Version Affected: All
Overview
Connecting to a SecureAuth server through Cisco's SSL Clientless VPN service fails with Connection failed. Server [IP address] unavailable.
This same generic message is shown regardless of what is actually preventing the connection, so the real cause has to be confirmed separately.
Cause
Cisco's SSL Clientless VPN service cannot read the SHA-2 512 ECDSA appliance certificate that SecureAuth binds to IIS by default. This is confirmed if a VPN connection succeeds through Cisco's AnyConnect client, but fails specifically through Cisco's SSL Clientless VPN service.
Resolution
Bind a different certificate to the Default Web Site in IIS — a SHA-1 appliance certificate or a purchased wildcard certificate will work.
- Open Internet Information Services (IIS) Manager.
- In the left-hand panel, expand the directory under the machine's name, expand Sites, and click Default Web Site.
- In the right-hand panel, click Bindings...
- In the Site Bindings window, select https 443 and click Edit...
- From the SSL certificate drop-down, select an alternative to the SHA-2 512 ECDSA appliance certificate. Use View... to confirm you've selected the right one.
- Click OK, then test the VPN connection again.
If the desired certificate does not appear in the SSL certificate drop-down, it may not have been imported correctly — confirm the certificate is in the Personal folder of the Local Machine certificate store, and that it has an associated private key.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.