Cisco VPN :: QuickVPN Client To ASA 5505 - Using Port 60443
Mar 16, 2011Setting up vpn using quickvpn client to asa5505. QucikVPN client version is 1.4.1.2. I need to use port 60443, port 443 is already taken.
View 1 RepliesSetting up vpn using quickvpn client to asa5505. QucikVPN client version is 1.4.1.2. I need to use port 60443, port 443 is already taken.
View 1 RepliesI have a Cisco SA520W router and needs to set up VPN. Du to major problems with the SSL VPN Client and windows 7, I had to let it go and try a different approach.
That was the QuickVPN client, but as it turs out, it simply impossible from reading the user manual to understand just how I have to set thing up. For instance, the VPN Wizard tells you to enter a preshared key. But in the QuickVPN Client, where do I enter the key?
And shall the "Enable Cisco VPN Client" be ticket off, I assumed yes, but seriously it is impossible to know.
Then in the VPN Wizard again, in the Remote & Local WAN Adress, what shall use FQDN or IP Address. The if FQDN, what shall a enter, the domain name for the router, whats the point in that? The domain name of the VPN Client, seriously, what's the point in that? I would assume that 99% of the VPN Client does NOT have a domain name. Then, if IP address, am I supposed to know the IP address of the client? Same with the "Secure Connection Remote Accessibility", what am I supposed to enter. The IP address which the Quick VPN Client network adapter shall have?
Is there a safe way to use the Cisco VPN Client (V5.x) and Cisco Quick VPN (V1.4.1.2) on the same Windows PC? I need to access my office RVS4000 and my customer's PIX 506 from the same laptop (but not at the same time).
Perhaps I should be asking "Is there a single Windows VPN client that works with both the Cisco RVS4000 and Cisco PIX 506? I have seen these questions asked on various forums but have yet to see a definitive answer.
I have a RV042 router setup with Client to gateway VPN access, and am connecting with a W7 PC running QuickVPN. We have many PC's that already have the standard CiscoVPN client on them, is it possible to configure the RV042 to allow these clients to conenct? I'm not sure how to get the Mutual authentication to work, or how to import the PEM certificiate into that client. It seems to allow it to import, but I can never select it.
View 2 Replies View RelatedI have a Cisco RV082 and can successfully connect with the Cisco QuickVPN Client, 1.4.2.1. However, after 1 to 5 minutes I see the Windows 7 bluescreen indicating that the system has halted due to a problem with a driver. I have installed the latest Windows updates and reinstalled the client.
The bluescreen only occurs if I use the Cisco QuickVPN Client.
The establishment of IPSEC tunnel between the RV220 and QuickVPN client works properly with the security certificate of origin of the router.RV220 V1.0.3.5QuickVPN V1.4.2.1
Since the establishment of a security certificate self-signed, the RV220 and QuickVPN client refuses to work together .
Here are the log of the QuickVPN client
2011/09/27 12:45:14 [STATUS]OS Version: Windows 7
2011/09/27 12:45:14 [STATUS]Windows Firewall Domain Profile Settings: ON
2011/09/27 12:45:14 [STATUS]Windows Firewall Private Profile Settings: ON
2011/09/27 12:45:14 [STATUS]Windows Firewall Private Profile Settings: ON
[code].....
How to setup quickvpn to work with RVS4000.
View 9 Replies View RelatedI am setting up remote access using an RV042 router. Using quickvpn or a client-to gateway vpn and shrewsoft client, I can only access/ping the LAN side of the remote router and one machine on the remote network. The PPTP server and native Windows 7 connection provide access to all machines on the remote network.I have 2 possible reasons for this and would like to find the real reason:
1) The remote RV042 is behind another router, and that router restricts access other than the PPTP traffic.
2) The VPN tunnels other than PPTP only allow access to the remote LAN side of the router and remote machines that have the remote router defined as their gateway in the IP configuration.
I have a RVS4000 router, and using Quick VPN client (latest version, 1.4.2.1?) on a computer with Windows Vista. I can connect to the router, and I can see computers, and drives on the network. When I click on a drive or computer, I can't connect to the devices. Local IP address are 192.168.1.x, remote is 192.168.2.x.
View 9 Replies View RelatedI bought a router Cisco WRVS4400N Wireless-N Gigabit Security Router - VPN v2.0 with the intention of using with the Quick VPN Client for connecting to my home network.
My home network is connected to a pre provide by my ISP Thomson TG784 and is connected to it but all my main network is controlled by the WRVS4400N, I have forward all the doors, as you can see by the log part below, and by analyzing the log you can see that I can't get any PING to complete the VPN connection.
OS is windows 7
QuickVPN Clien is 1.4.2.1
WRVS4400N firmware is v2.0.2.1
Thomson TG784 firmware is 8.4.2.Q
Log from Quick VPN
2012/01/11 19:44:03 [STATUS]One network interface detected with IP address 192.165.0.196
2012/01/11 19:44:03 [STATUS]Connecting...
2012/01/11 19:44:03 [DEBUG]Input VPN Server Address = husportugal.dnsalias.com
[code]....
Log from WRVS4400N
Jan 15 10:12:53 - [VPN Log]: added connection description "Casa_rw_rw"
Jan 15 10:12:54 - [VPN Log]: listening for IKE messages
Jan 15 10:12:54 - [VPN Log]: forgetting secrets
[code]....
I connect to my RVS4000 VPN router using QuickVPN. Very useful.
Sometimes I am not near my laptop and need to check data.
Is there a QuickVPN or compatible client for a BlackBerry Torch 9850, even if it's only functional when connected to WiFi?
I recently installed a new RV120W router at one of my customer's office. I have 2 users connecting using the Quick VPN software.The first one is running on a Windows XP Pro SP3. Everything works great on this PC.The second PC is running on a Windows Vista - The QUICKVPN client stays at Veryfing Network and Eventually I get an error " The remote gateway is not responding. Do you want to wait?I have disabled Firewall on both PCS for troubleshooting purposes.
View 1 Replies View Relatedi have a question about tunneling a software EasyVPN client to a client ASA Network. It looks like this:
EasyVPN Server 192.168.202.0/24 Network extension mode to Client EasyVPN ASA 192.168.1.0/24 This works fine in both directions. But now i want to connect the client ASA network via EasyVPN software client from outside. The user are already able to connect to the ASA Server on its static outside IP obtaining an IP from a 192.168.21.0/24 pool. This works fine. But how am i able to connect to the 192.168.1.0/24 network from this client?
I am having difficulty following the logic of the port-translation. Here is the configuration on a 5505 with 8.3,So I would have thought the outside access-list should reference the 'mapped' port but even with 3398 open I cannot remote desktop to the host. If I open 3389 then I can connect successfully.
View 12 Replies View RelatedSo here is my network.
ASA5505--->Cisco1841--->Cat2960
Code
ASA asa831-k8.bin
Cisco 1841 c1841-adventerprisek9-mz.151-4.M2.bin
Cat 2960 c2960-lanbasek9-mz.122-55.SE1.bin
and here is my dilemma.
I can SSH from the internet to my ASA on default port 22, directly to my public IP. I can SSH from the internet to my Cisco 1841 on port 2001. I can not however, SSH to my Cat 2960. From what i can tell, on the Cat2960 i can't change the default port 22 for SSH to different port, just like i did on the Cisco 1841. I looked to see if I can change the default port for SSH on he ASA, it does not look like this is an option.
The bottom line is that i want to be able to SSH to all three devices from the internet. I only have one public IP. As of now, what i can do is only SSH to the ASA on default port 22 directly to the public IP and Cisco 1841 on port 2001. It appears that changing the default SSH port on Cat 2960 is not an option. It also appears that I can't change the default SSH port on the ASA, if i could, i would and then i should be able to SSH to the Cat 2960 on port 22. No matter what i did on the ASA, it always listens on port 22 for SSH connections.
show asp table socket
TCP 001f549f <<pub IP>>:22 0.0.0.0:* LISTEN
how do i make it listen on different port?
Here is relevent config for SSH for cisco 1841 (port forwarding)
ON ASA
object network ROUTER
host 10.10.1.1
[Code].....
With the Cisco ASA-5505, is there a more secure port that can be configured for VNC other than 5901? I am new to Firewalls We have a User who has requested that 5901 be opened but I was advised not to do so for security concerns.
View 5 Replies View RelatedWe have a Cisco 5505 firewall and working to setup VPN through the firewall, what Cisco vpn client should we download for our users to have the right client on their desktop/latops.
View 3 Replies View RelatedThere is a Cisco VPN client (running on Windows 7) and an ASA5505. The goals are client could use remote gateway on ASA for Skype and able to access the devices in ASA inside interface.
The Skype works well but I cannot access devices in the interface inside via VPN connection. Following is the config, how to correct NAT or VPN settings?
ASA Version 7.2(4)
hostname ciscoasa
domain-name default.domain.invalid
enable password wDnglsHo3Tm87.tM encrypted
passwd 2KFQnbNIdI.2KYOU encrypted
names
[code].....
I find it troubling that i would have to pay for additional licensing to use the mobile version of anyconnect.
Is there a third-party app that will allow a secure connection back to my house from my iPhone?
I have a client that has a 5505 installed. They want to VPN in with their Win7 laptop, but they don't want to shell out $1000 for the 10-pack Cisco VPN client.I have successfully setup the clientless VPN, and they can, through a browser, get to their files, but they'd like to map network drives so it's just like they're in the office.I tried setting the IP Sec up on the 5505, and then using the built-in Win7 VPN network connection, but no go.I also do everything through the ASDM, but I realize some things cannot be done. I'd prefer to use the ASDM!Anyone else get this configured? 99% of what I see out here is how to connect the 5505 for site-to-site VPN.
View 4 Replies View RelatedWe recently upgraded our 5505s to 8.2(5) 26 and noticed that each will crash after a cerntain amount of time. Some crash every 30 minutes other will crash every 4 to 8 hrs. The only difference would be the user's home ISP and/or home router, if they have one. They are configured with a dynamic dhcp IP address for the outside interface and the crash files starts with the following:When we downgrade back to 8.2(5) 13 the problem goes away. Any known bugs for this version? I haven't been able to find anything yet. We do have one 5505 that does not have this issues. The only thing that may be different is that it was never at 8.2(5) 13. We had downgrade it from a 8.3 version.
View 2 Replies View RelatedI am unable to connect to the vpn I set up on my ASA 5505 using the Cisco VPN Client on a Windows machine. The log of the vpn client and the config of the ASA 5505 are below.
LOG CISCO VPN CLIENT
Cisco Systems VPN Client Version 5.0.06.0160
Copyright (C) 1998-2009 Cisco Systems, Inc. All Rights Reserved.
[Code]......
We have a RA Vpn split_tunnel setup in one of our locations which is working fine in all areas except for traffic destinged for one specific website using https. This vendor only allows the HTTPS connections to them to come from certain outside IP addresses. ssentially it should work like this:RAVPN_client (10.4.4.0/27) --> https request to vendor_ip (208.x.x.x) ---> ASA55XX --> NAT_to_outside_ip --> https request to vendor_ip (208.x.x.x) need to understand how you would go about NATing ONLY this specific https traffic from the RA VPN while not having to alter the setup otherwise. Internal hosts (aka behind the ASA physically) do not have any issue getting to this site, as its nat'd to the outside ip address as we expect.Here is what we are using for the NAT Exemption list he 10.2.2.x, 192.168.100.x and 172.23.2.x are other remote sites that we have. RA VPN users are using the 10.4.4.0/27 do not have any issues connecting to them, no matter the protocol.
View 3 Replies View RelatedI try to configure a simple EzVPN infrastructure:
EzVPN Server (CISCO2811, hostname cme) < -- > EzVPN Remote (ASA5505, hostname ezvpn-asa) < -- > Client
Attached you find both configuration of the EzVPN server and remote. The tunnel is getting up and if I ping from the ASA to the Router, I see the packets getting encrypted:
ezvpn-asa# ping 172.16.100.1
...
ezvpn-asa# show crypto ipsec sa
interface: outside
Crypto map tag: _vpnc_cm, seq num: 10, local addr: 172.16.100.2
[code]....
If I connect a client with IP address 192.168.1.2 to the interface eth0/1 and do a ping to the cme, I don't see any packets getting encrypted. I don't have any idea about VPN, I just need it for a wireless lab environment. What do I have to configure on the ASA, so the inside traffic is encrypted?
I get the following error when trying to connect a vpn client through an ASA5505 with an already configured ipsec AES/256 site to site connection:
regular translation creation failed for protocol 50 src:inside:192.168.1.167 dst:outside:xx.xxx.x.64
The site to site addressing is not relevant, I'm not trying to pass traffic over the site-to-site, but rather create a new vpn from inside client to outside external vpn box that's not under my control. The client is able to create a connection, but no traffic is passed, when I try to ping / rdp, the above message is returned to me. If I add the rule static(inside, outside) interface 192.168.1.167 netmask 255.255.255.255 then it works, everything works, but ONLY from this computer.
Been Google for hours, but with no result as of yet.
I have a Cisco ASA 5505 which is setup as an EasyVPN client to e remote VPN concentrator.
The Cisco ASA has the 50 internal user license with 10 VPN peers.
We just upgraded the license from the base 10 internal user to 50 user license but it has not resolved the problem and only 10 internal users still work, the 11th fails.
Does each EasyVPN client on the inside network take up 1 of the 10 VPN peer licences?
This seems to be the issue from what I can see, just need confirmation.
I have an ASA 5505 that is on the perimeter of a hub & spoke vpn network, when I connect to this device using the VPN client I can connect to any device across the VPN infrastructure with the exception of the sub net that the client is connected to, for instance:
VPN client internal network connects to 192.168.113.0 /24 and is issued that ip address 192.168.113.200, the VPN client can be pinged from another device in this network however the client cannot access anything on this sub net, all other sites can be accessed ie. main site 192.168.16.0/24, second site 192.168.110/24 and third site 192.168.112/24. The ACL Manager has a single entry of "Source 192.168.113.0/24 Destination 192.168.0.0/16 and the "Standard ACL 192.168.8.8./16 permit.
I'm setting up our ASA 5505 for remote access VPN and now need to insert the VPN client addresses (allocated via RADIUS) into OSPF so that they get redistributed through our network.
The configuration of the ASA is that its hairpinning because it is behind an existing router/firewall (192.168.252.254), therefore it only has an inside interface (plus one for management).
The VPN access works fine as long as I have a static route on our router/firewall pointing the VPN clients network range to the ASA. But once I configure OSPF with a redistribute static (because VPN client addresses get added the the ASA as statics), a host route (which is fine) gets added to our firewall with a next hop of the router/firewall itself and not the ASA.
ieVPN Client route on the ASAS 192.168.242.75 255.255.255.255 [1/0] via 192.168.252.254, inside (not to sure if this is expected behaviour - would have thought it should be a Connected route)
VPN Client route on the Router/Firewall
192.168.242.75 192.168.252.254 UGH 0 1246 em2 (I would have expected that OSPF should have put this in with a gateway of .200)
Route in the ASA OSPF database192.168.242.75 192.168.252.200 839 0x80000002 0x9e45 0
I have a Cisco ASA 5505 which is setup as an EasyVPN client to e remote VPN concentrator.The Cisco ASA has the 50 internal user license with 10 VPN peers.We just upgraded the license from the base 10 internal user to 50 user license but it has not resolved the problem and only 10 internal users still work, the 11th fails. Does each EasyVPN client on the inside network take up 1 of the 10 VPN peer licences? This seems to be the issue from what I can see, just need confirmation.
View 3 Replies View RelatedWe have a cisco asa 5505 on which we have setup a group VPN. The VPN connections from all cisco vpn clients works fine except one. The keep getting the below error
"Secure VPN Connection terminated locally by the client. Reason 412: The remote peer is no longer responding. Connection Terminated".
Not sure why only one client won't be able to connect. The version we are using is 5.0.02 for VPN client.
Got some issues when setting up IPSEC/VPN on the asa 5505. I want to connect from the ipad with the built in IPSec client..Get these errors when i run the debug crypto isakmp.
View 6 Replies View RelatedI am working with a small off that has a 5505 acting as a basic firewall. Behind it are off-the-shelf unmanaged switches. Two users have to work with an outside vendor and are having issues. They have a Sonicwall remote VPN client on each of their desktops and use this to connect to the vendor. They then RDP into VMWare-based Windows 7 desktops at the vendor's site to do their work. Randomly throughout the day (6-10 times per day) while they are actively working the RDP session will disconnect. It will auto-reconnect after a few seconds. The VPN log on the clients never show any issues. I believe this is an RDP problem because while the RDP session is disconnecting, their VPN client is not (it is set to NOT auto-reconnect if it gets disconnected so that I will know for sure if it gets disconnected). I don't see anything in the ASA's logs about denying connections involving their PCs and the remote VPN peer IP.
View 7 Replies View RelatedI already have traditional IPsec VPN access working just fine through this device. Users connect and authenticate using a windows AD server for RADIUS and everything works great. However, the customer wants to use AnyConnect instead of the traditional VPN client. So I added a SSL connection profile (the anyconnect essentials feature is enabled on the device) and told it to use the same IP pool and RADIUS server group as the IPsec clients. I used the ASDM wizard to configure it and had no issues completing the wizard. when trying to make a connection to the webvpn portal I get a 404 error instead of the client portal. Also when trying to connect with the Anyconnect client, I get the usual "Untrusted VPN certificate" warning, but the connection attempt fails when I click through it.The strange part is when I look at the issued certificate in the browser or the client, it's showing me the certificate from the RADIUS server. Why is it looking there for certificate and more importantly, why does it care at all about a certificate when I've specified in the connection profile to use AAA to authenticate?
View 1 Replies View Related