Cisco Firewall :: ASA 5510 - FTPS Explicit Client Fails At Init TLS Stage

Feb 11, 2013

I have a problem when trying to access from a workstation on the internal network to an external FTP server using Explicit FTPS. After the server requires the client TLS Authentication the client inits TLS but the connection is closed by timeout.
 
I have disabled the FTP inspection on the firewall and I have opened some high ports from the Internet to the test workstation (ACL and NAT rules), but without results.
 
If I try to connect from a workstation to the FTP server using a direct Internet connection I can access the FTP server without problems, so I think the problem is in the ASA.

View 6 Replies


ADVERTISEMENT

Cisco Firewall :: Get ASA 8.2(1) Working With FTPS On IIS 7.5?

May 16, 2012

I found the link that effectively said PIX/ASA 7.x does not support FTP with TLS/SSL (FTP/FTPS). I can't find anything which states whether it works on a later release? We have 8.2(1) and we are struggling to implement it. The FTP/FTPS server is in the DMZ and is hosted by Windows 2008 IIS 7.5. How to get this solution implemented, as the contractor from our local Cisco vendor spent 3 hours on it and couldn't get it working this morning.

View 1 Replies View Related

Cisco Firewall :: Unable To Run FTPS (FTP Over SSL) Across ASA 5540?

Mar 19, 2012

there was remote FTP - users behind ASA5540 can connect to it.
 
Now, with this ftp there is SSL/TLS encryption added and users behind this ASA can't connect to this FTPS.
 
It this possible for users behind ASA to connect to FTPSs?

View 2 Replies View Related

Cisco Firewall :: ASA 5510 Fails To Boot

Apr 10, 2013

I have a Cisco ASA 5510 with a strange issue. When I power it ON, the following is the status of the front panel LED:
 
Power is OFF
Status is Amber
Active is Amber
VPN is Green
Flash is OFF
 
Also nothing comes up on the console. I suspected a Power supply issue and replaced it, but still it doesn't seem to work.I cant open up a TAC as I do not have a Smart Net contract.

View 2 Replies View Related

Cisco Firewall :: Allowing FTPS Access In ASA5510

Apr 13, 2012

We had an ASA 5510 as a firewall in our environment, and there is a requirement to access an ftps server from our location. Currently from the server location they configured everything by allowing our public ip to their server and gave the following details to access ftp.Please suggest which traffic needs to be allowed in our ASA to access the ftp server address as mentioned above. From my initial analysis, it's found that 989 port is also enabled for the access, but that was not mentioned by them.

View 1 Replies View Related

Cisco Firewall :: Stuck At Initial Stage PIX 515e

Oct 30, 2011

I have a new pix 515e for Home practice.
 
1. I couldn't telnet the switch after configuring. should i have to use cross cable or not to connect PC-PIX? (as new switches and routers run through straight cable). more importantly i couldn't even ping the inside ip which is telnet and ssh enabled.

2.  Receiving the following after executing each and every command on global mode.

-Configuration Replication is NOT performed From standby Unit to Active Unit
-Configurations are no longer synchronized.

View 9 Replies View Related

Cisco VPN :: Microsoft VPN Client To ASA 5510 Firewall?

Aug 5, 2012

We just set up the AnyConnect SSL vpn on our ASA.  I am able to establish a connection fine using the Cisco AnyConnect client.  I would like to use the native Windows VPN client though if possible. What configuration changes on either the firewall or the client I would need to make for this to happen?

View 1 Replies View Related

Cisco Firewall :: ASA 5510 8.4 / VPN Traffic For Specific Client?

Mar 16, 2013

I have ASA 5510 8.4 Firewall where more than 20 Site to Site VPN Clients are configured on it. how to see the traffic for one Specific Site to Site VPN.Actually this site to site vpn is always keep dropping for every minute. I'm sure its a problem at the other end.The remaining 19 VPNS are UP and working without any problem. How to see the traffic for specific vlan.More over we dont have any syslog server in our network. Is their any chance we can check the traffic on the firewall?

View 6 Replies View Related

Cisco Firewall :: 5510 Client Need Small Server With VPN

Feb 26, 2011

We have cisco 5510 and on our floor we have client who we provide internet connection.  One of our client has small server and 2 computers and they want setup vpn connection so they can access their server from outside.  We have only one static public ip for firewall and exchange.  We don't want provide another public static ip to the our client so they can setup the vpn.  Is their any other way to setup vpn for them? can they the use our 1 public ip for vpn?

View 11 Replies View Related

Cisco Firewall :: 5510 - AnyConnect Client Profiles Not Replicating To Standby ASA

Jan 18, 2012

We have 2 ASA 5510's running in a Active/Standby configuration.  It appears that most of the changes we make on the active unit are replicated to the standby unit.  However, there are 3 AnyConnect Client Profiles on the active unit and none of them show up on the standby, the standby has no AnyConnect Profiles.  We also have 1 OnConnect script on the active unit and it does not appear on the standby unit either.
 
I was under the assumption that all config items on the active unit would replicate to the standby.  Is this not correct?  Do I need to do something extra to get everything replicated?  Are there other items that do not replicate? 

View 3 Replies View Related

Cisco VPN :: 5510 / 5540 / 5550 / 5580 - Series Firewall L2L And Client VPN

Feb 17, 2011

I want to privatize the outside interfaces of my ASA firewalls however I need a public IP address bound to an Interface to support L2L and client VPN (using the Cisco client software). What I'd like to do is route to the firewall privatized outside interface and have a DMZ interface with a public IP address on it for VPN peering. Ideally this would allow me to build rules on the outside interface limiting communication to the DMZ interface to IPSEC only. Thus VPN tunnels would traverse the outside interface and terminate on the DMZ interface giving me granular control of the peers and protocols allowed to the each the DMZ interface.  

Platforms: ASA 5510, 5540, 5550, 5580 
Versions: 7.2(4)33, 8.2(2) 

View 1 Replies View Related

Cisco Firewall :: ASA 5510 - Anyconnect Client Can't Reach Inside Network

Jan 2, 2012

So, I've set up Anyconnect client access to an ASA-5510.
 
I've got a handful of interfaces, which contain hosts that should be accesible to anyconnect clients.  I'm unable to reach addresses on a specific network, due to what packet-tracer claims is an implicit deny, though I'm unsure where to apply an access-list in this case.
 
fw1# show nameif
Interface                Name                     Security
Ethernet0/0.205          SECURE                  90

[Code].....

View 7 Replies View Related

Cisco Firewall :: 5510 Security Plus To Terminate Client VPN Access For External Support Team

Aug 7, 2012

I have a customer that wants to purchase an ASA 5510 security plus to terminate client VPN access for an external support team. The customer claims to want URL content filtering/proxy which leads me to suggest a CSC SSM 20 plus module. But upon further conversation, he mentioned wanting IPS. In this case, the customer does not seem to know the difference between the URL content filter/proxy and the IPS and uses both terms interchangably.
 
1. What would you suggest in your expert opinion would be the best module to get for this customer? IPS or CSC
 
2. If I go with the CSC module, where can I find good documentation on how to configure it and get it up to date?
 
3. does the CSC module provide any web proxy functionality?

View 3 Replies View Related

Cisco Firewall :: 5510 Vpn Client Groups Configured / DHCP Server Stops Giving Network Service

Feb 20, 2013

I have a asa 5510 vpn client groups configured and connected to the internal network DHCP server stops giving network service dhcp and the network goes down.

View 6 Replies View Related

Cisco VPN :: 878 - Client Fails With ISAKMP Errors

Aug 18, 2012

cisco 878 configured to accept client vpn requests. From client prospective people get error 412 and they can't connect. Not sure what s wrong, following configuration and debug isakmp. Autentication is through a radius server.

View 3 Replies View Related

Cisco :: AP1200 - BBSM Fails To Locate Client

Apr 25, 2005

i have a bbsm server I'm bringing up on line. Trying to add the first site, i configured everything i think right, but the client gets a network error page, and the event log shows:
 
EventID:28
Source:BBSM_AtNotify
Description:
Failed to locate client ip:10.233.1.10 MAC: 00 00 00 00 00 db on any network device.
 
i did a debug on the AP1200 (12.3(4)JA) i am using and see that the bbsm is talking to the bbsm.  I just can't figure out what i am doing wrong.
 
[code]....

View 2 Replies View Related

Cisco VPN :: Client 5.0.07.0290 Version Fails To Add Route

Feb 1, 2013

I am having this problem trying to connect to my university network trough the vpn client from a pc running Windows 7 Ultimate 64-bit: the client connects but I have no Internet access. I first believed that the problem was related to the fact that I had ZoneAlarm Free Antivirus+Firewall installed, but I made several steps, including the complete removal of the ZoneAlarm product, and I still have the same problem.
 
Here's what I see in the log:
  
Cisco Systems VPN Client Version 5.0.07.0290
Copyright (C) 1998-2010 Cisco Systems, Inc. All Rights Reserved.
Client Type(s): Windows, WinNT
Running on: 6.1.7601 Service Pack 1

[code]....
 
Using the same client (32 bit version) in another pc of my lan which runs Windows XP and that had never ZoneAlarm installed on it, I have no problems.Also, using Shrew Soft Vpn Client 2.1.7 on the problematic pc I can connect to vpn without problems, so I am really stuck trying to understand what's wrong with Cisco Vpn Client.

View 6 Replies View Related

Cisco VPN :: AnyConnect 2.5.2006 Client Fails Installation On Windows 7 64

Dec 13, 2010

I have a Cisco AnyConnect 2.5.2006 failing installation on an upgrade from 2.4.1012. Win7 64-bit.RunOnce exists in the registry and I even added everyone/full perms to it to make sure it wasn't a perms issue. (it seems everyone recommends checking this key exists)I've cleaned the system and the registry multiple time for anything AnyConnect related. The installation 'appears' to fail on the installation of the 64-bit virtual adapter
 
Installation log is attached to this post.
 
[code]....

View 11 Replies View Related

Cisco Wireless :: 5508 - Client Authentication Fails For Wrong EAP-type

Jan 16, 2012

I have setup the WLC to authenticate to a MS Server2008 NPS for a WPA2/AES SSID. The connection is successful, but client authentication fails for wrong EAP-type. I believe this indicates a Windows7 client issue. What is the required client setup to satisfy the MS NPS?

View 8 Replies View Related

Cisco Firewall :: 5510 - Display User Message When User Connects Using AnyConnect Client?

Apr 20, 2009

We are using an ASA 5510 and remote access (SSL VPN) using the AnyConnect client.
 
Is it possible to display a user message when a user connects using the AnyConnect client, matching a specific dynamic access policy?  Can the message be displayed when the action is "Continue" rather than "Terminate"?  I can't seem to get this to work and wondered if there was a LUA function to do this.
 
We have a DAP which gives a restricted ACL when the user's anti-virus is out of date, and I wanted to notify the user to update their anti-virus and reconnect.

View 4 Replies View Related

Cisco Application :: APP 11501s Session Now INIT Not UP?

Oct 27, 2005

My app session was working fine and i managed to see it all up and working. now that i have tried to run script commit-redundancy etc i see the session as APP_SESSION_INIT instead of up. The log shows me on the standby box now that it sees the following :
 
FLOW-MGR 7 - DOS-SYN ATTACK 192.168.1.1 - 192.168.1.2:5001

View 5 Replies View Related

Cisco VPN :: Dell Latitude E6410 / VPN Client On Windows 7 Professional X64 / Connection Fails

Apr 18, 2011

we are using Cisco VPN client to access our corporate network.I have 5 new notebooks Dell Latitude E6410 OS Windows 7 Professional x64, with identical hardware configuration.I downloaded Cisco VPN Client 5.0.07.440 (64 bit) and installed it on all notebooks. It works fine on 3 notebooks, while on 2 notebooks the VPN connection fails with error:
 
Secure VPN collection terminated locally by the client.
Reason 403: Unable to contact the security gateway
 
We use a smartcard for VPN access (etoken from Aladdin)
 
Here an extract from Cisco log:
 
Cisco Systems VPN Client Version 5.0.07.0440Copyright (C) 1998-2010 Cisco Systems, Inc. All Rights Reserved.Client Type(s): Windows, WinNTRunning on: 6.1.7600...Sev=Info/6    CERT/0x63600026 Attempting to find a Certificate using Serial Hash....Sev=Info/6    CERT/0x63600027 Found a Certificate using Serial Hash....Sev=Info/6    CERT/0x63600026 Attempting to find a Certificate using Serial Hash....Sev=Info/6    CERT/0x63600027 Found a Certificate using Serial Hash....Sev=Info/6    CERT/0x63600026 Attempting to find a Certificate using Serial Hash....Sev=Info/6    CERT/0x63600027 Found a Certificate using Serial Hash....Sev=Info/4    CERT/0x63600015 Cert (cn=<omissis>,ou=Remote,ou=Users,ou=<omissis>,dc=it,dc=<omissis>,dc=local) verification succeeded....Sev=Info/4    CM/0x63100002 Begin connection process...Sev=Info/4    CM/0x63100004 Establish secure connection...Sev=Info/4   

[code]......
 
It seems the problem is in the certificate, but I verified and Cisco client says it's ok. It's also the only valid certificate in MMC->Certificates->Personal.Furthermore, also using other smartcard (etokens) of other users it doesn't work.

View 5 Replies View Related

Cisco :: 2048 - Self-Signed Certificate And Init 6 Process

Feb 16, 2012

I have a doubt about CiscoWorks. I need to generate the self-signed certificate with a key of 2048 bits to generate a CA with VeriSign. CiscoWorks do this automatically with a key of 1024 bits and I do not find a form to elect a a diferent key. Is it possible to generate a certificate with 2048 bits key?

Another problem is that I have CiscoWorks installed on Solaris. Many times at day the web application does not work and the only way to recuperate it is with the command "init 6" and I have to way 15 minutes until I can have access again. Why is produced this error? Who can I fit it?

View 1 Replies View Related

Linksys Wireless Router :: WRT310N V1 DHCP Client Fails To Renew Lease

Apr 28, 2013

I have a Linksys WRT310N v1 with firmware v1.0.10 build 002Jul 19, 2010 My router fails to renew it's DHCP lease from my cable provider, causing internet access to drop. I can still access my cable modem at 192.168.100.1, but I must do a "IP Address Release" then "IP Address Renew" to get back internet access. The router works fine otherwise.

View 6 Replies View Related

Cisco VPN :: 5510 - Connection Fails Using Full Tunnel?

Mar 31, 2012

We are using a 5510 and have issues trying to use VPN with full tunnel to connect from inside the firewall to a customer site. I don't seem to have a problem when using split tunnel profiles. How would you troubleshoot this?

View 12 Replies View Related

Cisco VPN :: Clientless SSL VPN Portal Customization Fails On 5510?

Aug 9, 2010

I am trying to customize a web VPN portal on my 5510 but I get errors whenever I try to add a customization object.  Running ADSM 6.1(5)51 on ASA 8.0(5).  The error I get when I try to apply a newly created customization object is:
 
[ERROR] export webvpn customization DfltCustomization disk0:/tmpAsdmImportFile2090698426  export webvpn customization DfltCustomization disk0:/tmpAsdmImportFile2090698426                            ^
% Invalid input detected at '^' marker.
[ERROR] import webvpn customization test disk0:/tmpAsdmImportFile2090698426    % copying 'disk0:/tmpAsdmImportFile2090698426' to a temporary ramfs file failed
[ERROR] delete /noconfirm disk0:/tmpAsdmImportFile2090698426    %Error deleting disk0:/tmpAsdmImportFile2090698426 (No such file or directory)
 
Tried revert webvpn all but I get error on that as well:
 
Result of the command: "revert webvpn all"
 
%ERROR: ifs_rm_dir_rec: unknown type of file `disk0:/csco_config/97/customization/86D3828A0A0EB0FFA3B55870AAA43E4F'

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ISE 3315 Stuck In INIT Entering Runlevel 3

Oct 1, 2012

my ISE 3315 is stuck in ISE 3315 stuck in INIT Entering runlevel: 3 when i connect a screen and keyboard i can only see this last message : ISE 3315 stuck in INIT Entering runlevel: 3 There is nothing after, i cannot login (no prompt) even after waiting 20 minutes with this message
 
I have no char return via serial cable depsite i was able to run initial setup from console (same cable, the DB9-DB9 provided, same serial config, same laptop)
 
Version ADE :  ADE-OS-2.0 (2.6.18-238.1.1.el5PAE)
Version ISE : 1.1.0.665

View 4 Replies View Related

Cisco VPN :: 8.21 / Packets Dropped At Encryption Stage?

Apr 27, 2013

I am truly struggling with the changes after 8.21. I am trying to get a VPN up between two sites. This is the B end, I am sure there are a bunch of problems in the other end too. Eg. the tunnel NAT does not have the right priority 1.when I establish the tunnel I get this:

3    Sep 01 2008    11:23:37  Tunnel Manager has failed to establish an L2L SA.  All configured IKE versions failed to establish the tunnel. Map Tag= outside_map.  Map Sequence Number = 1. 
# packet-tracer input inside tcp 10.2.32.11 80 10.1.1.10 80
 Phase: 1
Type: ACCESS-LIST
Subtype:

[code]....

View 1 Replies View Related

Cisco Switching/Routing :: Stuck At Initial Stage Pix 515e

Oct 30, 2011

Stuck at Initial stage CISCO pix 515e

View 2 Replies View Related

Cisco Security :: ASA 5510 - ASDM Fails To Load On Mac OSX 10.7 Running Java Version 1.6.0_33

Jun 24, 2012

I have an ASA 5510 running ASDM 6.4(9) and Cisco Adaptive Security Appliance Software Version 8.4(4)1.I am trying to configure for the first time and I am accessing the ASA via its Management Interface.I am successfully able to connect to the device and get to the Cisco ASDM 6.4(9) page.When I try to run the startup wizard, a couple of prompts displays up to the point where the java applet runs and aks me to enter my IP, username and password.As it is a new system, password and username is blank so I enter and I get a message saying "loading software from cache" which later changes to "software Update completed" and then nothing happens.I am running MacOSX 10.7 Lion, Java version 1.6.0_33.I did try and run this on a Windows system and i was able to load the interface.

View 2 Replies View Related

Daisy Chain 3 Wifi Routers - How To Extra 4 Ports On To Second Stage Router

Jan 16, 2013

I have got 3 wifi routers i want to daisy chain. Router 1 is main modem router, which is connected to 2 pcs and 2 wif routers (wired separately), both of these wifi routers have there own ip address and dchp turned off, so they work fine and broadcast wifi nicely. now what i want to do is connect another wifi router to one of these routers (not the main one) but what setting do i need? i tried to connect the 3rd wifi router with the same setting as per the other two ie diff ip and dchp off, but when i plugged it into the port of the second router it would not show as connected or get an internet connection. Its probably quite simple to sort out, but with me being a dimwit i am tering my air out. If i could not use a wifi router for this 3rd connection, is there any other way of putting an extra 4 ports on to my second stage router.

View 4 Replies View Related

Cisco VPN :: 5510 Vpn Client With No Nat

Jan 26, 2011

i have a 5510 with a working VPN but discovered that anyone connecting from a public IP can connect to VPN but can't go anywhere.so if i have say a linksys wifi on my cable modem and a private IP i can connect no problem. but if i'm on like a verizon data card which gives me a public IP i can connect to VPN but receive the below errors in my asa logs and can not reach anything on the network.What do i need added to allow remote ends without a nat device to also work?

View 4 Replies View Related

Cisco VPN :: Asa 5510 And Pix 515 VPN Client

Jan 1, 2012

Since last week we are having problems with remote users working with VPN client on Windows XP.The connection is stablished but no data traffic occurs. 

As we didn't do any change in vpn remote settings I did a test from Linux machine running VPNC client and it works well.It sounds so weird because it happens only on Windows client platform.We have CISCO ASA 5510 and PIX 515 running 8.0(4).

View 4 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved