Troubleshooting: Unable to Connect to Cisco's SSL Clientless VPN Service

Follow
    Applies to:
Deployment model:
  • On Premises
  • Version Affected: All
     
     

    Overview

    Connecting to a SecureAuth server through Cisco's SSL Clientless VPN service fails with Connection failed. Server [IP address] unavailable.

    Cisco SSL VPN Service page showing Connection failed, Server 192.168.2.254 unavailable.

    This same generic message is shown regardless of what is actually preventing the connection, so the real cause has to be confirmed separately.

     

    Cause

    Cisco's SSL Clientless VPN service cannot read the SHA-2 512 ECDSA appliance certificate that SecureAuth binds to IIS by default. This is confirmed if a VPN connection succeeds through Cisco's AnyConnect client, but fails specifically through Cisco's SSL Clientless VPN service.

     

    Resolution

    Bind a different certificate to the Default Web Site in IIS — a SHA-1 appliance certificate or a purchased wildcard certificate will work.

    1. Open Internet Information Services (IIS) Manager.
    2. In the left-hand panel, expand the directory under the machine's name, expand Sites, and click Default Web Site.
    3. In the right-hand panel, click Bindings...

    IIS Manager with Default Web Site selected and the Bindings link highlighted in the Actions pane.

    1. In the Site Bindings window, select https 443 and click Edit...

    Site Bindings dialog with the https port 443 binding selected and the Edit button highlighted.

    1. From the SSL certificate drop-down, select an alternative to the SHA-2 512 ECDSA appliance certificate. Use View... to confirm you've selected the right one.
    2. Click OK, then test the VPN connection again.

    If the desired certificate does not appear in the SSL certificate drop-down, it may not have been imported correctly — confirm the certificate is in the Personal folder of the Local Machine certificate store, and that it has an associated private key.


     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.