Skip to main content

ASA5585-X Multi Context mode does not allow clientless webvpn access.


Since migrating to an ASA5585-X running in multi context mode, we have been unable to use the clientless webvpn mode to push down the anyconnect software.  We opened a TAC case and got this response from Cisco.

Thanks for the information provided. Unfortunately clientless webvpn access is not supported in multiple context mode, that is the reason why you get the “Internal server error” when trying to access the ASA using a browser. While using the ASA in multiple context mode you need to find an alternative way to distribute the Anyconnect software and profile to the remote users since you won’t be able to provide it directly from the ASA.
The following enhancement request was opened to address this issue in future releases:

ENH: Add Features in Remote Access VPN in Multi-Context Mode
CSCuw19758
Description
Symptom:
This is an Enhancement Request

Add support for below features in Remote Access VPN in Multi-Context Mode:

1. Username-from-certificate and prefill-username for authorizing to radius
2. DAP
3. Client profile download
4. WebLaunch
5. AnyConnect image configuration per context
6. Stateful Failover
7. IKEv2, IKEv1
8. Stateful Failover
9. Flash virtualization
10. CoA
11. CSD/Hostscan
12. VPN Load-balancing
13. Customization/Localization

Workaround:
None

Currently there is no ETA for a fix to be released 

Comments

Popular posts from this blog

Moving the SSH port on a CISCO router

If you admin your routers over the internet you probably know you should be using SSH. Telnet being sent in clear text is easily sniffed and your passwords captured. However Cisco routers use the standard TCP port 22 for their SSH service. As soon as you open this up to the world and turn on SSH access logging you will start to see hundreds of IP's connecting to your device and running dictionary attacks against you using standard username and password combinations. The majority of these IP's seem to originate from China or Russia and they find your open port extremely quickly. This is very anoying it fills up your log files with these attacks and uses up your system resources dealing with them. I believe they are simply running scans for any open TCP port 22. For this reason I decided I could cut down the amount of attacks by moving the SSH port to a different number. One thing you should know before we start is that there is no way to actually change the SSH port number o...

Error Message %DUAL-6-NBRINFO: EIGRP-IPv4 34256

If you see the error  %DUAL-6-NBRINFO: EIGRP-IPv4 xxxx  is blocked: not on common subnet then it simply means that there are EIGRP devices sending multicast hellos on an interface which have a different IP Range configured to the receiving router.  160617: .Feb 22 15:11:05.194 GMT: %DUAL-6-NBRINFO: EIGRP-IPv4 34256: Neighbor 17 2.31.253.1 (Vlan43) is blocked: not on common subnet                                                     (172.31.252.1/31) 160618: .Feb 22 15:11:12.770 GMT: %DUAL-6-NBRINFO: EIGRP-IPv4 34256: Neighbor 19 2.168.205.0 (Vlan44) is blocked: not on common subnet (192.168.204.1/31)                                                                       ...

Shutting Cisco 3750 Stackwise ports

Today I came across a customers 3750 switch stack which had a flapping stackwise link. The stackwise link was transitioning up/down around 3 times a second and causing massive issues with connectivity and EIGRP routing for the site. Previously I believed that I would need to physically remove the Stackwise cable in order to restore service by shutting the flapping link. It seems it is possible to shut the Stackwise port from the CLI although it is done from enable mode rather than Configure terminal. The command is.. Switch#switch 1 stack port 1 ? disable Disable stack port enable Enable stack port The first number 1 would indicate the switch number in the stack and the second number 1 after the port is the Stackwise port number you want to shut. Make a note of which switch and port you shut as it will not show up in the config or the show outputs which could prove tricky when you want to reenable it.. You can determine the status of the ports using the command below but not how ...