AnyConnect Portal Login - unable to choose connection profiles

Hello

We have an AnyConnect-setup, using several profiles of connection for different clients.

However, we have a problem where some of them are not available to choose from on the portal of connection using a web browser. I tested it on IE and Chrome. Whenever I choose one of these groups, it automatically goes down to the first group in the list. This affects about half of the connection profile.

The ASA in question is a 5510, run 9.1 (7).

Hello

Here you go:
After upgrade to 9.1.7 users are unable to select certain groups of tunnel in the webvpn login page
https://Tools.Cisco.com/bugsearch/bug/CSCuw85261

Kind regards
Dinesh Moudgil

PS Please rate helpful messages.

Tags: Cisco Security

Similar Questions

  • How to restrict the use of the connection profile Anyconnect to traffic from an interface?

    Hello

    A few questions about the profiles connection Anyconnect and dynamic access policies:

    • I set up multiple profiles connecting Anyconnect with different characteristics. I want one of the profiles to be visible and usable only when the Anyconnect client connect through a specific interface (and not the outside interface). How can this be configured? As it is now all profiles are visible via all interfaces compatible VPN.
    • DAP: When dynamic access policies are configured, these will be global or is it possible to link a policy to a specific connection profile? I would like to configure the DAP Protocol to be effective only when you use a specific connection profile. What is a good way of thinking? What I want is: when a user Anyconnect choose a specific connection profile, it needs to connect using a DAP which requires membership in an ad group and existence of a local file.

    Best regards

    Thor-Egil

    • Unfortunately, you cannot restrict the interfaces of the AnyConnect fitting profile is assigned to AnyConnect connection profiles are global settings, no interface specific setttings, therefore, it will be available no matter what interface the AnyConnect is connected to.
    • DAP political work as an access list. It in the lowest priority to highest priority and he stops at the first match. For example, you can create a number of policies on what you want to match on. You cannot however force the user to authenticate to AD when they choose a specific group of tunnel. DAP is used to apply that only users that meets policy is allowed access. For example: If the user belongs to a specific ad group and also have a file exist, the user will be allowed access to use the AnyConnect. So it's the application that the user connects from a company laptop where you specified the policy, that is to say: exist in AD and have a specific file in his laptop. This is to ensure that those who try to connect to the site of the company non-portable, or internet kiosk have accessed to the VPN, because they may not be protected and can infect your corporate network, if they are allowed to access.

    Hope that makes sense.

  • Online backup is unable to update its settings in the windows registry. Your connection profile must support access to the registry to be able to use the online backup.

    OT: Online backup.

    When I try to use quicken backup, I get this message: online backup cannot update its settings in the windows registry.  Your connection profile must support access to the registry to be able to use the online backup.  Please run the Setup program by using the run as Administrator option.  How can I do this?

    Right-click on the file and choose Run as administrator.

  • Error message "User profile Service is a not the user of the connection profile cannot be loaded" when you try to connect using the Administrator profile

    Original title: cannot use my administrator profile

    When loging on my laptop, I get this error when I click on my profile administrator "user profile Service is not the user of the connection profile cannot be loaded. This comes after the password is accepted. The only way I can connect to my computer is one of my accounts of comments. I can't change anything because I can't sign as an administrator. How can I fix? I have a Compacq laptop running Windows Vista

    Original title: cannot use my administrator profile

    When loging on my laptop, I get this error when I click on my profile administrator "user profile Service is not the user of the connection profile cannot be loaded. This comes after the password is accepted. The only way I can connect to my computer is one of my accounts of comments. I can't change anything because I can't sign as an administrator. How can I fix? I have a Compacq laptop running Windows Vista

    If you cannot connect to your admin account, no tutorials can help you because they need you to connect to an administrator account to carry out the instructions.

    See if the following can get an admin account...

    Go to Safe Mode...

    Restart your computer > immediately and repeatedly pressing the F8 key until you see a black and white screen. The top/down arrow and select Mode safe mode with networking.

    Now, while in safe mode, you perform one of the following?

    1 can connect to your account admin without the error message?
    If so, do. Then do a system restore. Choose a date when you were free to login to your account admin as your restore point.

    http://www.howtogeek.com/HOWTO/Windows-Vista/using-Windows-Vista-system-restore/

    If the system restore does not slove the problem, then use this tutorial

    http://support.Microsoft.com/kb/947215

    2. If you are unable to log in to your account administrator in safe mode, you see another administrator next to your account?
    If so, you are lucky. This is the built-in Administrator account.
    There is, by default, no password.
    It could connect and do the system restore.

    If the system restore is not enough, then perform the tutorial even as above:
    http://support.Microsoft.com/kb/947215

    If you can't do or of what precedes, I'm afraid you will have to re - install your Vista.

  • Disable the download Anyconnect client / turn off the url connection

    Hello

    Is there a way to disable the Anyconnect client download when you navigate to the anyconnect url? Or just make the connection of the url is not accessible
    While users can still connect with their client anyconnect installed in the corporate network.

    Thank you!

    Dave.

    You can't disable the download directly. This had been discussed several times here at least one CSC who also confirmed a case of TAC. Link.

    A hack is that if your image Anyconnect is an older, users will never invited to be updated.

    Re URL, you can turn off the alias that fill the drop-down list on the web portal, but also long as your have the SSL VPN service active, external interface of the ASA will be used toward the top of the login page to less than the default connection profile.

    What is your reason for wanting to turn off in the first place? Perhaps there is another method to achieve what you want.

  • Block certain Applications via without client AnyConnect Portal

    I need to set up a connection profile through ASDM v 6.3 for a user to access a certain web application only.  The user connect only in the web portal for remote access.  Can someone tell me how to configure it in the ASA?

    Greatly appreciated.

    Under the ASDM--> VPN for remote access--> clientless SSL VPN access--> group policies--> modify the relevant policy for your webvpn:

    -Then under construction: just disable everything except the bookmark that you configured for this web application in particular 1.

    Hope that helps.

  • Logical relationships in DataModeler version 4.1.0.866 unable to choose over Mac Yosemite 10.10.1 866

    Hi team,

    I can't select logic and physical relationships in DataModeler version 4.1.0.866 on Mac Yosemite 10.10.1 866 (Java SDK 1.8). DataModeler does not allow me to choose. I mean the following scenario: I create two entities (tables) and add a logical relationship (or physical) between them. After that I can't choose the relationship in the diagram window. In the meantime I still can select the relationship in the browser window.

    Could you please suggest me it is a bug (maybe a platform specific issue) or have I missed something in the options of the software?

    I found a topic on the same issue. It describes the same problem, even if the subject is unanswered and has been archived.

    New bug - build logical relationships in version 4.0.2.15 unable to choose 15.21 on Mac

    In the end, if it is a bug (even a specific platform), where do I publish details about it for one day in the future for a fix of the Oracle team?

    Kind regards

    Kostyantyn

    Kostyantyn salvation,

    Thanks for reporting this problem.  As you suggest, there doesn't seem to be a problem specific to the platform.

    Another user has also reported a similar problem: MDG: cannot click on the relationship lines in the diagrams on the Retina Mac screens

    I connected a bug on this issue.

    Kind regards

    David

  • Unable to choose the range in iMovie

    Unable to choose the range of iMovie 10.1.2

    Hi, Jeff.

    You can select a range inside a clip with your clip in the timeline, placing your cursor on it and hold the 'r' key when you drag your cursor over the clip while pressing your mouse or track pad.  The range will be described in a yellow box.

    To select a range of multiple clips, select the first clip, and then select the last element while holding down the SHIFT key.

    Best,

    -Rich

  • Error blue screen STOP: 0x0000007e. I powercycled the sys, unable to choose for sure (keys do not work when you try to select a mode) sys is trying just to go back to the blue screen. Help, please

    STOP: 0x0000007e (0xc000001d, ox8537008 0xba4c3508 0xba4c3204) and the system would not come to the top.

    Error blue screen STOP: 0x0000007e. I powercycled the sys, unable to choose for sure (keys do not work when you try to select a mode) sys is trying just to go back to the blue screen. Help, please

    Symptoms: Booted computer, loaded the raid drivers and showed at the start screen XP for half a second then to BSOD with a Stop error Code 0x0000007E - see also a lot of users (0xC0000001D, 0 x-, etc.) as well.

    Solution:

    1 boot from your Windows XP CD and start the recovery console. You may need to press F6 while RC loads in order to load the SATA drivers. you will have a prompt c:\WINDOWS to the console.

    2. type: CD $NtUninstallKB977165$ \spuninst (it's the update, I had to uninstall to get out of the boot loop, other updates can be uninstalled by changing the name of the directory to $NtUninstallKBCODE$, where KBCODE is the code KB)

    3. type: BATCH spuninst.txt

    4. type: exit

    Don't forget to configure your system to boot from the HD before resuming. I hope this helps. Saved me a lot of hassle today.

    -Tom Steele
    http://www.hawkandtom.com Tom Steele

  • When I send messages in windows mail, icon that says unable to choose the recipient

    When I send a message in windows mail, I have an icon that says that I am unable to choose recipients.  I use windows vista 64 bit

    Try this:

    Open the applet default programs, which you can access from the start menu or via the Control Panel, then click on the first item: "set your default programs." After a few seconds, a list of programs appears. Click on "Windows Contacts". If there is no answer with "this program has all its flaws" then attach it by clicking on the option indicated by the first green arrow.
     
    If still no joy, try to compact and repair the database.
     
     
     
  • SRA 4600 Web Application Firewall blocks access to the Portal login page.

    We have a 8.0.0.1 - 16 4600 running and run the Web Application Firewall.  We had a few reports of users home that our portal page was not available, only tried IE, but everything went well here.  Today we had an internal machine with the same question and noticed that it was blocking WAF access: "threat of avoided WAF: Injection SQL 1 attack" you can see nothing wrong with this machine that may be cause the WAF to block the Portal login page.  Here are the event log:

    "Jun 10 09:34 sslvpn1 SSLVPN: id = sslvpn sn = C0EAE4745184 time =" 2015-06-10 09:34 ' vp_time = '2015-06-10 14:34 UTC' pri fw = xx.xx.xx.xx = 2 m = 34 c = 402 src = dst = xx.xx.xx.xx xx.xx.xx.xx user = 'Unknown' usr = 'Unknown' msg = "prevented WAF threat: SQL Injection attack 1 ' URI=remote.ncmic.com:443/ rule-match =" _ga = ga1.2.1366358136.1433946841; " _dc_gtm_ua-21325736-1 = 1 "AttackCat = 'SQL Injection attack 1' somm ="SQL Injection is a technique of attack used to exploit websites that construct SQL statements from user-supplied input,"hamid = category '9005' = 'command execution - SQL Injection' agent =" Mozilla/4.0 (compatible; " MSIE 7.0; Windows NT 6.1; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729 .NET CLR 3.0.30729; Media Center PC 6.0; NET4.0C;. NET4.0E; Tablet PC 2.0)' geoCountryID = '0' geoCountryName = 'LAN' geoRegionName = 'unknown' geoCityName = 'unknown '.

    Other machines can access the page without problem... thoughts?

    Can not reproduce this problem at the moment...

  • VPN access query remote ASA - several group policies for the unique connection profile

    Hi all

    Two quick questions here that I need to help.

    1. in an ASA 5525, is it possible to have several group policies for a single connection profile?

    Scenario: A customer is running F5 Firepass to their VPN solution and this device is used by them to have multiple strategies group by the connection profile. We plan to migrate them to ASA (5525) and I don't know if the ASA can support that.

    2. in an ASA-5525 for Clientless Remote access VPN, can pass us the page to connect to an external server? For example, if I have a connection with a URL profile setup: "'https://wyz.vpn.com/ ';" for the LDAP/Radius Authentication, but for https://wyz.vpn.com/data and https://wyz.vpn.com/test I want to HTTP based authentication form and this page needs to be sent to an external server that is to say ASA step will manage this page, but rather the first page for this is served by the external server.

    Scenario: One of our clients is running F5 Firepass to their VPN solution. On the F5 they have pages of configuration such as the https://wyz.vpn.com/ that the F5 shows to the user when they connect via VPN without client; However if the user types https://wyz.vpn.com/data in the browser, the traffic comes to the F5, but F5 redirects this traffic to an external server (with an external url as well). Then it's this external server that transfers the first page of the user requesting authentication for HTTP form based authentication information.

    Thanks in advance to all!

    Hello

    You can have fallback to LOCAL only primary method.

    http://www.Cisco.com/c/en/us/TD/docs/security/ASA/asa90/configuration/gu...

    HTH

    Averroès.

  • Several connection profile with the profile settings of 'master' unique in force.

    I am trying to install "existing" of several user profiles that, as soon as the opening of session will load automatically the parameters of a "master" profile  This "master" profile will be updated periodically by the administrator.  I want to eliminate the need for the administrator manually copy the update 'master' profile to all existing user profiles.  Instead, in the case of each user login they would automatically have profile settings updated, while now the permission level for each user.  I'm not a computer scientist, but I am sufficiently well informed to be able to follow some fairly general instructions.  I'm very grateful for any input.  Windows 7 Ultimate

    Could only be done through the development of a custom software that must be run under the main administrator account and would update the respective user accounts directly.  A task force in and of itself would be particularly useful, but I guess that computers A and B distinct users that may be useful.
    What you want to do would be best addressed with a true Windows server and domain that would allow the creation and the management groups and a lot of administrative control.

  • Unable to choose in the drop-down list

    I don't know what his name, so I'll give an example. I go on YouTube and open my subscriptions & playlist. I push the tab more, and I can see my other titles of the playlist. When I try to type on one of the titles, the option button close. I can not open & take an option on a website. If I have the chance and I was fast enough to push an option before the box closes it will open the file or the site without problem. I tried double tapping on the option button to keep it open, but it never works. Anyone know how to fix this?

    Hello

    Thanks for posting on the Microsoft community.

    If I have understood correctly, you are unable to choose an option in the drop-down list.

    If you have another browser option, I suggest that you try to open the particular website on this browser and see if it works.

    Please perform the following methods to resolve the problem, if you use Internet Explorer as your browser:

    Method 1:

    This can be caused because of compatibility problems with the Web site. Then I suggest that you try to open the Web site in compatibility mode.

    Check out the following link to open a website in compatibility mode:

    http://Windows.Microsoft.com/en-us/Internet-Explorer/use-compatibility-view#IE=ie-11

    If this does not work, try Method 2.

    Method 2:

    Try resetting Internet Explorer.

    Note: By resetting Internet Explorer settings, return you it to the State wherever it was when it was first installed on your computer. This is useful to solve the problems that could be caused by the settings that have been changed after installation.

    Warning: Reset the Internet Explorer settings can reset security settings or privacy settings that you have added to the list of Trusted Sites. Reset the Internet Explorer settings can also reset parental control settings. We recommend that you note these sites before you use the reset Internet Explorer settings. Also re - activate the Add-ons.

    Check out the following link and follow the steps to reset Internet Explorer:

    http://support.Microsoft.com/kb/923737

    I hope this helps. Feel free to answer us back with the results.

  • Behance prosite membership - unable to choose software

    I bought behance prosite for my portfolio and the way to do it was by subscribing to one or more applications of CC. The problem was that I couldn't choose. Photoshop is automatically chosen and I have been unable to choose another. In this case After Effects.

    I already contacted support, but they do not answer! So I don't know if it's just like that or if something went wrong in the buying process. And it becomes too difficult, I can not find the place to talk or chat to someone from the support team, I have to go through dozens of steps that does any you where.

    Any help?

    Moving to this discussion on the Adobe Creative Cloud forum.

Maybe you are looking for