Cisco ASA Certificate Management for AnyConnect
Certificates on a Cisco ASA serving AnyConnect (Cisco Secure Client) traffic do two related but distinct jobs. First, the ASA
Cisco Adaptive Security Appliance, the stateful firewall platform that has anchored enterprise perimeters for two decades and is now being succeeded by Secure Firewall (FTD). Articles tagged ASA cover security levels, NAT 8.3+ and twice NAT, ACLs, AnyConnect SSL and IKEv2 VPN, site-to-site IPsec, failover, packet-tracer, hardening, and ASAv 9.x lab walkthroughs.
Certificates on a Cisco ASA serving AnyConnect (Cisco Secure Client) traffic do two related but distinct jobs. First, the ASA
Dynamic Access Policies (DAP) on the Cisco ASA are the runtime override layer for VPN sessions. They evaluate at login
Authentication, Authorization, and Accounting (AAA) on a Cisco ASA decides three things for every VPN session: who is the user,
Two of the most overloaded terms in Cisco ASA VPN configuration are group-policy and tunnel-group. They sound similar,
Split tunneling controls which traffic from a connected VPN client traverses the encrypted tunnel and which traffic exits to the
AnyConnect (Cisco Secure Client) supports two transport options when connecting to an ASA: SSL/TLS over TCP/443 and IKEv2/
AnyConnect SSL VPN (rebranded as Cisco Secure Client) is the most common remote-access VPN you will configure on a
Most "the ACL is broken" tickets are not really broken ACLs. They are misunderstood ACLs: a packet you
Most Cisco ASA NAT outages are not "the rule does not work". They are "the rule works,
Identity NAT, sometimes called NAT exemption or "no-NAT", is the rule you write when you specifically do
Twice NAT is the rule type you reach for when one source-only or destination-only translation is not enough.
Static NAT is the rule that lets the rest of the internet reach a server you own. The classic case