<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Tech 21 Century</title>
	<atom:link href="http://www.tech21century.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.tech21century.com</link>
	<description>Technology in the 21st Century</description>
	<lastBuildDate>Thu, 02 Feb 2012 03:34:51 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>Comment on Allowing Microsoft PPTP through Cisco ASA by Brad</title>
		<link>http://www.tech21century.com/allowing-microsoft-pptp-through-cisco-asa/comment-page-1/#comment-18133</link>
		<dc:creator>Brad</dc:creator>
		<pubDate>Thu, 02 Feb 2012 03:34:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech21century.com/?p=894#comment-18133</guid>
		<description>thanks for the info! this pointed me in the right direction. I did need to run one more command to apply the policy to the interface on my ASA 5505 (ver. 8.2):

service-policy pptp_policy interface outside

I found that here: http://www.cisco.com/en/US/docs/security/asa/asa83/command/reference/i2.html#wp1761500</description>
		<content:encoded><![CDATA[<p>thanks for the info! this pointed me in the right direction. I did need to run one more command to apply the policy to the interface on my ASA 5505 (ver. 8.2):</p>
<p>service-policy pptp_policy interface outside</p>
<p>I found that here: <a href="http://www.cisco.com/en/US/docs/security/asa/asa83/command/reference/i2.html#wp1761500" rel="nofollow">http://www.cisco.com/en/US/docs/security/asa/asa83/command/reference/i2.html#wp1761500</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How To Configure AnyConnect SSL VPN on Cisco ASA 5500 by SF</title>
		<link>http://www.tech21century.com/how-to-configure-anyconnect-ssl-vpn-on-cisco-asa-5500/comment-page-1/#comment-17902</link>
		<dc:creator>SF</dc:creator>
		<pubDate>Mon, 23 Jan 2012 11:02:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech21century.com/?p=305#comment-17902</guid>
		<description>First of all big thank for maintaining very usefull site !!

As per my previous post, I have mentioned that Anyconnect has comaptibility issue with Kaspersky, after doing lots of googlings, I found a blog site where one of the users has mentioned that he/she manged to get around this by unchecking port 443 on Kaspersky port monitor settings. This of course did work for me too.
However still having issues when enabling Secure Desktop, which works fine when used with a workstation that doesn&#039;t have Kaspersky. 

The other biggest problem is when I upgraded ASA 8.4, I realised that NAT implementation has been changed. Following link explains this. 

[link not correct]

Also Cisco has announced a bug 

[link requires authentication]


The biggest problem I have currently is to authenticate users using active directory, which worked fine before the version upgrade. When I configure server address and try to test I get follwing error.

&quot;
Authentication test to host 192.168.xx.xx failed. Following error 
occured-

ERROR: Authentication Rejected: Memmory 
error &quot;

Following blog shows that some other users also have experienced this but mnaged to get around. However in my case I am still stuck therefore I would be great, if you could shed a light on this.
</description>
		<content:encoded><![CDATA[<p>First of all big thank for maintaining very usefull site !!</p>
<p>As per my previous post, I have mentioned that Anyconnect has comaptibility issue with Kaspersky, after doing lots of googlings, I found a blog site where one of the users has mentioned that he/she manged to get around this by unchecking port 443 on Kaspersky port monitor settings. This of course did work for me too.<br />
However still having issues when enabling Secure Desktop, which works fine when used with a workstation that doesn&#8217;t have Kaspersky. </p>
<p>The other biggest problem is when I upgraded ASA 8.4, I realised that NAT implementation has been changed. Following link explains this. </p>
<p>[link not correct]</p>
<p>Also Cisco has announced a bug </p>
<p>[link requires authentication]</p>
<p>The biggest problem I have currently is to authenticate users using active directory, which worked fine before the version upgrade. When I configure server address and try to test I get follwing error.</p>
<p>&#8221;<br />
Authentication test to host 192.168.xx.xx failed. Following error<br />
occured-</p>
<p>ERROR: Authentication Rejected: Memmory<br />
error &#8221;</p>
<p>Following blog shows that some other users also have experienced this but mnaged to get around. However in my case I am still stuck therefore I would be great, if you could shed a light on this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How To Configure AnyConnect SSL VPN on Cisco ASA 5500 by BlogAdmin</title>
		<link>http://www.tech21century.com/how-to-configure-anyconnect-ssl-vpn-on-cisco-asa-5500/comment-page-1/#comment-17849</link>
		<dc:creator>BlogAdmin</dc:creator>
		<pubDate>Fri, 20 Jan 2012 17:52:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech21century.com/?p=305#comment-17849</guid>
		<description>Shiva,
You can use AAA (Authentication Authorization Accounting) server to authenticate the VPN users. In this way you can enable Accounting on the AAA server which will give you all authentication logs.</description>
		<content:encoded><![CDATA[<p>Shiva,<br />
You can use AAA (Authentication Authorization Accounting) server to authenticate the VPN users. In this way you can enable Accounting on the AAA server which will give you all authentication logs.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How To Configure AnyConnect SSL VPN on Cisco ASA 5500 by Shiva</title>
		<link>http://www.tech21century.com/how-to-configure-anyconnect-ssl-vpn-on-cisco-asa-5500/comment-page-1/#comment-17840</link>
		<dc:creator>Shiva</dc:creator>
		<pubDate>Fri, 20 Jan 2012 03:09:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech21century.com/?p=305#comment-17840</guid>
		<description>Hi,

I have ASA Firewall and need to capture the VPN authentication logs/events on the firewall.
 
Currently these type of logs are not getting generated on the Firewall.
 
Can you please let me know what changes needs to be done on the firewall in order to capture these logs.</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>I have ASA Firewall and need to capture the VPN authentication logs/events on the firewall.</p>
<p>Currently these type of logs are not getting generated on the Firewall.</p>
<p>Can you please let me know what changes needs to be done on the firewall in order to capture these logs.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Allowing Microsoft PPTP through Cisco ASA by BlogAdmin</title>
		<link>http://www.tech21century.com/allowing-microsoft-pptp-through-cisco-asa/comment-page-1/#comment-17827</link>
		<dc:creator>BlogAdmin</dc:creator>
		<pubDate>Thu, 19 Jan 2012 13:50:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech21century.com/?p=894#comment-17827</guid>
		<description>Andrew,

In order for scenario 2 to work, you need a dedicated public IP which will be static nat to the inside server. Your problem shows that GRE does not pass from client (outside) to server inside. Only TCP port 1723 can pass from what you describe.</description>
		<content:encoded><![CDATA[<p>Andrew,</p>
<p>In order for scenario 2 to work, you need a dedicated public IP which will be static nat to the inside server. Your problem shows that GRE does not pass from client (outside) to server inside. Only TCP port 1723 can pass from what you describe.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Allowing Microsoft PPTP through Cisco ASA by Andrew</title>
		<link>http://www.tech21century.com/allowing-microsoft-pptp-through-cisco-asa/comment-page-1/#comment-17825</link>
		<dc:creator>Andrew</dc:creator>
		<pubDate>Thu, 19 Jan 2012 11:14:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech21century.com/?p=894#comment-17825</guid>
		<description>Hi BlogAmin,

thanks for the tutorial.I&#039;ve a problem with it.

I&#039;ve an ASA 5110 8.0(4) released. I&#039;m working on scenario 2. 
When i try to connect with the client, it contact the server, try to verify user and password and after 30second it reply with the message:

&lt;strong&gt;Error 806: a connection between your computer and the VPN server has been established but the VPN connection cannot be completed.  The most common cause for this is that there is at least one internet device between your computer and the VPN server is not configured to allow GRE protocol packets Verify that protocol 47 GRE is allowed on all personal firewall devices or routers.  if the problem persists, contact your administrator.&lt;/strong&gt;

If i try a telnet from client to server, on 1723 port, it work.

where i wrong?

Thanks</description>
		<content:encoded><![CDATA[<p>Hi BlogAmin,</p>
<p>thanks for the tutorial.I&#8217;ve a problem with it.</p>
<p>I&#8217;ve an ASA 5110 8.0(4) released. I&#8217;m working on scenario 2.<br />
When i try to connect with the client, it contact the server, try to verify user and password and after 30second it reply with the message:</p>
<p><strong>Error 806: a connection between your computer and the VPN server has been established but the VPN connection cannot be completed.  The most common cause for this is that there is at least one internet device between your computer and the VPN server is not configured to allow GRE protocol packets Verify that protocol 47 GRE is allowed on all personal firewall devices or routers.  if the problem persists, contact your administrator.</strong></p>
<p>If i try a telnet from client to server, on 1723 port, it work.</p>
<p>where i wrong?</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How To Configure AnyConnect SSL VPN on Cisco ASA 5500 by BlogAdmin</title>
		<link>http://www.tech21century.com/how-to-configure-anyconnect-ssl-vpn-on-cisco-asa-5500/comment-page-1/#comment-17778</link>
		<dc:creator>BlogAdmin</dc:creator>
		<pubDate>Mon, 16 Jan 2012 16:12:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech21century.com/?p=305#comment-17778</guid>
		<description>Hi SF,

unfortunately I have not encountered something similar before. Hope that someone can shed some light on this. Maybe there is a solution if you make Kaspersky to bypass checking of the active-x application that anyconnect ssl is downloading on the user&#039;s computer.</description>
		<content:encoded><![CDATA[<p>Hi SF,</p>
<p>unfortunately I have not encountered something similar before. Hope that someone can shed some light on this. Maybe there is a solution if you make Kaspersky to bypass checking of the active-x application that anyconnect ssl is downloading on the user&#8217;s computer.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How To Configure AnyConnect SSL VPN on Cisco ASA 5500 by SF</title>
		<link>http://www.tech21century.com/how-to-configure-anyconnect-ssl-vpn-on-cisco-asa-5500/comment-page-1/#comment-17772</link>
		<dc:creator>SF</dc:creator>
		<pubDate>Mon, 16 Jan 2012 11:16:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech21century.com/?p=305#comment-17772</guid>
		<description>After following the above configuration example, I manged to setup VPN on ASA, however when the remote PC was trying to establish the connection, it failed and ASA generated below log.


5 Jan 16 2012 09:28:11 722010    Group  User  IP  SVC Message: 16/ERROR: Failed to fully establish a connection to the secure gateway (proxy authentication, handshake, bad cert, etc.)..

However when tried with different PC it worked and reliased it was the Kaspersky AV was causing the issue.

As per the following link, Cisco recommends to remove AV but that is not the longer term solution. Therefore I wolud like to know whether anyone else has  come across this issue and whether there is a concrete resolution for this. 


http://www.cisco.com/en/US/docs/security/vpn_client/anyconnect/anyconnect25/administration/guide/ac08managemonitortbs.html</description>
		<content:encoded><![CDATA[<p>After following the above configuration example, I manged to setup VPN on ASA, however when the remote PC was trying to establish the connection, it failed and ASA generated below log.</p>
<p>5 Jan 16 2012 09:28:11 722010    Group  User  IP  SVC Message: 16/ERROR: Failed to fully establish a connection to the secure gateway (proxy authentication, handshake, bad cert, etc.)..</p>
<p>However when tried with different PC it worked and reliased it was the Kaspersky AV was causing the issue.</p>
<p>As per the following link, Cisco recommends to remove AV but that is not the longer term solution. Therefore I wolud like to know whether anyone else has  come across this issue and whether there is a concrete resolution for this. </p>
<p><a href="http://www.cisco.com/en/US/docs/security/vpn_client/anyconnect/anyconnect25/administration/guide/ac08managemonitortbs.html" rel="nofollow">http://www.cisco.com/en/US/docs/security/vpn_client/anyconnect/anyconnect25/administration/guide/ac08managemonitortbs.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on AVS4YOU Coupon Code by BlogAdmin</title>
		<link>http://www.tech21century.com/avs4you-coupon-code/comment-page-1/#comment-16710</link>
		<dc:creator>BlogAdmin</dc:creator>
		<pubDate>Thu, 15 Dec 2011 17:00:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech21century.com/?p=1360#comment-16710</guid>
		<description>Hi Sarah,

The software license is for one computer only, so it would be good for either your home computer or your laptop.</description>
		<content:encoded><![CDATA[<p>Hi Sarah,</p>
<p>The software license is for one computer only, so it would be good for either your home computer or your laptop.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on AVS4YOU Coupon Code by Sarah Wilkes</title>
		<link>http://www.tech21century.com/avs4you-coupon-code/comment-page-1/#comment-16692</link>
		<dc:creator>Sarah Wilkes</dc:creator>
		<pubDate>Thu, 15 Dec 2011 09:10:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech21century.com/?p=1360#comment-16692</guid>
		<description>Hello
I am new to video taking I have my home desktop $ the laptop IBM T-30,I know its old but I use this when I travel the back road and trails of the west USA. I would like to know if I buy your software I will put it on my home computer but would like it to also run when I am out on the road to proof my work so when I get home I can move the video and images to the home system and finish the work then publish them..

If I find that my thinkpad is too old to run your software I don&#039;t want to have a copy of you software I can&#039;t use.
If I can do this setup I would buy one copy of AVS software now</description>
		<content:encoded><![CDATA[<p>Hello<br />
I am new to video taking I have my home desktop $ the laptop IBM T-30,I know its old but I use this when I travel the back road and trails of the west USA. I would like to know if I buy your software I will put it on my home computer but would like it to also run when I am out on the road to proof my work so when I get home I can move the video and images to the home system and finish the work then publish them..</p>
<p>If I find that my thinkpad is too old to run your software I don&#8217;t want to have a copy of you software I can&#8217;t use.<br />
If I can do this setup I would buy one copy of AVS software now</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using disk: enhanced

Served from: www.tech21century.com @ 2012-02-04 12:25:05 -->
