Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

ASA 5505 - windows client access to VPN

Status
Not open for further replies.

davejam

Technical User
Jan 6, 2004
313
0
0
GB
Hi all,

Bit of a long story but here goes.

I took on my current position (2+ years ago) and at the time we had a contracted network guru (possibly) and were in the process of moving over to fibre.

Along with many other network upgrades we needed to implement and move over to the ASA 5505 which was setup and working fine, email was setup to pass through to our exchange, ftp passes through to our ftp machines, and we had a couple of VPN tunnels setup for our then branches (which have since been franchised off and access dropped).

I wanted to be able to get access to our network for the bosses and mobile workers (which we had through our old router using windows vpn client), after about a month he decided it was not possible and got us working with the cisco VPN Client. Although this is not what i'd asked for he managed to talk the director into the fact that it was more secure, therefore better than the windows connection.

We then had an issue as it would not work with 64bit, so he got a windows 64bit version which is what we are still using, and here in lies my problem.

Using the cisco tool it does not seem to work with windows 7 as well as i'd thought, and now i find my bosses machine is working on offline files when he is out of the building.
Our outlook does connect but we get intermittent issues with both security acceptions and user login poppup requests.

We have managed to get by with the above problems, not ideal but as its a live system, its a worry to start playing with things.

Unfortunately with people more and more using 3g and now 4g to connect the tool has become a real bind as it drops the connection every couple of minutes. What i really want is to move to a windows vpn (i know people will advise to stay with the cisco tool, but from what i've read, it is possible.

I have knowledge on working with all parts of IT and have setup Cisco routers in the past, I have a basic understanding on how its currently working, have access into the router with ADSM and have been trying a couple of NEW settings to get a connection, new tunnel group, new group policy and new user (and new ip pool) but have been getting no where as yet.

I have found a few articles on line and on cisco.com but don't want to make to many changes without some real results with going forward.

I cannot take it offline, and i deffinately don't want to have to start setting it back up from scratch!

Has anyone managed to set this up, does it require mashing through all of the settings? I almost want to add it in as an extra with new users etc is fine. I don't mind spending the time, just want to know if 1. its possible and 2. a starting point!!

If you want any further information I can supply, just banging my head against a wall and going round in circles.

Cheers


daveJam

easy come, easy go!!!
 

I would approach this by:
a/ check which version of Cisco Anyconnect VPN client supports Windows 7 and download that
b/ check which version of ASA firmware supports the new version of ANyconnect and upgrade it to that

Alternatively, you could investigate:
 
AnyConnect version 5.0.07.0290 64 bit works fine with 8.4 and 8.6 (ASA)...

ip access-list extended IP-Options-and-Powerball
deny ip any any winning-powerball-ticket
permit ip any any option any-options
!
class-map ACL-Options-and-Powerball
match access-group name IP-Options-and-Powerball
!
policy-map CoPP-POLICY
class ACL-Options-and-Powerball
drop
!
control-plane
service-policy input CoPP-POLICY
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top