Info Security Memo
  • Blog
  • Sitemap
    • Categories
  • Contact
  • About
  • Resources
  • Tools
  • 51sec.org

Build Confidence

Focusing on Information Security 

Info Security Notes

Cisco Configuration Professional (CCP) Configure IOS SSL VPN (AnyConnect SSL VPN)

8/7/2016

0 Comments

 
Basic Cisco Configuration Professional (CCP) configuration has been posted before at following link:
  • Cisco CCP Installation and Basic Configuration
This Post will demonstrate how to use CCP to configure SSL VPN on an IOS Router.

1. Confirm SSL-VPN License Installed

You can reviewanother post regarding how to add Cisco license into a router.
 photo 2016-08-01_12-48-45_zpsi738p9o2.png



From Command Line:
VPN-1#show license detail
Index: 1        Feature: NtwkEssSuitek9                    Version: 1.0
        License Type: EvalRightToUse
        License State: Active, Not in Use, EULA not accepted
            Evaluation total period: 8  weeks 4  days
            Evaluation period left: 8  weeks 4  days
            Period used: 0  minute  0  second
        License Count: Non-Counted
        License Priority: None
        Store Index: 2
        Store Name: Built-In License Storage
Index: 2        Feature: SSL_VPN                           Version: 1.0
        License Type: Permanent
        License State: Active, Not in Use
        License Count: 10/0/0  (Active/In-use/Violation)
        License Priority: Medium
        Store Index: 1
        Store Name: Primary License Storage
Index: 3        Feature: datak9                            Version: 1.0
        License Type: EvalRightToUse
        License State: Active, Not in Use, EULA not accepted
            Evaluation total period: 8  weeks 4  days
            Evaluation period left: 8  weeks 4  days
            Period used: 0  minute  0  second
        License Count: Non-Counted
        License Priority: None
        Store Index: 1
        Store Name: Built-In License Storage
Index: 4        Feature: ios-ips-update                    Version: 1.0
        License Type: EvalRightToUse
        License State: Active, Not in Use, EULA not accepted
            Evaluation total period: 8  weeks 4  days
            Evaluation period left: 8  weeks 4  days
            Period used: 0  minute  0  second
        License Count: Non-Counted
        License Priority: None
        Store Index: 3
        Store Name: Built-In License Storage
Index: 5        Feature: ipbasek9                          Version: 1.0
        License Type: Permanent
        License State: Active, In Use
        License Count: Non-Counted
        License Priority: Medium
        Store Index: 0
        Store Name: Primary License Storage
Index: 6        Feature: securityk9                        Version: 1.0
        License Type: Permanent
        License State: Active, In Use
        License Count: Non-Counted
        License Priority: Medium
        Store Index: 2
        Store Name: Primary License Storage
Index: 7        Feature: securityk9                        Version: 1.0
        License Type: EvalRightToUse
        License State: Inactive
            Evaluation total period: 8  weeks 4  days
            Evaluation period left: 8  weeks 4  days
            Period used: 0  minute  0  second
        License Count: Non-Counted
        License Priority: None
        Store Index: 0
        Store Name: Built-In License Storage



2. Launch SSL-VPN Configuration Wizard
 photo 2016-08-01_12-49-33_zpsdo5diqi6.png

 photo 2016-08-01_12-49-57_zpsnaspf8w0.png

3. Configuration Wizard:
3.1 Configure IP Address and Name
 photo 2016-08-01_12-50-52_zpsqrrhixdh.png


3.2 Configure User Authentication Methods
 photo 2016-08-01_12-51-34_zpshf3jbhvo.png

3. Configure IP Address Pool
 photo 2016-08-01_14-47-37_zpsihbgtcnk.png

 photo 2016-08-01_14-48-26_zpslgkvhnr8.png

3.4 SSL VPN Tunnel Interface

 photo 2016-08-01_14-50-15_zpsb2d0wo3a.png

3.5 SSL VPN Portal Page
 photo 2016-08-01_14-50-39_zpstwdllnho.png

3.6 Summary of the Configuraiton
 photo 2016-08-01_14-51-05_zps2uiq2fhw.png

SSL VPN Service Name : Rogers-SSL-1
SSL VPN Policy Name : policy_1
SSL VPN Gateway Name : gateway_1

Virtual Template IP Address: Un-numbered to GigabitEthernet0/0

User Authentication Method List :  Local

Intranet websites:  Disabled

Full Tunnel Configuration
 SVC Status : Yes
 IP Address Pool : 192.168.5.0-x
 Split Tunneling : Disabled
 Split DNS : Disabled
 Install Full Tunnel Client : Disabled


Configuration which sent to the router:

aaa authentication login ciscocp_vpn_xauth_ml_1 local
ip local pool 192.168.5.0-x 192.168.5.50 192.168.5.200
interface Virtual-Template1
 exit
default interface Virtual-Template1
interface Virtual-Template1
 no shutdown
 ip unnumbered GigabitEthernet0/0
 exit
webvpn gateway gateway_1
 ip address 158.106.98.166 port 443
 http-redirect port 80
 inservice
 ssl trustpoint TP-self-signed-3017776587
 exit
webvpn context Rogers-SSL-1
 aaa authentication list ciscocp_vpn_xauth_ml_1
 gateway gateway_1
 virtual-template 1
 max-users 75
 inservice
 secondary-color white
 title-color #669999
 text-color black
 policy group policy_1
  svc keep-client-installed
  functions svc-enabled
  svc address-pool 192.168.5.0-x netmask 255.255.255.255
  exit
 default-group-policy policy_1
 exit



4. Upload AnyConnect 4.x Package
Latest version is 4.3.01095. It can be downloaded from Cisco Website.

The downloaded package can be imported into Router from CCP Configuration - Security - VPN - SSL-VPN - Package:


Check the package from command line:
VPN-1#dir flash:
Directory of usbflash0:/

    1  -rw-    75608148   Jun 3 2016 14:13:10 -04:00  c1900-universalk9-mz.SPA.154-3.M3.bin
    2  -rw-        3066   Jun 3 2016 14:24:04 -04:00  cpconfig-19xx.cfg
    3  -rw-        1160  Jul 24 2016 10:58:00 -04:00  1.lic.txt
    4  drw-           0   Jun 3 2016 14:24:34 -04:00  ccpexp
  374  -rw-       22737   Jun 3 2016 14:27:22 -04:00  home.html
  382  -rw-        1154   Aug 1 2016 10:34:22 -04:00  2.lic
  388  drw-           0   Aug 1 2016 14:56:12 -04:00  webvpn
  395  -rw-    25162392   Aug 1 2016 15:07:34 -04:00  anyconnect-win-4.3.01095-k9.pkg

251371520 bytes total (113504256 bytes free)




5. Verify

Lauch web page from broswer:

After log into SSLVPN Service portal, choose Start for Application Access:

Another Web page will be opened to try to load AnyConnect Secure Mobility Client. It also provide link to manual Installation for AnyConnect VPN client which has been uploaded into Router at step 4.




Cisco AnyConnect Secure Mobility Client launched:
 photo 2016-08-04_13-34-49_zps0gablidl.png 




Reference:
  • AnyConnect VPN (SSL) Client on IOS Router with CCP Configuration Example


0 Comments



Leave a Reply.

    Categories

    All
    Architecture
    Blog
    Checkpoint
    Cisco
    Cloud
    CyberArk
    F5
    Fortigate
    Guardium
    Juniper
    Linux
    Network
    Others
    Palo Alto
    Qualys
    Raspberry Pi
    Security
    SIEM
    Software
    Vmware
    VPN
    Wireless

    Archives

    March 2024
    February 2024
    January 2024
    December 2023
    November 2023
    October 2023
    September 2023
    August 2023
    July 2023
    June 2023
    May 2023
    April 2023
    March 2023
    February 2023
    January 2023
    December 2022
    November 2022
    October 2022
    September 2022
    August 2022
    July 2022
    June 2022
    May 2022
    April 2022
    March 2022
    February 2022
    January 2022
    December 2021
    November 2021
    October 2021
    September 2021
    August 2021
    July 2021
    June 2021
    May 2021
    April 2021
    March 2021
    February 2021
    January 2021
    December 2020
    November 2020
    October 2020
    September 2020
    August 2020
    July 2020
    October 2019
    September 2019
    June 2019
    July 2018
    May 2018
    December 2017
    August 2017
    April 2017
    March 2017
    January 2017
    December 2016
    November 2016
    October 2016
    September 2016
    August 2016
    July 2016
    June 2016
    May 2016
    April 2016
    March 2016
    February 2016
    January 2016
    December 2015
    November 2015
    October 2015
    September 2015
    August 2015
    July 2015
    June 2015
    May 2015
    April 2015
    March 2015

    Print Page:

    RSS Feed

    Email Subscribe
Powered by Create your own unique website with customizable templates.
  • Blog
  • Sitemap
    • Categories
  • Contact
  • About
  • Resources
  • Tools
  • 51sec.org