Cisco IOS SSL VPN does not-Internet Explorer

Hi all

I seem to have a strange issue of SSL VPN.  I have a Cisco 877 router with c870-advsecurityk9 - mz.124 - 24.T4.bin and I can't get the SSL VPN (VPN Web) works with Internet Explorer (tried IE8 on XP and IE9 on Windows 7).  When I go to https://x.x.x.x, I 'Internet Explorer cannot Display The Webpage ".  It kind of works in Chrome (I can get the Web page and connect, but I can't start the thin client, when I click on Start, nothing happens).  It seems to only work with Firefox.  It seems quite similar to this topic with the ASAs - http://www.infoworld.com/d/applications/cisco-asa-users-cant-use-ssl-vpns-ie-8-901

Here is an excerpt of the configuration:

------------

!

username password vpntest XXXXX

AAA authentication login default local
!
!
!
Crypto pki trustpoint TP-self-signed-1873082433
enrollment selfsigned
name of the object cn = IOS - Self - signed - certificate - 1873082433
revocation checking no
rsakeypair TP-self-signed-1873082433
!
!
TP-self-signed-1873082433 crypto pki certificate chain
certificate self-signed 01
-omis-
quit smoking
!
WebVPN gateway SSLVPN
router host name
address IP X.X.X.X port 443
SSL encryption aes-sha1
SSL trustpoint TP-self-signed-1873082433
development
!
WebVPN context SSLVPN
title "Blah Blah"
SSL authentication check all
!
Login-message "enter the magic words...". »
!
port-forward "PortForwardList."
description of remote-port 3389 to remote-server '10.0.1.3' local-port 33389 "RDP".
!
SSL-policy strategy group
port-forward "PortForwardList" auto-Télécharger
Group Policy - by default-SSL-policy
Gateway SSLVPN
users of max - 3
development

------------

I tried:

Activation of SSL 2.0 in Internet Explorer

* Adding the site to websites of trusted in Internet Explorer

* Add to the list of sites allowed to use Cookies

At a loss to understand this.  Has anyone encountered this before?  Whereas Cisco's Web site shows an example usage of IE (http://www.cisco.com/en/US/products/ps6496/products_configuration_example09186a008072aa61.shtml), surely, it should work in IE you would think?

Thank you

Hello

I would check out where exactly it is a failure, either the connection ssl itself or something after that. The best way to do that is executed a wireshark capture when you try to access the page using IE. You can compare this with that with Mozilla too just to confirm that ssl works fine.

Also you can try with different SSL encryption algorithms as a difference between the browsers is the encryption they use. 3DES is expected to be a good option to try.

Tags: Cisco Security

Similar Questions

  • Cisco IOS SSL VPN on mobile

    Hello

    I want to know can I use the Cisco IOS SSL VPN on the use of mobile client Anyconnect. If yes what is the prerequisite, is there any kind of additional license required.

    Thank you

    In the following article:

    http://www.Cisco.com/c/en/us/support/docs/security/AnyConnect-VPN-client...

    Q. is possible to connect the iPad, iPod or iPhone AnyConnect VPN Client to a Cisco IOS router?

    A. No. it is not possible to connect the iPad, iPod or iPhone AnyConnect VPN Client to a Cisco IOS router. AnyConnect on iPad/iPhone can connect only to an ASA that is running version 3,0000.1 or a later version. Cisco IOS is not supported by the AnyConnect VPN Client for Apple iOS. For more information, refer to the section security devices and software support to the Release Notes for Cisco AnyConnect Secure Mobility Client 2.4, Apple iOS 4.2 and 4.3.

    --

    Please do not forget to rate and choose a good answer

  • SSL VPN problems with Internet Explorer

    Well, first of all, you need 64-bit to run Internet Explorer web based VPN devices in the SA500 series (we use SA540). After that we thought that out, we cannot always past SSL VPN Client install on client computers. It keeps reloading the Web page or simply nothing at all. Any ideas?

    In addition, that the CA guys do you use SSL VPN? GoDaddy certificates are not compatible, as I just discovered the hard way.

    Hi Qasim,

    The question seems to be more localized with windows blocks everything. I actually spent much time working on this yesterday to finally make it work with a 64 bit vista and a window 7 64 bit machines.

    The few details that I did have some success;

    Tools-> Internet Options-> security-> trust Sites

    • Move down
    • Disable protected mode
    • Click sites, and then add the SSL VPN page to become a member of trust
    • When adding the trusted site, uncheck 'require a server secure for all sites in this zone.

    Tools-> Internet Options-> Advanced-> Security section

    • Select "Allow downloads to run or install even if the signature is not valid"

    In addition, you must download Microsoft Visual C++ Distribution 2010 and ensure that you are running the latest version of Java.

    These are the things I had to do to allow Windows to allow me to connect. I hope it has some help for you.

    -Tom

  • After the upgrade yesterday from Vista to Windows 7, now my Cisco VPN does not work and I get an error message titled: grounds 440 driver fault. Any ideas to fix this?

    After the upgrade yesterday from Vista to Windows 7, now my Cisco VPN does not work and I get an error message titled: grounds 440 driver fault.  Any ideas to fix this?

    This was the solution!  The works of vpn as $ 1 million now.  I followed the instructions above to enter the uninstall program and selecting the repair option.  I rebooted the machine, then used the troubleshooting on vpn software compatibility option.  Selected Windows windows xp (service pack 2) as the correct software and cisco vpn client started right up.

    Thanks, Nick!

    Rick

  • When I click on an e-mail link in Firefox, I get a message in the left corner of my screen that says "mail to: email address. Outlook will not open upward as it does in Internet Explorer. I set Outlook as my default email in Windows 7.

    When I click on an e-mail link in Firefox, I get a message in the left corner of my screen that says "mail to: email address. Outlook opens automatically as it does in Internet Explorer. I did my default email in Outlook in Windows 7.

    This has happened

    Each time Firefox opened

    Is when I upgraded to Windows 7.

    See this:
    http://support.Mozilla.com/en-us/KB/changing+the+e-mail+program+used+by+...

  • Portion of IOS SSL VPN PKI

    I'm trying to configure an SSL VPN on a 2811. I believe I have the part SSL VPN, but I can't tell because I get stuck on the certificate server, ca trustpoint configuration and the identity of trustpoint.

    Does anyone know of a guide that walks you through the cert CA, Cert ca trustpoint and identitiy trustpoint iOS SSL VPN server? For some reason, I'm having a problem to enter the configuration of the certificate.

    Thanks for the help

    Triton.

    Follow these steps:

    > Add the host SSLVPN.securemeinc.com file to the user (client)

    > When you open the SSL VPN page on the user's browser. Right click... Select "Properties..." 'See Ceriticate' and then save/open the certificate on the computer companies.

    > Make sure the time is synchronized between the VPN server and client

    Concerning

    Farrukh

  • Cisco AnyConnect SSL VPN

    Hi guys,.

    I am currently ut setting for the first time on a Cisco ASA 5505 Cisco AnyConnect SSL VPN.

    I enclose my topology.

    I ran the wizard of the ASDM on the ASA2 I want to use for my VPN connections.

    Everything works fine except that I can't access any internal computer servers on my network.

    I do a specific configuration because my servers have a different default gateway of the ASA that I use for my VPN?

    I have since the ASA2 the 192.168.10.0 network.

    my remote ip address of the pool is 10.0.0.1-10.0.0.10/24

    config (I've included what, in my view, is necessary, please let me know if you need to see more):

    ASA 2.0000 Version 8

    Sysopt connection permit VPN

    tunnel of splitting allowed access list standard 192.168.10.0 255.255.255.0

    network of the NETWORK_OBJ_10.0.0.0 object

    10.0.0.0 subnet 255.255.255.0

    NAT (inside, outside) static source any any static destination NETWORK_OBJ_10.0.0.0 NETWORK_OBJ_10.0.0.0 non-proxy-arp-search to itinerary

    internal GroupPolicy_vpn group strategy

    attributes of Group Policy GroupPolicy_vpn

    value of 192.168.10.20 WINS server

    value of server DNS 192.168.10.15

    client ssl-VPN-tunnel-Protocol ikev2

    Split-tunnel-policy tunnelspecified

    Split-tunnel-network-list value split tunnel

    domain.local value by default-field

    WebVPN

    User PROFILE of value type profiles AnyConnect

    type tunnel-group tunnel_vpn remote access

    tunnel-group tunnel_vpn General-attributes

    address ra_vpn_pool pool

    Group Policy - by default-GroupPolicy_vpn

    tunnel-group tunnel_vpn webvpn-attributes

    activation of the Group tunnel_vpn alias

    !

    Thanks in advance!

    Hello

    The unit behind your ASAs on the internal LAN should really be a router switch or L3 and not a basic L2 switch.

    You now have an asymmetric routing on your network, and this is the reason why the connection of the VPN device will not work.

    The problem comes from the fact that internal devices use the ASA1 for the default gateway. When trying to connect to the VPN Client, the following happens

    • Client VPN armed sends TCP SYN that happens by the VPN with the ASA2
    • ASA2 passes the TCP SYN to the server
    • Server responds with TCP SYN ACK for the VPN Client and sends this information to the ASA1 as the destination host is in another network (vpn pool)
    • ASA1 sees the TCP SYN ACK, but never saw the TCP SYN so he abandoned the connection.

    To work around the problem, you need to essentially configure TCP State Bypass on the ASA1 although I wouldn't really say that, but rather to change the configuration of the network so that traffic makes this way to start.

    An option, even if not the best, would be to set the LAN of the ASA2 to ASA1 on some physical ports and set up a new network connection between them (not the same 192.168.10.x/yy). In this way the ASA1 would see the entire conversation between servers and VPN Clients and there are no problems with the flow of traffic.

    But as I said it probably still isn't the best solution, but in my opinion better than having recourse to special configurations ASA1.

    There could be a 'special' configuration on the ASA2 that you could use to make the Client VPN connections operate in their current configuration, without changing anything in the physical topology.

    You can change the NAT for VPN Clients configuration so that the VPN ALL users would actually PATed to 192.168.10.4 IP address when they connect to your internal network. Given that the server would see the connection coming from the same network segment, they would know to forward traffic back with the ASA2 rather than ASA1 like her today.

    If this is not an ideal solution.

    No source (indoor, outdoor) nat static any any static destination NETWORK_OBJ_10.0.0.0 NETWORK_OBJ_10.0.0.0 non-proxy-arp-search to itinerary

    the object of the LAN network

    192.168.10.0 subnet 255.255.255.0

    NAT (exterior, Interior) 1 dynamic source NETWORK_OBJ_10.0.0.0 destination static LAN LAN interface

    Hope this helps

    -Jouni

  • Why do the topics become Chinese when I access my email via Firefox but not Internet Explorer?

    Why do the topics become Chinese when I access my email via Firefox but not Internet Explorer?

    Hello, this is a display caused the extension Advisor default McAfee site - please try to disable or remove that in case you have now until there's a mcafee update that may resolve the problem.

    http://service.McAfee.com/faqdocument.aspx?ID=TS100162
    https://community.McAfee.com/thread/76071

  • My new iPhone iOS 9.1 does not appear on my iMac screen 10.6.8.  I don't want to upgrade to El Capitan.  Is there a solution?

    My new iPhone iOS 9.1 does not appear on my iMac screen 10.6.8.  I don't want to Snow Leopard upgrade to El Capitan.  Any suggestions?

    CarbonCopyClone on an external drive in an external enclosure.  Upgrade than SL ElCapitan leaving the intact internal SL.  Start externally using the option key pressed at the start, do what you need with the iPhone, then stop and do what ever you need to again with SL disc.

    Cludgy, but it works.  I keep my SL still functional because there iDVD, but use updated OSXs for other purposes.

  • Hello! I restored my iPhone 5 because IOS 9.2 does not work well, and now the IPhone does not recognize the SIM CARD ☹️ please someone help me! What can I do?

    Hello!! Recently, I have restored my iPhone 5 because IOS 9.2 does not work well. But now my iPhone does not recognize the SIM CARD.

    I Don' t know what to do, help me please

    You get an error message?

    What did he say?

  • 6 iPhone with iOS 9.2 does not and freezing when I try to turn on + WiFi freezes

    6 iPhone with iOS 9.2 does not and freezing when I try to turn on + WiFi freezes cannot allow him. (When I get to start the Iphone by pluging it to Itunes)

    I've done a new install and reset the network settings.

    But always the same questions

    Thanks a lot for your help

    I have the same questions and more from Friday December 11 when I've upgraded to iOS 9.2.

    Device: iPhone 5 s

    Problems:

    -Screen freezes randomly reboot * required (sometimes restart by the camera itself)

    -Sometimes device reacts very slowly on the command (or even then restarts)

    -For the most part within the first hour when used, sometimes immediately (after restart)

    -Cannot slide or apps to react when I touch

    -AssitiveTouch on, keep available however to move and opening, but no order accepted when the screen is in gel

    Resolution of problems so far:

    -Reset all settings (no result)

    -Backup on iTunes (11 dec)

    -Erase content and settings and restore the backup to iCloud (10 Dec *) (no result)

    -Erase content and settings and restore the backup of iTunes (11 dec) (no result)

    -Tried with the new iPhone camera 6 and restore backup icloud (unsuccessfully; restore hangs at "1 minute remaining")

    -Tried with the new iPhone camera 6 and restore backup of iTunes (no result: same freezing questions reappear)

    Conclusion date: is not a hardware problem (device), but one software: combination of the configuration (such as backup) and the new iOS 9.2.

    By the way: I guess that not possible to restore 9.1 on the device.

    The new iPhone 6 initially contained iOS 9.1, but then did not 'see' backups, because they were made from a 9.2 iOS device.

    So I had to first install the iPhone 6 as a new iPhone, upgrade to iOS 9.2 and then I was able to reset and restore the backup (with no good result, as described above).

    *) restarts: hold Home-button on/off-button simultaneously for 10 seconds

    backup *) in the form of clouds 10 Dec worked without problem on iOS 9.1.

    I will continue to investigate on removing the apps installed a year or two, see if that generates the result.

  • Accidentally deleted Windows Explorer (not Internet Explorer)

    Looking for a way to download or restore of Windows Explorer (not Internet Explorer).

    First of all, in response to the first question below on the race "explore c: /" when I did that, the local directory c: came. Should I do something more about it? I still hope to restore Windows Explorer.

    What you have proven this response is that Windows Explorer is still there and still doesn't work as it should for any aspect you gave (although again, just the startup and power use Windows, see your desktop, etc turns works in Windows Explorer.)  What I'm saying is that there is nothing to 'restore' in have you seen/shown so far.  You have a Windows Explorer.

    If there is something specific, you can say is missing, maybe we can help.

  • Update iOS yesterday again does not help Revel update.

    Yesterdays iOS update still does not help the revel update. Hoped Apple update would fix the path of Revel, but not so much.

    Please see the post below updates on the issue of the revel facilities:

    Problem installing Adobe Revel 2.3.2

  • site loads great in Firefox but not internet explorer, why?

    Hello

    I built my first good website with Dreamweaver CS4.  I learned that I'm going and to get to a finished site, so I was very happy!

    Anyway, I previewed and loaded and played back on Firefox and Safari and the site was well in both.   But when my husband read using Internet Explorer, it says that the graphic logo was not clear.

    Is anyone know why and what I need to do to make it compatible in all browsers?

    Please keep in mind, that I have not Internet Explorer as am only using a MAC so cannot listen to samples here!  (why is it now?  allows you to be able to get for a Mac...?)

    Thanking you in advance

    Mich

    Mich,

    It is always better to optimize the images in your graphics editor for the exact dimensions required in the page. If you use HTML to resize the images, you will get distorted anything.

    While you check the site, you may be interested to know that there is essentially no content on your site for the search engines, the translators, the screen readers and the other assistive devices to the web to grab.

    To view your site the way that search engines, use this tool http://www.seo-browser.com/

    You might want to rethink the practice of using pictures instead of actual HTML content.

    Just my 3 cents.

    Nancy O.
    ALT-Web Design & Publishing
    Web | Graphics | Print | Media specialists
    www.Alt-Web.com/
    www.Twitter.com/ALTWEB
    www.Alt-Web.blogspot.com

  • Cisco Anyconnect VPN does not work in windows 7 64 bit

    Hello
    I found that the cisco anyconnect (version 3, any series) does not work in windows 7 (64-bit).
    The vpn is connected, but there is not any internet access.

    I tried to solve the problems of:

    -Disabling the firewall.

    -disable the anti-virus etc.

    But while I tried using with 32 bit, it works very well.

    Also, I found that there is not a specific version of anyconnect vpn for only 64-bit.

    Do any body have the idea how to solve this problem, either it's a bug of cisco vpn itself?

    Certainly, you just need to install a later version of AnyConnect.  You need a Cisco, for example a SmartNet maintenance contract, to download the new versions.

Maybe you are looking for

  • How to preserve the multi-level iPhoto in Photos folder directory

    If you upgrade OS to Yosemite or El Capitan, how to preserve my folder customized Photos iPhoto multi-level directory? My iPhoto library is 105 GB and contains 41 000 photos, all carefully arranged in a directory of custom and subsidiary subjects. iP

  • Keep its email alert

    My new 6 iPhone gives me beep whenever I receive by e-mail even if the preference of sounds in Control Panel is set to 'None' for email. Anyone know of a way to make it work correctly? Thank you!

  • iPad, updated to iOS 9.2 cannot access to App Store

    Hello after update to iOS 9.2 when I open App Store I get white screen How can I solve this problem? Best regards Caesar

  • Cannot re configure my E2000

    Hello I recently used a registry cleaner that weaken important files. It is my duty to do an installation customized Win 7 Home Premium (I forbade me to do another update).  Custom installation removed from my hard drive and the software E2000 work p

  • After Effects, help using Shatter for league of legends

    I want to make a video game for YouTube. I have experience of moviemaker but I want cool effects in these videos. I play League of legends and my goal is to make the health bars to burst as I melt people in team battles. I want their health to "break