AnyConnect on non-standard port (for example, 444)

Hello

Hoping that someone may be able to help because I am confused. I'm trying to implement Anyconnect on an ASA 5505 running 9.0 software (1) / ASDM version 7.1 (1) 52.

I followed various guides online (all about the same) using the wizard. The only difference in my case, it's that I can't use port 443 as it is already in use for ActiveSync. So I want to use instead the 444.

To achieve this I ran the anyconnect VPN wizard according to the instructions and then go to Setup > remote access VPN > and change the port settings here (https and dtls in 444 443 ports).

What then happens client-side:

I can browse the router/site: for example https://123.123.123.1:444 and it makes up the login/password screen, it accepts the credentials as it should be and going through the procedure of download client. All fine so far. When the anyconnect client tries to connect it emits a warning about the certificate (which is ok that I've used self-signed for now) so I have the ability to connect in any case that I chose. He then proceeds to try to connect and just sits there before finally crashing to the customer.

On the side of the ASA of things then I looked at the newspaper so that what is happening and it goes through the following steps:

1 he initiated the handshake, then I see there is an accumulation of my port 444 IP tcp connection, immediately followed by disassembly. The buildup/disassembly continues to repeat until the client blocks.

So in summary, I can get as far as the SAA (to enter the credentials, download the client etc.). The customer can go as far as to acknowledge that the cert is not reliable, I can acknoweldge and move from, and he starts the authentication but just stop there.

I am lost on where to go from here. I wonder if it's something to do with the fact Im not using 443. I also tried installing the client as an installation program independent on another pc and enter the address with the port 444 after (for example 123.123.123.1:444), same result. Tested on windows 7 and 8.1.

Any help is greatly appreciated!

Thank you

Do not do this through the "Assistant", but after doing this through the command one line works on a 9.1 (3) running 5505 - I use port 8086.

The lines for ssh

WebVPN
no activation outside
port 8086
allow outside
AnyConnect enable
tunnel-group-list activate

Note that you must first disable all enable her ' not out ' before changing the port.

Tags: Cisco Security

Similar Questions

  • vMA vCenter 4.1 and non-standard port

    I just implemented the vMA 4.1, everything works obtained auth fine AD, even work.  However, when I try to run a command as a user of the AD, I get this:

    [vi-admin@vma01 ~] [vcenter01] $ esxcfg-mpath - l - vihost esxhost4.globalivewireless.local
    Enter the user name: domain\domainadminacct
    Enter the password:
    Error to connect to the server " " https://vcenter01/sdk/webService': Connection refused

    Don't see much in the newspapers.

    However, if I try to connect to this URL, it will fail - it's because we connect to vCenter using 30443.  The vifp addtarget with - port_number specified work (does not work without the specified port), but it seems standard commands always try to use 443.

    Is it possible to change the nature of the non-use of to our non standard port 443?

    This is more than a concept vCLI, vMA. Think of vMA as just a camera vCLI, instead of having to install the vCLI yourself, vMA is delivered pre-packaged is a Linux device.

    Have a look here for info - http://pubs.vmware.com/vsphere-50/index.jsp?topic=/com.vmware.vcli.examples.doc_50/cli_overviews.3.8.html

    Basically, for each global option such as username, password, server, etc. that you can specify in a file, then instead of typing on each option, you can simply use the – config [fichier_config] that includes your options.

  • Lost the standard games for example heart, Spider, Minesweeper, Solitaire etc when installing Windows 7

    Upgrading to Windows 7 lost regular games for example return of hearts, Spider, Minesweeper, Solitaire, etc., how can I get them?

    This thread contains a solution cannot be confirmed by the original poster, and was left unanswered. Microsoft support is no longer tries to contact the original poster.

    Lisa
    Microsoft Answers Support Engineer
    Visit our Microsoft answers feedback Forum and let us know what you think.

  • application of non-standard port

    I was asked to open the ports 135, 63000 and 65100 for TCP traffic. What are these ports commonly used for?

    See the document RFC 1700:

    http://www.FAQs.org/RFCs/rfc1700.html

    TCP 135 is a windows service:

    Loc - srv 135/tcp Location Service

    Used for WINS, DNS, and DHCP Manager

    TCP 63000 is higher than the well known so it could be any application configured ports (plus large 1024):

    http://www.google.ca/search?hl=en&q=TCP%5C63000&btnG=Google+Search&Meta=

    65100 TCP:

    http://www.google.ca/search?hl=en&q=TCP%5C63100&btnG=Search&Meta=

    sincerely

    Patrick

  • How to send queries dns to non-standard port in windows 8

    I want to send queries dns to nonstandard port (other then 53). I found this article that describes how do (in the windows registry to add HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DNS\Parameters   SendOnNonDnsPort parameter of type dword with the value of the port desired). Unfortunately I could not find this path in the registry of Windows 8 (he has only HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\) and creation, it did not help. So, how can I can change this port, without having to install any additional software?

    Hi Edward,.

    The question you posted would be better suited in the TechNet Forums. I would recommend posting your query in the link below.

    http://social.technet.Microsoft.com/forums/en/category/w8itpro

    Good day!

  • Alerts emails to a non-standard SMTP port

    Is it possible to configure LiveCycle ES 8.2 to send e-mails to alert to a SMTP server on a non-standard port?  In the /AdminUI there is a field for the server, but not for the port.

    Thank you

    Hi Jon

    The ability to configure a nonstandard port in the /AdminUI has been added in the ES2.

    There is a work around that you can use the 8.2.1.

    Depending on the process under the management of the process, open the process called Notification by Email.

    You will see 3 services:

    1. don't send no attachments

    2 send mail

    3. send with map of attachments

    On the properties of each service on the connection settings tab, locate the SMTP Port number.

    You will notice that it is hardcoded at 25.

    Change it to some port that you need for your SMTP server.

    Your task Notifications will now be transmitted using this port.

    Diana

  • Tips for the TCP wait of asynchronous Messages with non-standard expression tanks

    Hi all

    I have a PITA instrument that I need to communicate with in a system of greater control.  This instrument communicates via RS232 to a server running on the PC OEM application.  In order to communicate with the instrument, I have to use the TCP protocol on a specific port on Localhost - So far so good as long the protcol is answer command.

    The problem is that the instrument sends several messages asynchronously of different sizes with a double newline as a tank of termination (there are many CR/LFS all these messages so that they cannot be a MOE) and I am struggling to find a way to manage receive asynchronous messages of variable length with a cusom CHARACTER term. without having simply a fast dedicated for TCP loop reads trying to catch these asynchronous status messages.

    I wish the functions VISA TCP has worked with the local host, given that the properties that can be set to change the chariot of non-standard term.

    Open to suggestions-

    Thank you

    Ronin

    Yes, I'll be streaming in my own string buffer and then to choose the messages out of the buffer when you find the stop character.

    A technique to improve performance, rather than reading a single byte at a time is to use the "immediate" on reading TCP mode and use a high value for the "bytes read" - in this way, it will return all of the data that is there without waiting for all the specified bytes or the time-out. He will wait only the full timeout if 0 bytes are received (which you can ignore) - set to a low value such as 100ms.

  • Member for years non-standard in the dimension of the planning years

    We have a non-standard (planning) the dimension member years called 'No year '. In order to add it to the start, I had to go to the back end of the schedule (tables HSP_OBJECT and HSP_UNIQUE_NAMES) and edit the members there. It was version 9. The order of the years members was then FY95 through FY14, then came year no., then FY15. It worked for our years of start and end in the planning, as our school was FY09 and our end of the year was the year of no., allowing us to the regime through FY14 and entry year no data specific to year n on the forms. It also allowed us to omit 'Year No' of our scripts using a range of FY09:FY14 years (using substitution variables). Now that the year overturned (and, incidentally, we have upgraded to version 11) and our years of planning are FY10 thanks FY15, I would move no. year after FY15. However, I do not seem to be able to do in updating underlying tables above. I make the changes for the two tables, but it is not reflected in the schedule (they appear in the order), and if I try to change it or the other of the two members in the planning (year or FY15), it gives me an error indicating that the Member already exists. Anyone know how I can do to move the No. year Member? I need to not only this year, but to have a process my client can follow each year, moving from that Member within the outline to be directly after the last year of planning.

    Thank you

    Sabrina

    If you want to go on the tables of piracy and changing the order of 'No year '.

    If you run the SQL on your planning application

    Select * from hsp_object where type_objet = 38

    You can see the column in position and will have values like 1000000 = first place, 1000010 = Second Place and so on.

    To change the position you have to raise the value of position of 'No year' and 'FY15.

    setting a day of position set hsp_object = '1000070'
    where type_objet = 38 and object_name = 'No year '.

    setting a day of position set hsp_object = '1000080'
    where type_objet = 38 and object_name = 'FY14.

    Restart planning. Now all this is done at your own risk, and when you app goes boom don't blame me :)
    If 'No year' has been added in the right direction when you add the year, he must always remain as the last position.

    Planning rights object between adjustment ranges ID holders, the normal year (FY..) values are 50002 go
    No year is out of this range for example 50412
    When no. year is added correctly then planning will add a new to the normal range of values for the year (the year last value + 1) and then changes it the order of position

    See you soon

    John
    http://John-Goodwin.blogspot.com/

  • Newby - problems for export non-standard characters. CSV or delimited by tabs

    I'm trying to export data from a table where many fields contain non-standard characters such as double quotes * []] * or * labels *. If I * export to one. CSV file, embedded quotes foul invariably upward alignment of output columns and if I select one * export tabs-delimited *, built-in tabs do the same thing.

    Is anyway that I can specify the text qualifier to use so that I can choose a character that is not used in the text (like, for example the tilde * [*] *)?

    I use discoverer 3.1

    Thanks in advance

    Hello

    With a requirement of export complicated like this, it is often better to create a named calculation that returns the fields in the required format, as a single column, for example

    col1 | » ~'|| col2. » ~'|| COL3

    Then, you can simply export the report to a text and get all the fields with the correct delimiters and the characters replaced.

    Rod West

  • Watch does not recognize the weight class as exercise-how can you add the duration of activity manually because none of the presets eg elliptical etc. is appropriate. Also does not count calories for example 35 when the rest of the group is around 500

    Look does not recognize the weight class as exercise-how can you add the duration of activity manually because none of the presets etc for example elliptical is appropriate and therefore do not count toward the daily goal. Also does not count calories for example 35 when the average of the others in the group is around 500.

    Hello

    When you use the application of the training session, choose the type of activity that best fits your business. For anything else - like weight - select the other category.

    During the follow-up of one year to the next helps:

    • Activity app will credit the ring of progress of exercise with one minute for every minute of the workout.
    • Active calories will be based on the data recorded by the heart rate sensor or a brisk walk, whichever is greater.

    Note, however, that the heart rate sensor is likely to give better results for the workouts that involve rhythmic (for example running) rather than the irregular movements.

    More information:

    Use of the workout on your Apple Watch - Apple Support

  • Using the Serial Port for data acquisition Non-Serial

    I searched the forums and can't find anything on this topic.

    I saw that it was possible to use the parallel port for e/s digital single and I was hoping that the serial port can be configured the same. It seems all VI VISA only to use the serial port to receive ASCII characters at a given flow rate, but is it possible to simply query the status of the line series at my own speed to see if it is high or low, kind of like a single pin DAQ?

    It seems that it would be possible until the serial data are read and controlled by labview, not Windows. Let me know if you have ideas of how to approach this problem, or any comment as to why it is not possible.

    Thank you all!

    Select the property > settings series > Modem of the line parameters. For example, the State of the CTS is an entry to the pc.

    With the help of these lines is a very poor substitute for a scope or map DAQ. The only things you can return is Asserted, Unknown or Unasserted. The range of acceptable signals is important enough. Anything between + 3 and -3 is an unknown state. Your other signals is + / 3 to 15 volts. What type of signals do you really want to capture?

    Edit: there is no such thing as a visa so I have no idea of what you actually use.

  • Set the port for WMI for Windows Server Standard Edition 2003 R2

    Hi guys,.

    Can I know how to solve a static port for WMI using Windows Server Standard Edition 2003 R2?

    Thanks in advance!

    Ask in the forum Windows Server:
    http://social.technet.Microsoft.com/forums/en-us/category/WindowsServer

  • How can I prevent standard users access records personnel administrator for example. photos and documents

    How can I prevent standard users access records personnel administrator for example. photos and documents

    Hello bh51,

    Did you run your antivirus as well as any spyware removal?  As davidhk requested, then you are able to turn sharing off the coast, but it just doesn't work?   I suggest creating a new folder and move the data, and then see if other users are still able to view these.

    Please let us know status.

  • When I try to copy a single file (for example: size of 1 GB) drive hard to any what external memory device via the USB port, the copy process takes several hours to complete

    I use a DELL Studio 15 laptop computer. When I try to copy a single file (for example: size of 1 GB) hard drive to any external memory device (for example: USB key or external hard drive) via the port USB, the copy process takes several hours to complete. I have checked the viruses using McAfee Antivirus, but could not find. Can someone suggest me a solution?

    Hello

    ·          Were there any changes made to your computer before this problem?

    Step 1: Format the external device to the NTFS format and check if the problem persists.

    See: http://windows.microsoft.com/en-US/windows-vista/Convert-a-hard-disk-or-partition-to-NTFS-format

  • Hi, I would like to use one of your images on a product for the purpose of illustration, for example, it will be used to show where people can place their own image on a badge. Standard license would allow this?

    Hi, I would like to use one of your images on a product for the purpose of illustration, for example, it will be used to show where people can place their own image on a badge. Standard license would allow this?

    Hello

    Yes. It totally depends on what application you use.

    See pricing and membership creative cloud plans | Adobe Creative Cloud for plans and prices.

    Kind regards

    Sheena

Maybe you are looking for

  • Need to support Toshiba in Romania

    I have sent 3 emails asking for support in my turn, no one answered. No one answered the phone for 4 months!Anyone know if they exist?We have NO support in Romania for our tour! Toshiba he knows?

  • XP Home: Any keyboard shortcut to reach the Office?

    Hello In Windows 7, the user can reach the office without having to minimize each application one by one by clicking on the rectangular button on the right side of the taskbar. What in XP Home, can I create a button on the taskbar for that? If not is

  • LRT214 management via OpenVPN

    I installed the LRT214 with the current firmware LRT2x4_1.0.4.03_20150914. I am able to connect to the router via OpenVPN; Ping the router and other guests, however, I am unable to manage the router/AP. It seems that the port (80) on the management o

  • BlackBerry Simultor does not work properly in Windows 7 64 bit

    I downloaded 6.0.0.141 and Simulator 4.6.1.333,5.0.0.621 yesterday. My current system is Windows 7. The java version is Java version "1.6.0_17".Java (TM) SE Runtime Environment (build 1.6.0_17 - b04)Java for 64-bit Server VM (build 14, 3 - b01, mixed

  • OptiPlex 360 NIC for Win 7 upgrade

    With the end of XP support in April, I have about 40 360 s Optiplex I want to upgrade to Windows 7. I ran MS Upgrade Advisor, and the only thing that looks suspicious is the Broadcom NIC card. That is the case, I think it would be cheaper to upgrade