AnyConnect tunnels through HTTPS


1
. Enable WebVPN on the interface

webvpn
enable PUBLIC
svc ask enable

!

2. Configure AAA authentication and tunnel group

tunnel-group DefaultWEBVPNGroup type remote-access
tunnel-group DefaultWEBVPNGroup general-attributes
authentication-server-group LOCAL

!

3. If using LOCAL database, add users to the Database

username test password t3stP@ssw0rd
username test attributes
service-type remote-access

!

4. Point the ASA to an AnyConnect image

webvpn
svc image anyconnect-win-2.1.0148-k9.pkg

!

5. Enable AnyConnect

webvpn
enable PUBLIC

!

6. Add an address pool to assign an ip address to the AnyConnect

ip local pool client-pool 192.168.1.1-192.168.1.254 mask 255.255.255.0

!

7. Configure group policy

group-policy DfltGrpPolicy internal
group-policy DfltGrpPolicy attributes
vpn-tunnel-protocol svc webvpn

!

8. NAT Exemption

access-list NONAT extended permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0
!
nat (inside) 0 access-list NONAT

!

9. DNS

group-policy DfltGrpPolicy attributes
dns-server value 8.8.8.8
default-domain value

!

10. Split Tunneling + Binding to Group-Policy

access-list SPLIT standard permit 192.168.1.0 255.255.255.0

group-policy DfltGrpPolicy attributes
split-tunnel-policy tunnelspecified
split-tunnel-network value SPLIT

!

11. Autolaunch Anyconnect ( Cisco SSL VPN Client (SVC)

group-policy DfltGrpPolicy attributes
webvpn
svc ask none default svc

!
!

12. Complete Configuration :

access-list NONAT extended permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0
!
access-list SPLIT standard permit 192.168.1.0 255.255.255.0
!
ip local pool client-pool 192.168.2.1-192.168.2.254 mask 255.255.255.0
!
nat (inside) 0 access-list NONAT

!
!

webvpn
enable PUBLIC
svc ask enable
svc image disk0:/anyconnect-win-2.4.1012-k9.pkg 1
!
tunnel-group DefaultWEBVPNGroup type remote-access
tunnel-group DefaultWEBVPNGroup general-attributes
authentication-server-group LOCAL
!
group-policy DfltGrpPolicy internal
group-policy DfltGrpPolicy attributes
dns-server value 8.8.8.8
default-domain value dallas.co.uk
vpn-simultaneous-logins 50
vpn-idle-timeout none
vpn-tunnel-protocol svc webvpn
password-storage enable
address-pool client-pool
split-tunnel-policy tunnelspecified
split-tunnel-network value SPLIT
!
username ECVPN01 attributes
service-type remote-access
!
username ECVPN01 attributes
webvpn
file-browsing enable
file-entry enable
homepage value http://172.28.2.10

 

Summary :
Complete Configuration (nonat/split tunnel/client-pool) :

access-list NONAT extended permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0
!
access-list SPLIT standard permit 192.168.1.0 255.255.255.0
!
ip local pool client-pool 192.168.2.1-192.168.2.254 mask 255.255.255.0
!
nat (inside) 0 access-list NONAT
!

Complete Configuration (webvpn) :

webvpn
enable outside
svc enable
svc image disk0:/anyconnect-win-2.4.1012-k9.pkg 1
svc image disk0:/macimg.dmg 2
!

Complete Configuration (group-policy)

group-policy DfltGrpPolicy internal
group-policy DfltGrpPolicy attributes
dns-server value 8.8.8.8
vpn-simultaneous-logins 50
vpn-idle-timeout none
vpn-tunnel-protocol svc webvpn
password-storage enable
split-tunnel-policy tunnelspecified
split-tunnel-network-list value SPLIT
default-domain value mydomain.com
!

Tunnel-Group Configuration :

ip local pool client-pool 192.168.50.1-192.168.50.254 mask 255.255.255.0
!
tunnel-group DefaultPolicy type remote-access
tunnel-group DefaultPolicy general-attributes
address-pool client-pool
authentication-server-group (PUBLIC) LOCAL
default-group-policy DfltGrpPolicy
!
tunnel-group DfltGrpPolicy webvpn-attributes
group-alias MYVPN enable
!
webvpn
tunnel-group-list enable
!

Username Configuration :

username ECVPN01 attributes
service-type remote-access
!
username ECVPN01 attributes
webvpn
file-browsing enable
file-entry enable
homepage value http://172.28.2.10