D1580 6D39898F 2D301D06
  03551D0E 04160414 FA2184EA 08A50D96 D9DE21A8 2D15806D 39898F2D 300D0609
  2A864886 F70D0101 04050003 41007436 311ED06C 82B38EEF 81B98EC9 BB70E093
  B024936C F049D3D9 E18D4BC2 866206F0 4A1351CA 01067C8E 118C9EE7 91C73007
  1F216270 8A18AB66 C2610819 8C56

  • VPN
142
Views
0
Helpful
0
Replies
This widget could not be displayed.