CERT ID on ASA change with impact session AnyConnect?

Hello all - I should probably know this answer, however, I'm not 100%.

If I change the cert ID (trust point) of the external interface to use a "most recent" certificate, although there are client AnyConnect connected, the session will end?

I believe that the answer is Yes, since the keys will change.

Any help is appreciated!

Thank you!

Hello

He not disconnect users, because the main purpose of the use of cert in the first place other than identity is to distribute safe symmetric session key. Once this is done, the work of cert is done.

I did a quick test on my end.

I have connected a customer to the ASA using certificates. Here are the results:

ASA-32-25 # sh run all the ssl
SSL server-version everything
client SSL version all
SSL encryption, 3des-sha1-aes128-sha1 aes256-sha1 md5 - rc4-rc4-sha1
Trust SSL SSL outdoors<-- this="" is="" the="" certificate="" applied="" on="" outside="">
SSL certificate authentication CAF-timeout 2

Now, I have connected my client and he got connected successfully:

ASA-32-25 (config) # poster not vpn - its

Session type: AnyConnect

Username: anyconnect Index: 50
Public IP address 192.168.10.2 assigned IP:: x.x.x.x
Protocol: AnyConnect-Parent-Tunnel SSL
License: AnyConnect Premium
Encryption: AnyConnect-Parent: (1) no SSL Tunnel: 3DES (1)
Hash: AnyConnect-Parent: (1) no SSL Tunnel: SHA1 (1)
TX Bytes: 11488 bytes Rx: 1351
Group Policy: Group GroupPolicy_Test Tunnel: Test
Connect time: 12:24:15 EDT Thursday, April 17, 2014
Time: 0 h: 00 m: 04 s
Inactivity: 0 h: 00 m: 00s
Result of the NAC: unknown
Map VLANS: VLAN n/a: no

I removed then, the certificate for the external interface.

ASA-32-25 (config) # points trust without ssl SSL outdoors

And when I checked the status of the connected client, I saw that he was still logged:

ASA-32-25 (config) # poster not vpn - its

Session type: AnyConnect

Username: anyconnect Index: 50
Public IP address 192.168.10.2 assigned IP:: x.x.x.x
Protocol: AnyConnect-Parent-Tunnel SSL
License: AnyConnect Premium
Encryption: AnyConnect-Parent: (1) no SSL Tunnel: 3DES (1)
Hash: AnyConnect-Parent: (1) no SSL Tunnel: SHA1 (1)
TX Bytes: 11488 bytes Rx: 1351
Group Policy: Group GroupPolicy_Test Tunnel: Test
Connect time: 12:24:15 EDT Thursday, April 17, 2014
Time: 0 h: 00 m: 12s
Inactivity: 0 h: 00 m: 00s
Result of the NAC: unknown
Map VLANS: VLAN n/a: no

The conclusion therefore, is that users will not be cut if you change the certificate on the external interface.

Hope that answers your question.

Vishnu

Tags: Cisco Security

Similar Questions

  • Problem with kill session

    Hello

    I want to kill one of my session and I can't :/ I paste this query:
    SELECT sid, serial #, osuser, program, server, machine FROM v$ session;

    Find the sid and serial # my process and carry out this change the command:
    alter system kill session '544 793';

    So, I can see this output:
    change kill system succeeded.

    But once retype selected first, I still have a trial '544 793'?
    Might explain my why?

    Tutu wrote:
    I don't have the privileges to kill the process level OS :/ That from database. But what this process is KILLED? She still exists in the database, is not it.

    Yes, the process is still in the database, using the amount of space between the sessions and processes and other resources of the system as well.
    There may be several reasons for this:
    1 session remains in this status as asociated process is not killed, for example session expected SQLNet client message. Customer at the moment would be an activity that he would receive the error and the session would leave.
    2 PMON can do sometihng with this session. Doing little cleaning, then kill is issued and this session remains for some time.

    In order to get rid of this session - ID opsystem kill command. If do not have rights - you ask someone who has.

  • I can't open videos or change with Movie Maker. Is it because I have a Sony Handycam? He said that there is a lack of "codec". Where can I install the missing codec from?

    original title: help with Movie Maker...

    I can't open videos or change with Movie Maker.

    Is it because I have a Sony Handycam?

    He said that there is a lack of "codec". Where can I install the missing codec from?

    Very frustrating because I've used it before - maybe because I have SP3? But I don't want to uninstall SP3... :-(

    Help, please!

    Thank you!!

    Thanks for the info.

    MPEG files are problematic in all versions of Movie Maker.
    Best bet would be to convert the files to the. WMV format
    before you import into Movie Maker.

    There are many converters available on the net... some
    free... some detail.

    The following freeware converter is just one example:

    (FWIW... it's always a good idea to create a system)
    Restore point before installing software or updates)

    Format Factory (freeware)
    http://www.videohelp.com/tools/Format_Factory
    (the 'direct link' is faster)
    (the file you want to download is: > FFSetup280.zip<>
    (FWIW... installation..., you can uncheck
    ('all' boxes on the final screens)
    (Windows XP / Vista / 7)

    First, you will need to decompress the file or just open the
    Drag FFSetup280.exe out of the folder
    and drop it on your desktop. To install left click.

    Next, after the download and installation of Format
    Factory... you can open the program and
    left click on the toolbar, the "Option" button and
    "Select an output folder to" / apply / OK.
    (this is where you find your files after they)
    are converted)

    Drag and drop your video clips on the main screen...

    Select "all to WMV" / OK...

    Click on... Beginning... in the toolbar...

    That should do it...

    Good luck...

  • CS-mars does support ASA 5500 with version 8.4?

    Dear all,

    My mars is not able to discover devices Cisco ASA cisco ASA 5550 with last fact IOS is compatible with the CS March...

    Thanks in advance...

    Selva

    After some googleing I found that it is not supported...

    For more information, see link below

    http://www.Cisco.com/en/us/docs/security/security_management/CS-Mars/6.1/compatibility/local_controller/dtlc6x.html#wp85319

    HTH,

    GKP

  • ASA EzVPN with several remote subnets

    Hello world

    I'll have the challenge of EasyVPN installation based on ASA 5520, and ASA 5505 (with the ASA5505 as the vpnclient) with several networks behind the ASA 5505.

    Access by the network directly connected on the 5505 to the central site works very well.

    But the second network segment (which is behind a router on the directly connected network) cannot connect to the central site.

    I guess I need to specify that some sort of acl's to be able to do that.

    BTW we do not use tunneling split, because all traffic moves through the tunnel (no local internet access).

    The layout looks like this

    (--LAN--)-5520---5505-(--LAN1--)-ROUTER-(--LAN2--)-(WAN)-

    LAN1 and LAN connection works great through the EZVPN Tunnel.

    LAN2 connection to the LAN does not work through the Tunnel of EZVPN.

    Here is the configuration used so far (outside the normal SHEEP, groups of objects and stuff ISAKMP crypto):

    Client:

    vpnclient Server 10.x.x.x

    extension-mode network mode vpnclient

    EzVPN vpngroup vpnclient password *.

    vpnclient username user1 password *.

    vpnclient enable

    Crypto ipsec df - bit clear-df outdoors

    Server:

    internal EzVPN group strategy

    Group Policy attributes EzVPN

    allow to NEM

    allow password-storage

    tunnel-group EzVPN type ipsec-ra

    General characteristics of tunnel-group EzVPN

    Group Policy - by default-EzVPN

    IPSec-attributes tunnel-group EzVPN

    pre-shared key *.

    user user1 password *.

    I hope you can help

    Best regards

    Jarle

    Unfortunately, it is not supported on the platform of the SAA. With EasyVPN on the SAA, only the connected networks can be advertised. To accomplish what you want to do, you need to configure a static IPSec tunnel and announce local networks via ACL interesting traffic. You can also use an IOS device that does not have the capabilities of "multiple subnet" with EasyVPN.

    http://www.Cisco.com/en/us/docs/iOS/sec_secure_connectivity/configuration/guide/sec_easy_vpn_rem.html#wp1098057

  • ASA 5510 with AIP SSM-10

    I'm new to network administration and our company has an ASA 5510 with and map AIP SSM-10. On the interface ASA when I try to load Intrusion detection, he said the following:

    "For IPS 5.1 (1) S205.0, use the link below to access the IPS Device Manager." (If the SSM management IP address or the port is translated, replace them accordingly in the below URL). IPS 6.0.1 or above will be fully interated ASDM. »

    Unfortunately, no URL is displayed below this message and there is no documentation in the company that owns this configuration. Is there a way to reset the AIP without resetting the ASA? How can I find the IP address to be able to configure it?

    The ASA CLI, you will be able to check the IP address of the AIP module:

    view the details of the module

    It will show you the ip address of mgmt of the module, and you can https to the IP address of your PC.

  • Can you import a Camtasia (MP4) video released and change with captions in Captivate?

    Can you import a Camtasia (MP4) video released and change with captions in Captivate?

    You can import video as any another video, but you will not be able to change the video itself. If you want to do this, create a video demo and use the demo in Captivate video editor, which allows you to add and synchronize animations and static objects.

  • I want to create a dynamic field which changes with a pull down menu in one of our forms.

    Hi guys,.

    First post so forgive me for breaks of OCD.

    Would anyone be able to help me, I want to be able to modify the send e-mail button so that when you click on submit will invest in a custom subject line, but this must change with a menu drop-down I have the form as well.

    If it is could is it possible you let me know?

    Thanks again

    p.s. If I don't clear my request made me know

    You should have mentioned that earlier... LCD forms are very different compared to PDF Forms.

    You should ask your question here: LiveCycle Designer

  • I have a license of cs6 ps for windows but I change with mac, can I disable win and activate for mac?

    I have a license of cs6 ps for windows but I change with mac, can I disable win and activate for mac?

    Please check: a product for another language or version of trading platform

  • Creating a button that changes with images in a slide show in Adobe Muse?

    You are able to create a new button inside or outside of a slideshow that changes with the images?  I want to have the images change and contain a title and a link to the project that they are linked to.  Whenever the image changes, so automatically or someone clicks the "Next/previous" buttons, the button link and title will change with it.

    You can use the part of the legend of slideshows. Since the text in a changes of legend as well as the image in the slideshow, you can add your own text to images.

  • Is it possible to make a reflection of the image that will change with the image? [was: reflection]

    Is it possible to make a reflection of the image that will change with the image?

    I believe that a dynamic object will solve your problem.

    Place your original image to a new file as a smart object and do the same for reflection (made by processing, reducing the opacity and introduce a slight blur horizontal) on its own layer, then:

    by double clicking on the smart object in the layers panel and return to the original image, any change in the original and save, automatically update the vertical image and its reflection.

  • My client wants ot edit photos and text on its Web site. the site will not be hosted by BusinessCatalyst. Is it possible, and it is possible for me to synchronize the changes with my data?

    My client wants ot edit photos and text on its Web site. the site will not be hosted by BusinessCatalyst. Is it possible, and it is possible for me to synchronize the changes with my data?

    Hello

    Update June 2014 to Muse allows In-Browser editing for Muse sites hosted with third-party providers (not Adobe).

    See https://helpx.adobe.com/muse/using/whats-new.html#In-browser%20Editing%20enhancements for more details.

    Abhishek

  • stop when the element changes with the article.

    I have code like this


    <? [for-each@section:G_1[CODE='D']? >
    <? for-each: G_2? >
    <? IND? > <? STYLE? > <? FIN? > <? DR.? >
    <? end for each? >
    <? end for each? >

    every thing works fine I get new page that I was clear condition by <? [for-each@section:G_1[CODE='D']? >

    but inside the inner loop <?-foreach: G_2? >

    <? STYLE? > change with this article, I need the page break again as with in a section (I have section break on the outer loop) I could receive 3-4 styles, information on the same page so needs to break again when each style change with this article.

    I'm try below logic does not not as expected.

    <? If: STYLE [(.=preceding::STYLE)]? > <? split-of-page-break:? > <? end if? >

    and

    <? If: prior - sibling:G_2 / STYLE! = STYLE or position () = 1? > <? split-of-page-break:? > <? end if? >

    can anyone help me what is the mistake that I did.

    check the Inbox sent changed model.

  • Background images that change with scrolling, just how do you?

    These fabulous sites, were presented on the Muse Adobe Site of the day

    http://www.StreetReach.org/

    http://www.lauranet.nl/

    Brilliant sites. What they have in common is a background image (of all kinds) which changes with scroll, I can't get my brain around how's done it?

    Can someone point me in the right direction?

    Thank you

    Start with some of them:

    http://TV.Adobe.com/watch/Muse-feature-tour/Adobe-Muse-Parallax-scrolling-may-2013/

    www.YouTube.com/watch?v=5OOLEztI-so

    www.YouTube.com/watch?v=8m2Lg241e3A

    www.YouTube.com/watch?v=gZI_K1TXqOM

    I got these (and MANY others) by Google, "scrolling Parallax of the Muse.

    Good luck.

  • Title change with the selection of mode selector

    Hello Experts,
    I have a report that is divided into three different reports and I use a selector to display for the three reports, the title needs to change with the selection of the report, and I gave the name of view as selector select the report. I was wondering if there is a way to do it. I tired adding @{select report} in the title, but it does not work. Please notify.

    Thank you
    RC

    user1146711 wrote:
    I have this setup already in place and I want the title to change with the selection in the view.

    Why it is not working? The view selector simply selects the name of the reports. When selected, the composed page should show the title of the actual report, which will be different for each view because they are exemplary.

    I'm not at work so I can't test this, but if you have successfully copied the title of the view and any copies, when you change a all the changes; then maybe the works of title as the Table view. If this is true, use the display of the title, but rather to use the view of the narrative and follow my steps above. See if it works.

    Edited by: David_T December 29, 2011 07:41

Maybe you are looking for