« Cisco ASA...In VMWare?!? | Main | RFC 2795: Infinite Monkey Protocol Suite (IMPS) »

May 21, 2009

Base Config: ASA WebVPN

This is becoming a common configuration for me. Here's a base template I use:

ip local pool WebVPNPool 192.168.251.10-192.168.251.100 mask 255.255.255.0

webvpn
enable outside
svc image disk0:/anyconnect-win-2.3.0254-k9.pkg 1
svc image disk0:/anyconnect-macosx-i386-2.3.0254-k9.pkg 2
svc enable
tunnel-group-list enable

group-policy WebVPNPolicy internal
group-policy WebVPNPolicy attributes
dns-server value X.X.X.X
vpn-tunnel-protocol svc
group-lock value WebVPNAccessProfile
split-tunnel-policy tunnelspecified
split-tunnel-network-list value Split_Tunnel_List
default-domain value business.local
address-pools value WebVPNPool
webvpn
svc ask none default svc
hidden-shares none
file-entry disable
file-browsing disable
url-entry disable

tunnel-group WebVPNAccessProfile type remote-access
tunnel-group WebVPNAccessProfile general-attributes
default-group-policy WebVPNPolicy
tunnel-group WebVPNAccessProfile webvpn-attributes
group-alias WebVPN enable

Posted by JC at May 21, 2009 10:49 AM

Comments

could i use this config in the asa for vmware you just posted about?

Posted by: craig s at May 22, 2009 6:14 AM

Hi, JM i was expecting the same from you, as i am configuring anyconnect vpn, finally i got success in configuring it, after configuring only i found your template, but here i feel you havent configured the ACL for split tunnel.

Thanks and Regards

Praveen

Posted by: praveen at May 30, 2009 12:39 AM

Great post! i was look for this configurations.

Posted by: Freetechexams.com at June 2, 2009 1:07 PM

I have been looking for the same sinxe long. Thanks

Posted by: shivlu jain at June 8, 2009 8:34 AM

Hello Jeremy,

Indeed it is a good idea to keep templates for frequently needed configurations. This is what I do all the time. No need to reinvend the wheel everytime you need to configure something.

The template you have is for the anyconnect VPN client actually and not for the clientless ssl VPN...please correct me if I'm wrong.

I like your blog and visit it often. Good work.

Thanks

Posted by: ciscoasa at June 26, 2009 4:34 AM

Hi JC..
Hey JC you post here such a fantastic configuration, actually i am in searching of this type of config from last 5 days & 2day atlast i get it from here so thank you so much JC...

Posted by: digital camera cases at September 7, 2009 4:59 AM

Hi JC..
Hey JC you post here such a fantastic configuration, actually i am in searching of this type of config from last 5 days & 2day atlast i get it from here so thank you so much JC...

Posted by: digital camera cases at September 7, 2009 5:00 AM

I am eating a Devil Dog with a glass of milk. Yum! Oh, and thanks for the config, very nice.

Posted by: DevilDogAndMilk at September 16, 2009 5:57 PM

Hello JC,

I am such you get so much thank you's i still would love to add mine, you are doing a very wonderful job inspiring people, please dont stop. I used the Asa template for site-to-site VPN and i get this output anytime i show crypto isakmp sa ciscoasa(config)# sh crypto isakmp sa

Active SA: 1
Rekey SA: 0 (A tunnel will report 1 Active and 1 Rekey SA during rekey)
Total IKE SA: 1

1 IKE Peer: 77.220.13.3
Type : user Role : initiator
Rekey : no State : MM_WAIT_MSG2
ciscoasa(config)#

I can guess that MM_WAIT_MSG2 refers to the second step in the main mode of IKE Phase 1, only i dont know what to do anymore to troubleshoot this problem. Can you please HELP!!!

Posted by: Linda Azah at October 9, 2009 3:16 AM

Dear Author www.ciscoblog.com !
I apologise, but, in my opinion, you commit an error. I can defend the position. Write to me in PM, we will discuss.

Posted by: hodataibg at December 3, 2009 9:53 PM

I shoot all kinds of stuff with all kinds of cameras. I am a working photographer who shoots for advertising and corporate client as well as to make images for my own books about photography. Over the last two years I've been using small cameras like the Canon G10 and the SX10 for more and more of my work. In the studio, shooting set up shots or small products these cameras shine by dint of their easy to use Live View and increased depth of field. When I bought the SX 10 it was for the long range of the zoom lens which meant I could shoot anything from a construction site to tight shots of the cabins at the top of the construction cranes. I've done some portraits with studio lights and an SX10 and they were also very usable. I wish the SX 10 and SX 20 had raw file capability but they don't. That just means I have to be a bit more careful about WB and exposure. I've used the SX10 at outdoor swim meets and found that the lens performs better than expected right out to the end.So, why the SX 20? Recently I've been asked to do more and more little video snippets for clients and for my publisher and while I like the results from the SX10 I wanted real HD video for the times that a medical practice has asked for video clips for both their website AND for power point and other uses. I wanted the extra detail for the times that they use the clips in projected presentations. The price point works.I've spent a couple days testing the SX 10 and the results are very, very good. The front mounted microphones are of very high quality and the sound for most applications is very acceptable. Would I like a mike input? You bet! Does that sour the deal? Not in the least.The image quality of the stills is just as good as the SX 10 at low ISO's and about 1/2 a stop better at 200 and 400. I'll chalk that up to the new digic processor.All in all the build quality and the easy operation make the camera a winner for me. These days clients are more interested in using images and video in a wide range of multimedia and the SX 20 is a great tool for anything that's headed to the web. I still own traditional DLSR cameras and use them but left to my own devices I find the smaller sensor cameras to be highly competent and very usable.With an SX20 and a G10 I feel like I can handle just about anything except shots that call for narrow depth of field. Traditional photographers may not want to hear that video is becoming a required skill but that won't make it go away. This camera is a cost effective way to get your feet wet, find your way around and get your feet wet. I like it.

Posted by: Kathyrn Devol at December 21, 2009 5:44 PM

I want to quote your post in my blog. It can?
And you et an account on Twitter?

Posted by: beentech at December 25, 2009 5:05 AM

Hi-ya, I bumped into this site by on accident when I was searching on Google then I popped in to your web site. I must say your website is really cool I just love the theme! At this moment I don’t have the time at the moment to fully read your sitebut I have bookmarked it. I will be back in a day or two. Thanks for a great site.

Posted by: Adam at December 25, 2009 1:29 PM

Hi buddy, your blog's design is simple and clean and i like it. Your blog posts are superb. Please keep them coming. Greets!!!

Posted by: Dan Beandoin at January 2, 2010 4:19 AM

I use hidden camera to look what my neighbours are doing in the backyard. There are no words for me to describe how they have no shame. Worse, they come on Sunday to prayer as if nothing has happened. Oh my.

Posted by: hidden cameras in india at January 20, 2010 4:17 AM

Hey - nice blog, just looking around some blogs, seems a pretty nice platform you are using. I'm currently using Wordpress for a few of my sites but looking to change one of them over to a platform similar to yours as a trial run. Anything in particular y

Posted by: Carie Feyereisen at January 25, 2010 5:07 PM

Post a comment




Remember Me?

(you may use HTML tags for style)