SSL Remote Access

Loading SDM Recommended

Cisco Security Device Manager (SDM) provides an easy-to-navigate and simple graphical user interface (GUI) to set up and manage different features that a Cisco IOS router provides. It is bundled with a variety of administration, configuration, and monitoring tools to check the health of the device and the traffic traversing through it. Although setting up SDM is optional, you should use SDM in configuring the SSL VPN functionality in Cisco IOS routers. NOTE SSL VPN is a relatively new feature...

Ssl Vpn Specifications on Cisco ASA

As with any network design, you need to determine the size and scope of the SSL VPN implementation, especially the number of concurrent users that will connect to gain network access. If one Cisco ASA is not enough to support the required number of users, the available load-balancing features, such as ASA clustering, must be considered to accommodate all the potential remote users. Table 4-1 lists the supported security appliances, their VPN throughput, and the number of supported SSL VPN users...

Port Forwarding Technology

Clientless web access supports only a small set of corporate business applications that already have a web interface or can be easily webified. To be a complete remote access VPN solution, SSL VPN-based solutions need to be able to support other types of applications. The port-forwarding client solves part of the problems. The SSL VPN port-forwarding client is a client-side agent that intercepts specific application traffic and redirects the traffic to the SSL VPN gateway through the...

Case Study SSL Connection Setup

The section examines the setup of an SSL connection as a case study of the workings and implementations of the concepts we have discussed so far. The section examines the communications from both the SSL session level and lower TCP IP packet level using tools such as ssldump and ethereal. The SSL connection used in this case study is fairly simple. A user at IP address 10.1.1.200 browses to a website at IP address 66.94.230.34 using HTTPS, views the page, and then closes the connection. First,...

Configuring Application ACL

Vpn Ssl Port Forward Cisco Java Applet

Network administrators can restrict their clientless SSL VPN users to access certain application servers by configuring the application access control lists ACL . They can filter traffic such as Hypertext Transfer Protocol HTTP , HTTPS, FTP, and Common Internet File System CIFS , to name a few. These ACLs affect only the clientless SSL VPN traffic. An application ACL is configured by choosing Configure gt VPN gt SSL VPN gt Edit SSL VPN gt SecureMeContext gt Edit gt App ACL. Click Add, specify...

Configuring Group Policies

The user group and default group policies are configured by choosing Configuration > Remote Access VPN > Clientless SSL VPN Access or Network (Client) Access > Group Policies. Click Add to add a new group policy. As shown in Figure 5-4, a user group-policy, called ClientlessGroupPolicy, has been added. This group-policy only allows clientless SSL VPN tunnels to be established and strictly rejects all the other tunneling protocols. If you would rather assign attributes to default...

Any Connect VPN Client Configuration Guide

During the early development period of SSL VPNs, network administrators needed a VPN client that had similar benefits of an IPsec remote access VPN client, but required less administrative overhead than installing and maintaining the IPsec VPN client. To accommodate those requirements, the idea of a full tunnel SSL VPN client emerged. In the pre-version 8.0 releases, Cisco provided the SSL VPN Client (SVC). This is a self-downloading, self-installing, self-configuring, and self-uninstalling VPN...

Step 2 Defining Any Connect VPN Client Attributes

After loading the AnyConnect package in the router's configuration, SDM allows you to define the client parameters. Before an AnyConnect VPN Client is functional, you have to configure the following attributes Defining a pool of addresses Creating a Layer 3 interface Optionally, you can define other attributes to enhance the functionality of the SSL VPN configuration. They include Keep SSL VPN client installed The sections that follow define these options. The Cisco IOS router allows you to...

Monitoring an Ssl Vpn in Cisco IOS

Monitoring Ssl

This section discusses the monitoring steps that are available to help you run the SSL VPN solution smoothly on the IOS router. To monitor SSL VPN sessions, the first step is to check how many active SSL VPN tunnels are established on the IOS router. You can achieve this by choosing Monitor > VPN Status > SSL VPN (All Contexts) > SecureMeContext > Users. The Cisco IOS router shows you all the active VPN sessions for the SecureMeContext context. As shown in Figure 6-47, an active...

Accessing ASDM

ASDM's interface can be accessed from any workstation whose IP address is in the trusted network list. Before you establish the secure connection to the appliance, verify that IP connectivity exists between the workstation and the Cisco ASA. To establish an SSL connection, launch a browser and point the URL to the IP address of the appliance. In Figure 5-1, the administrator is accessing ASDM by entering https 192.168.1.1 admin as the URL. The URL is redirected to https 192.168.L1 admin public...

Diffie Hellman

Published in 1976, Diffie-Hellman (DH) was the first published public-key algorithm. Diffie-Hellman is a key agreement protocol that enables communication parties to agree on a shared secret without any prior-known secrets. Diffie-Hellman is often used in key exchange and during the establishment phase of a VPN tunnel. The Diffie-Hellman algorithm works as follows 1 The communication parties agree on two system parameters a large prime p and a generator g. These are chosen such that for any...

Reverse Proxy Technology

HTTPS provides secure web communication between a browser and a web server that supports the HTTPS protocol. SSL VPN extends this model to allow VPN users to access corporate internal web applications and other corporate application servers that might or might not support HTTPS, or even HTTP. SSL VPN does this by using several techniques that are collectively called reverse proxy technology. A reverse proxy is a proxy server that resides in front of the application servers, normally web...

SSL Record Protocol and Handshake Protocols

This section describes the SSL protocol operation, including SSL connection negotiation, key derivation, and secure data transfer. The section explains how the various cryptographic elements described earlier are used in SSL to build a secure communication. An SSL connection is established in two main phases. The handshake phase (phase 1) negotiates cryptographic algorithms, authenticates the server, and establishes keys for data encryption and MAC. The secure data transfer phase (phase 2) is...

Introduction to Remote Access VPN Technologies

Since the advent of the Internet, network administrators have looked for ways to leverage this low-cost, widespread medium to transport data while protecting data integrity and confidentiality. They looked for ways to protect the information within the data packets while providing transparency to the end user. This spawned the concept of Virtual Private Networks (VPN). Subsequently, the Internet Engineering Task Force (IETF) was engaged to craft standard protocols and procedures to be used by...

Overview of Cisco Ssl Vpn Product Portfolio

Cisco currently offers the SSL VPN functionality in a number of its product offerings, including the following Cisco VPN 3000 series concentrator The Cisco VPN 3000 series concentrator was the first Cisco product to offer the SSL VPN functionality. The clientless and thin-client modes were introduced in the 4.1 version of code, whereas the full-tunnel client support was added in the 4.7 version of code. Cisco VPN 3000 series concentrators are now end-of-life units. Cisco recommends that you...

Cisco ASA 5500 Series

The Cisco ASA 5500 series Adaptive Security Appliance provides an advanced Adaptive Identification and Mitigation (AIM) architecture and is a key component of the Cisco Self-Defending Network. As mentioned earlier in this chapter, the security appliances integrate firewall, IDS IPS, and VPN capabilities and provide an all-in-one solution for an organization. Seven Cisco ASA 5500 series models are available in the current Cisco ASA 5500 series product line. They include the following The Cisco...

Enabling Any Connect VPN Client Functionality

Preferred Dtls Tunnel

After the AnyConnect VPN Client is loaded into flash, the next step is to enable the AnyConnect Client functionality on the interface that is terminating the connection. This is achieved by selecting Enable Cisco AnyConnect VPN Client or Legacy SSL VPN Client Access on the Interfaces Selected in the Table Below in Configuration > Remote Access VPN > Network (Client) Access > SSL VPN Connection Profiles. Select the outside interface if it is the interface that will terminate the SSL VPN...

Split Tunneling

Dmz Split Tunnel Acl

After the tunnel is up, the default behavior of the Cisco AnyConnect VPN Client is to encrypt traffic destined to all the IP addresses. This means that if an SSL VPN user wants to browse to http www.cisco.com over the Internet, as illustrated in Figure 5-41, the packets will get encrypted and be sent to Cisco ASA. After decrypting them, the security appliance will look at its routing table and forward the packet to the appropriate next-hop IP address in clear text. These steps are reversed when...

Initial Connectivity Issues

If you are using AnyConnect VPN Client in your environment and a user is having initial connectivity issues, enable debug webvpn svc on the security appliance and analyze the debug messages. Most of the configuration-specific issues can be easily fixed by looking at the error messages. For example, if your security appliance is not configured to assign an IP address, you will receive a No Assigned Address error message in the debugs. This is highlighted in Example 5-14. Example 5-14 debug...

Step 1 Loading the CSD Package

Like AnyConnect Client, you have to load the CSD package in the local flash of the SSL VPN gateway. If you are not sure whether you have CSD installed on your IOS router, type show flash or dir and look for the sdesktop.pkg file in the webvpn directory. Using SDM, you can choose Configure > VPN > SSL VPN > Packages and check whether the CSD is installed. SDM allows you to Download the latest Cisco Secure Desktop (CSD) installation bundle. It connects to Cisco.com by prompting you for...

Defining Prelogin Policies

Remote Access Settings Registry

In the supported Windows, OS X, and Linux-based operating systems, you can define the potential locations where the client computers might be connecting from. For example, if your users connect from the office network, home office network, and even Internet caf s, you can define a location for each setup and give appropriate access to your users. For users connecting from the office network, you classify those hosts fairly securely and allow a less restrictive environment. For users connecting...

Step 1 Set Up CSD

The first step in achieving the listed goals is to create a secure environment for remote users. This is achieved by following these steps 1 Choose Configuration > Remote Access VPN > Secure Desktop Manager > Setup, click Browse Flash to select the CSD file you want to use, and select Enable Secure Desktop. 2 Choose Configuration > Remote Access VPN > Secure Desktop Manager > Windows Location Setting and define a prelogin sequence based on registry key and IP address range. Create a...

Configuring Ssl Vpn Portal Customization

Figure 5-11 shows the default SSL VPN page when a connection is initiated from a web browser. The title of the page is SSL VPN Service and the Cisco Systems logo is displayed in the upper-left corner of the web page. The initial page prompts the user for user authentication credentials. Figure 5-11 Default SSL VPN Login Page Figure 5-11 Default SSL VPN Login Page You can customize the initial SSL VPN login page based on security policies of your organization. Cisco ASA also allows you to...

Step 3 Configuring Ssl Vpn Look and Feel

Figure 6-5 shows the default SSL VPN page when a connection is made to the IOS router from a web browser. The title of the page is SSLVPN Service, and the Cisco Systems logo is displayed in the upper-left corner of the web page. The initial page prompts the user for user authentication credentials. The default login message is Welcome to Cisco Systems SSLVPN Service. You can customize the initial SSL VPN login page based on the security policies of your organization. Cisco IOS routers also...

Public Key Infrastructure Digital Certificates and Certification

The preceding section showed how you can use digital signatures to achieve important security requirements, such as entity authentication, nonrepudiation, and data origin authentication. You might have noticed that one piece is still missing in the picture. To verify the digital signature, you need to have the sender's public key. This public key should be distributed not only to the public in a scalable way but also be trusted as the true public key of the sender. (For example, Bob can post...

Monitoring and Troubleshooting Ssl Vpn

The following sections discuss the monitoring and troubleshooting steps that are available to help you in running the SSL VPN solution smoothly on a security appliance. To monitor the WebVPN sessions, first check how many active SSL VPN tunnels are established on the security appliance. You can do this by choosing Monitoring > VPN > VPN Statistics > Sessions. The security appliance shows you all the active VPN sessions, including the clientless and full tunnel client connections. As shown...

CSD Architecture

CSD not only checks certain attributes on the client computer to ensure its compliance but also enhances data security by providing an encrypted vault to authorized users. When a user wants to establish an SSL VPN session and CSD is enabled, the client and the gateway go through a number of steps, discussed as follows. These steps are also illustrated in Figure 5-45 Step 1 A user tries to request the SSL VPN login page by pointing his or her browser to the gateway IP address. Step 2 The user...

Ssl Vpn Prerequisites

You must meet a number of prerequisites before you can start implementing an SSL VPN in your enterprise. They are discussed in the following sections. The SSL VPN functionality on the ASAs requires that you have appropriate licenses. For example, if your environment is going to have 75 SSL VPN users, you can buy the SSL VPN license that can accommodate up to 100 potential users. Table 5-2 lists the available licenses and their respective part numbers. Note that an SSL VPN license file for ten...

Configuring Clientless Ssl Vpns

As mentioned in Chapter 3, SSL VPN Design Considerations, Chapter 4, Cisco SSL VPN Family of Products, and Chapter 5, SSL VPNs on Cisco ASA, remote users can use SSL VPNs to browse their internal websites and Outlook Web Access. A Cisco IOS router terminates the HTTPS connections on its public interface and then forwards the HTTP or HTTPS requests to the internal web server. The response from the web server is then encapsulated into HTTPS and forwarded to the client. This feature uses only an...

Configuring Smart Tunnels

As discussed earlier, port forwarding provides access to applications that use static TCP ports. It modifies the HOSTS files on a host so that traffic can be redirected to a forwarder that encapsulates traffic over the SSL VPN tunnel. Additionally, with port forwarding, the Cisco ASA administrator needs to know what addresses and ports the SSL VPN users will connect to, and requires the SSL VPN users to have admin rights to modify the HOSTS file. To overcome some of the challenges related to...

Step 1 Set Up Radius for Authentication

The first step is to set up a RADIUS server for user authentication as follows 1 Choose Configure > VPN > AAA > AAA Servers and Groups > AAA Servers > Add. Choose RADIUS as the Server Type and configure 192168.1.10 as its IP address. Select Configure Key and specify cisco123 as the New Key. Enter cisco123 under Confirm Key. Click OK when finished. 2 Choose Configure > VPN > AAA > AAA Servers and Groups > AAA Server Groups > Add. Under Group Name, type InternalRADIUS, select...

Content Rewriting

The previous section described URL mangling, which is an important technique in the process by which SSL VPN users access corporate resources using the clientless web access mode. The second important technique is content rewriting. As a reverse proxy server, the SSL VPN gateway fetches web-based content from an internal web server and performs content rewriting. The main goal of the content rewriting is to change the URL references and Java socket calls so that all users' requests point to the...

Ssl Vpn Licenses on Cisco ASA

Unlike IPsec, the SSL VPN capability in the security appliance is not included free of charge in the base system price. If you want to enable SSL VPN on a security appliance, you must purchase appropriate licenses. The base security appliance includes two SSL VPN users by default for evaluation, lab testing, and remote management purposes. Anything beyond that requires you to buy a separate SSL VPN license. For example, if your environment will have 75 SSL VPN users, you can buy the SSL VPN...

Ssl Vpn Licenses on Cisco IOS Routers

Just as with Cisco ASAs, you need to purchase licenses to enable SSL VPN on a Cisco IOS router. Before you implement SSL VPN on an IOS router, or in a cluster of IOS routers, you need to determine the size of SSL VPN deployment, especially the number of concurrent users of this service. For example, if one IOS router is not enough to support the required number of users, you must consider traditional load balancers or server-clustering schemes to accommodate all potential remote users. SSL VPN...

Logout Page

Logout Pages

Cisco ASA even allows you to customize the logout page. You can define the logout message and provide an option for whether users can be allowed to log back in. You can pick the color of the title font and title background, and the font and background colors of the logout page. In Figure 5-19, the administrator has added the logout message Please Clear Your Browser's Cache, Delete Any Downloaded Files, and Close All Open Browsers Before You Sign Out. The login button is not allowed, and thus...

Configuring Bookmarks

Using a clientless SSL VPN, remote users can browse their internal websites, file server shares, and Outlook Web Access (OWA) servers. Cisco ASA achieves this functionality by terminating the SSL tunnels on its outside interface and then rewriting the content before sending it to the internal server. For example, if a user tries to access an internal website, the user's HTTPS connection is terminated to the outside interface. The ASA then forwards the HTTP or HTTPS request to the internal web...

Setting Up the Appliance

When the ASDM file is accessed, the Cisco ASA loads the first ASDM image that it finds from the local flash. If multiple ASDM images exist in the flash, use the asdm image command and specify the location of the ASDM image you want to load. This ensures that the appliance always loads the specified image when ASDM is launched. In Example 5-9, the appliance is set up to use asdm-603.bin as the ASDM image file. Example 5-9 Specifying the ASDM Location Chicago(config) asdm image disk0 asdm-603.bin...

Configuring File Servers

In addition to the web servers, you can also define a bookmark list of the file servers that the clientless users can access. Cisco ASA supports network file sharing using the Common Internet File System (CIFS), a file system that uses the original IBM and Microsoft networking protocols. Through CIFS, users can access their file shares located on the file servers. Users can download, upload, delete, or rename the files under the shared directories, but only if the file system permissions allow...

Windows File Sharing

Cisco IOS routers support network file sharing through Common Internet File System (CIFS). Using CIFS, users can access their file shares located on the file servers, as illustrated in Figure 6-15. Users can download, upload, delete, or rename the files under the shared directories, but only if the file system permissions allow them to perform those actions. Figure 6-15 CIFS Browsing on the IOS SSL VPN Gateway mMBjjl'UMMI Figure 6-15 CIFS Browsing on the IOS SSL VPN Gateway mMBjjl'UMMI...

Defining Policies for the Mac and Linux Cache Cleaner

As mentioned earlier in the chapter, Cache Cleaner is supported not only on Windows operating systems but also on Linux and Mac OS X systems. Additionally, you can define a limited VPN feature policy for these clients. Table 6-8 lists the available features that you can implement for Mac- and Linux-based computers. Figure 6-43 Defining Windows CE Policies tMrtut Wpi-.um. 1 fiS.JOO. Sfcul_jKii*i.hfrJ yrniTKHTQ* KuiunrMi-Cjinlnil - bj HL Secure Desktop Manager tor W bVPN WN 1 ture Poky under...

Enabling Clientless Ssl Vpn on an Interface

The first step in setting up a clientless SSL VPN on the security appliances is to enable SSL VPN on the interface that will terminate the user session. If SSL VPN is not enabled on the interface, Cisco ASA will not accept any connections, even if SSL VPN is globally enabled. To enable SSL VPN on an interface through ASDM, choose Configuration > Remote Access VPN > Clientless SSL VPN Access > Connection Profiles and select the Allow Access check box next to the interface on which you want...

Ssl Vpn Tunnel Client

Traditional clientless web access and port-forwarding access do not satisfy the needs of power users and telecommuters who run VPNs on corporate-owned machines and like to have full access to the corporate resources. The IPsec VPN is a better fit to provide full network-layer access to the VPN users. Organizations that already have a remote access IPsec VPN can use the existing VPN solution to provide network-layer access and clientless SSL VPN for application-level VPN access. Today, most SSL...

URL Mangling

URL mangling is used to direct user URL requests to the SSL VPN gateway that intermediates the user requests by parsing them to the true destination server address and then forwards the requests to the servers on behalf of the end users. For the web bookmarks on an end user's sign-in page, the bookmarks have been premangled by the SSL VPN gateway. For a URL request that has been input by end users, the URL is mangled by a JavaScript that is downloaded from the SSL VPN gateway at user sign-in...

Defining a Pool of Addresses

During the SSL VPN tunnel negotiations, an IP address is assigned to the VPN adapter of the AnyConnect VPN Client. The client uses this IP address to access resources on the protected side of the tunnel. Cisco ASA supports three different methods to assign an IP address back to the client Many organizations prefer assigning an IP address from the local pool of addresses for flexibility. The IP address is assigned by configuring an address pool and then linking the pool to a policy group. You...

Step 1 Define Clientless Connections

The first step in achieving the listed goals is to set up clientless connections for remote contractors as follows 1 Define bookmarks for the internal servers (web and CIFS) by choosing Configuration > Remote Access VPN > Clientless SSL VPN Access > Portal > Bookmarks > Add. Specify a bookmark list name called Contractors-List and then click Add to specify a bookmark title of Internal-Web. Select http under the URL Value drop-down menu, and configure a URL value of http...

Setting Up Basic Host Scan

To configure CSD to scan a remote computer for basic information, click Add under Basic Host Scan and select the type of basic scan you would like to configure. As mentioned in the previous section, a basic Host Scan can identify registry keys, active processes, and files located on the remote workstation. For example, if you want CSD to scan a registry key from the workstation and based on that information you want to apply appropriate action by DAP, add Registry Scan under Basic Host Scan....

Step 1 Defining a Smart Tunnel List

Reverse Proxy Smart Tunnel Ifilter

You must define a list of the applications that you want clientless SSL VPN users to access. Smart tunnel list is defined by choosing Configuration > Remote Access VPN > Clientless SSL VPN Access > Portal > Smart Tunnels > Add. Specify a name for the new smart tunnel list. This list name has only local significance, and it is eventually used to map the smart tunnel attributes to a group policy, discussed in the next step. To define a specific application to be used for smart...

Single SignOn

Optionally, you can add a single sign-on (SSO) server to ensure that clientless users do not get prompted again to enter their user credentials if they try to access windows-based shares. In SSO, the security appliance acts as a proxy between the clientless SSL VPN user and the authentication server. The security appliance uses users' cached credentials (an authentication cookie) when the user tries to access secure websites or shares within the private network. If you use NT LAN Manager (NTLM)...

Configuring Anti Spyware Host Scan

To set up the security appliance to scan the remote workstation for antispyware, click Add under AntiSpyware. You can check remote workstations for antispyware compliance and update noncompliant computers. A new window opens with a list of all supported antispyware vendors and their respective products. Select the antispyware vendor and product that you use in your environment from the list and click OK when finished. Similar to the antivirus scan option, you can also force the remote...