<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: How To Configure AnyConnect SSL VPN on Cisco ASA 5500</title>
	<atom:link href="http://www.tech21century.com/how-to-configure-anyconnect-ssl-vpn-on-cisco-asa-5500/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.tech21century.com/how-to-configure-anyconnect-ssl-vpn-on-cisco-asa-5500/</link>
	<description>Technology in the 21st Century</description>
	<lastBuildDate>Mon, 06 Feb 2012 17:21:56 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: BlogAdmin</title>
		<link>http://www.tech21century.com/how-to-configure-anyconnect-ssl-vpn-on-cisco-asa-5500/comment-page-1/#comment-18255</link>
		<dc:creator>BlogAdmin</dc:creator>
		<pubDate>Mon, 06 Feb 2012 17:21:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech21century.com/?p=305#comment-18255</guid>
		<description>Hi Stella,

I have spotted two things:

1) Reverse the nat statement to the following:

nat (cust1,outside) source static obj_10.15.200.0 obj_10.15.200.0 destination static obj_10.15.202.0 obj_10.15.202.0

2) remove the inside route statement and make it more specific. Maybe this statement is not needed at all</description>
		<content:encoded><![CDATA[<p>Hi Stella,</p>
<p>I have spotted two things:</p>
<p>1) Reverse the nat statement to the following:</p>
<p>nat (cust1,outside) source static obj_10.15.200.0 obj_10.15.200.0 destination static obj_10.15.202.0 obj_10.15.202.0</p>
<p>2) remove the inside route statement and make it more specific. Maybe this statement is not needed at all</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stella</title>
		<link>http://www.tech21century.com/how-to-configure-anyconnect-ssl-vpn-on-cisco-asa-5500/comment-page-1/#comment-18236</link>
		<dc:creator>Stella</dc:creator>
		<pubDate>Mon, 06 Feb 2012 06:05:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech21century.com/?p=305#comment-18236</guid>
		<description>Hi,

Trying to get this working and just will not work!  I have Cisco Anyconnect SSL VPN and the client connects fine.  but cannot ping the default gateway 10.15.202.2.  From the ASA I cannot even ping the client who gets the 1st IP address out of the pool.  What am I doing wrong?  Cisco ASA 8.4.

I have sub interfaces on my inside network and the cust1 user needs access to 10.15.200.0/24

on ASDM logging I can see the connection being built and torn down..  just no connectivity???

The config I have:

asa-fw1# sh run

ASA Version 8.4(2)
!
hostname w1


!
interface GigabitEthernet0/0
description outside
nameif outside
security-level 0
ip address 204.xx.xxx.xx 255.255.255.248

interface TenGigabitEthernet0/8
no nameif
no security-level
no ip address
!
!
interface TenGigabitEthernet0/8.16
description Admin
vlan 16
nameif inside
security-level 100
ip address 10.15.16.1 255.255.255.248
!
interface TenGigabitEthernet0/8.200
description cust1
vlan 200
nameif cust1
security-level 20
ip address 10.15.200.1 255.255.255.0
!
!
interface TenGigabitEthernet0/9
shutdown
no nameif
no security-level
no ip address
!
ftp mode passive
dns server-group DefaultDNS
domain-name xxxxxxx.com
object network obj_10.15.202.0
subnet 10.15.202.0 255.255.255.0
object network obj_10.15.200.0
subnet 10.15.200.0 255.255.255.0

access-list Access_cust extended permit ip 10.15.200.0 255.255.255.0 object obj_10.15.202.0
pager lines 24
logging enable
logging buffered informational
logging asdm informational

mtu outside 1500
mtu inside 1500
mtu cust1 1500

ip local pool cust_address_pool 10.15.202.1-10.15.202.254 mask 255.255.255.0



icmp unreachable rate-limit 1 burst-size 1
icmp permit 10.15.202.0 255.255.255.248 outside
no asdm history enable
arp timeout 14400
nat (cust1,outside) source static obj_10.15.202.0 obj_10.15.202.0 destination static obj_10.15.200.0 obj_10.15.200.0


route outside 0.0.0.0 0.0.0.0 204.xx.xxx.xx 1
route inside 10.0.0.0 255.0.0.0 10.15.16.5 1

timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
timeout tcp-proxy-reassembly 0:01:00
timeout floating-conn 0:00:00
dynamic-access-policy-record DfltAccessPolicy
user-identity default-domain LOCAL
http server enable
http 10.0.0.0 255.0.0.0 inside
no snmp-server location
no snmp-server contact
telnet timeout 5
ssh 10.1.20.0 255.255.255.0 inside

ssh timeout 5
console timeout 0
vpn-sessiondb max-other-vpn-limit 10000
vpn-sessiondb max-anyconnect-premium-or-essentials-limit 4
!
tls-proxy maximum-session 1000
!
threat-detection basic-threat
threat-detection statistics access-list
no threat-detection statistics tcp-intercept
webvpn
enable outside
anyconnect image disk0:/anyconnect-win-2.5.3055-k9.pkg 1
anyconnect enable
tunnel-group-list enable
group-policy SSLClientPolicy internal
group-policy SSLClientPolicy attributes
dns-server value 10.1.1.25
vpn-filter value Access_cust
address-pools value cust_address_pool
group-policy DfltGrpPolicy attributes
dns-server value 10.1.1.25
vpn-tunnel-protocol ikev1 l2tp-ipsec ssl-client ssl-clientless
default-domain value xxxxxx.com

username admin password xxxxxxxxxxxxxxx encrypted
username cust1 password xxxxxxxxxxxxxxx encrypted
tunnel-group SSLClientProfile type remote-access
tunnel-group SSLClientProfile general-attributes
default-group-policy SSLClientPolicy
tunnel-group SSLClientProfile webvpn-attributes
group-alias SSLVPNClient enable
!
class-map inspection_default
match default-inspection-traffic
class-map default
!
!
policy-map type inspect dns migrated_dns_map_1
parameters
  message-length maximum client auto
  message-length maximum 512
policy-map global_policy
class inspection_default
  inspect dns migrated_dns_map_1
  inspect ftp
  inspect h323 h225
  inspect h323 ras
  inspect ip-options
  inspect netbios
  inspect rsh
  inspect rtsp
  inspect skinny
  inspect esmtp
  inspect sqlnet
  inspect sunrpc
  inspect tftp
  inspect sip
  inspect xdmcp
!
service-policy global_policy global
prompt priority state hostname
no call-home reporting anonymous
call-home
profile CiscoTAC-1
  no active
  destination address http https://tools.cisco.com/its/service/oddce/services/DDCEService
  destination address email callhome@cisco.com
  destination transport-method http
  subscribe-to-alert-group diagnostic
  subscribe-to-alert-group environment
  subscribe-to-alert-group inventory periodic monthly 11
  subscribe-to-alert-group configuration periodic monthly 11
  subscribe-to-alert-group telemetry periodic daily
Cryptochecksum:8038877e65c2884a7549f84fdb4c1ac0
: end



any thoughts?</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>Trying to get this working and just will not work!  I have Cisco Anyconnect SSL VPN and the client connects fine.  but cannot ping the default gateway 10.15.202.2.  From the ASA I cannot even ping the client who gets the 1st IP address out of the pool.  What am I doing wrong?  Cisco ASA 8.4.</p>
<p>I have sub interfaces on my inside network and the cust1 user needs access to 10.15.200.0/24</p>
<p>on ASDM logging I can see the connection being built and torn down..  just no connectivity???</p>
<p>The config I have:</p>
<p>asa-fw1# sh run</p>
<p>ASA Version 8.4(2)<br />
!<br />
hostname w1</p>
<p>!<br />
interface GigabitEthernet0/0<br />
description outside<br />
nameif outside<br />
security-level 0<br />
ip address 204.xx.xxx.xx 255.255.255.248</p>
<p>interface TenGigabitEthernet0/8<br />
no nameif<br />
no security-level<br />
no ip address<br />
!<br />
!<br />
interface TenGigabitEthernet0/8.16<br />
description Admin<br />
vlan 16<br />
nameif inside<br />
security-level 100<br />
ip address 10.15.16.1 255.255.255.248<br />
!<br />
interface TenGigabitEthernet0/8.200<br />
description cust1<br />
vlan 200<br />
nameif cust1<br />
security-level 20<br />
ip address 10.15.200.1 255.255.255.0<br />
!<br />
!<br />
interface TenGigabitEthernet0/9<br />
shutdown<br />
no nameif<br />
no security-level<br />
no ip address<br />
!<br />
ftp mode passive<br />
dns server-group DefaultDNS<br />
domain-name xxxxxxx.com<br />
object network obj_10.15.202.0<br />
subnet 10.15.202.0 255.255.255.0<br />
object network obj_10.15.200.0<br />
subnet 10.15.200.0 255.255.255.0</p>
<p>access-list Access_cust extended permit ip 10.15.200.0 255.255.255.0 object obj_10.15.202.0<br />
pager lines 24<br />
logging enable<br />
logging buffered informational<br />
logging asdm informational</p>
<p>mtu outside 1500<br />
mtu inside 1500<br />
mtu cust1 1500</p>
<p>ip local pool cust_address_pool 10.15.202.1-10.15.202.254 mask 255.255.255.0</p>
<p>icmp unreachable rate-limit 1 burst-size 1<br />
icmp permit 10.15.202.0 255.255.255.248 outside<br />
no asdm history enable<br />
arp timeout 14400<br />
nat (cust1,outside) source static obj_10.15.202.0 obj_10.15.202.0 destination static obj_10.15.200.0 obj_10.15.200.0</p>
<p>route outside 0.0.0.0 0.0.0.0 204.xx.xxx.xx 1<br />
route inside 10.0.0.0 255.0.0.0 10.15.16.5 1</p>
<p>timeout xlate 3:00:00<br />
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02<br />
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00<br />
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00<br />
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute<br />
timeout tcp-proxy-reassembly 0:01:00<br />
timeout floating-conn 0:00:00<br />
dynamic-access-policy-record DfltAccessPolicy<br />
user-identity default-domain LOCAL<br />
http server enable<br />
http 10.0.0.0 255.0.0.0 inside<br />
no snmp-server location<br />
no snmp-server contact<br />
telnet timeout 5<br />
ssh 10.1.20.0 255.255.255.0 inside</p>
<p>ssh timeout 5<br />
console timeout 0<br />
vpn-sessiondb max-other-vpn-limit 10000<br />
vpn-sessiondb max-anyconnect-premium-or-essentials-limit 4<br />
!<br />
tls-proxy maximum-session 1000<br />
!<br />
threat-detection basic-threat<br />
threat-detection statistics access-list<br />
no threat-detection statistics tcp-intercept<br />
webvpn<br />
enable outside<br />
anyconnect image disk0:/anyconnect-win-2.5.3055-k9.pkg 1<br />
anyconnect enable<br />
tunnel-group-list enable<br />
group-policy SSLClientPolicy internal<br />
group-policy SSLClientPolicy attributes<br />
dns-server value 10.1.1.25<br />
vpn-filter value Access_cust<br />
address-pools value cust_address_pool<br />
group-policy DfltGrpPolicy attributes<br />
dns-server value 10.1.1.25<br />
vpn-tunnel-protocol ikev1 l2tp-ipsec ssl-client ssl-clientless<br />
default-domain value xxxxxx.com</p>
<p>username admin password xxxxxxxxxxxxxxx encrypted<br />
username cust1 password xxxxxxxxxxxxxxx encrypted<br />
tunnel-group SSLClientProfile type remote-access<br />
tunnel-group SSLClientProfile general-attributes<br />
default-group-policy SSLClientPolicy<br />
tunnel-group SSLClientProfile webvpn-attributes<br />
group-alias SSLVPNClient enable<br />
!<br />
class-map inspection_default<br />
match default-inspection-traffic<br />
class-map default<br />
!<br />
!<br />
policy-map type inspect dns migrated_dns_map_1<br />
parameters<br />
  message-length maximum client auto<br />
  message-length maximum 512<br />
policy-map global_policy<br />
class inspection_default<br />
  inspect dns migrated_dns_map_1<br />
  inspect ftp<br />
  inspect h323 h225<br />
  inspect h323 ras<br />
  inspect ip-options<br />
  inspect netbios<br />
  inspect rsh<br />
  inspect rtsp<br />
  inspect skinny<br />
  inspect esmtp<br />
  inspect sqlnet<br />
  inspect sunrpc<br />
  inspect tftp<br />
  inspect sip<br />
  inspect xdmcp<br />
!<br />
service-policy global_policy global<br />
prompt priority state hostname<br />
no call-home reporting anonymous<br />
call-home<br />
profile CiscoTAC-1<br />
  no active<br />
  destination address http <a href="https://tools.cisco.com/its/service/oddce/services/DDCEService" rel="nofollow">https://tools.cisco.com/its/service/oddce/services/DDCEService</a><br />
  destination address email <a href="mailto:callhome@cisco.com">callhome@cisco.com</a><br />
  destination transport-method http<br />
  subscribe-to-alert-group diagnostic<br />
  subscribe-to-alert-group environment<br />
  subscribe-to-alert-group inventory periodic monthly 11<br />
  subscribe-to-alert-group configuration periodic monthly 11<br />
  subscribe-to-alert-group telemetry periodic daily<br />
Cryptochecksum:8038877e65c2884a7549f84fdb4c1ac0<br />
: end</p>
<p>any thoughts?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SF</title>
		<link>http://www.tech21century.com/how-to-configure-anyconnect-ssl-vpn-on-cisco-asa-5500/comment-page-1/#comment-17902</link>
		<dc:creator>SF</dc:creator>
		<pubDate>Mon, 23 Jan 2012 11:02:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech21century.com/?p=305#comment-17902</guid>
		<description>First of all big thank for maintaining very usefull site !!

As per my previous post, I have mentioned that Anyconnect has comaptibility issue with Kaspersky, after doing lots of googlings, I found a blog site where one of the users has mentioned that he/she manged to get around this by unchecking port 443 on Kaspersky port monitor settings. This of course did work for me too.
However still having issues when enabling Secure Desktop, which works fine when used with a workstation that doesn&#039;t have Kaspersky. 

The other biggest problem is when I upgraded ASA 8.4, I realised that NAT implementation has been changed. Following link explains this. 

[link not correct]

Also Cisco has announced a bug 

[link requires authentication]


The biggest problem I have currently is to authenticate users using active directory, which worked fine before the version upgrade. When I configure server address and try to test I get follwing error.

&quot;
Authentication test to host 192.168.xx.xx failed. Following error 
occured-

ERROR: Authentication Rejected: Memmory 
error &quot;

Following blog shows that some other users also have experienced this but mnaged to get around. However in my case I am still stuck therefore I would be great, if you could shed a light on this.
</description>
		<content:encoded><![CDATA[<p>First of all big thank for maintaining very usefull site !!</p>
<p>As per my previous post, I have mentioned that Anyconnect has comaptibility issue with Kaspersky, after doing lots of googlings, I found a blog site where one of the users has mentioned that he/she manged to get around this by unchecking port 443 on Kaspersky port monitor settings. This of course did work for me too.<br />
However still having issues when enabling Secure Desktop, which works fine when used with a workstation that doesn&#8217;t have Kaspersky. </p>
<p>The other biggest problem is when I upgraded ASA 8.4, I realised that NAT implementation has been changed. Following link explains this. </p>
<p>[link not correct]</p>
<p>Also Cisco has announced a bug </p>
<p>[link requires authentication]</p>
<p>The biggest problem I have currently is to authenticate users using active directory, which worked fine before the version upgrade. When I configure server address and try to test I get follwing error.</p>
<p>&#8221;<br />
Authentication test to host 192.168.xx.xx failed. Following error<br />
occured-</p>
<p>ERROR: Authentication Rejected: Memmory<br />
error &#8221;</p>
<p>Following blog shows that some other users also have experienced this but mnaged to get around. However in my case I am still stuck therefore I would be great, if you could shed a light on this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BlogAdmin</title>
		<link>http://www.tech21century.com/how-to-configure-anyconnect-ssl-vpn-on-cisco-asa-5500/comment-page-1/#comment-17849</link>
		<dc:creator>BlogAdmin</dc:creator>
		<pubDate>Fri, 20 Jan 2012 17:52:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech21century.com/?p=305#comment-17849</guid>
		<description>Shiva,
You can use AAA (Authentication Authorization Accounting) server to authenticate the VPN users. In this way you can enable Accounting on the AAA server which will give you all authentication logs.</description>
		<content:encoded><![CDATA[<p>Shiva,<br />
You can use AAA (Authentication Authorization Accounting) server to authenticate the VPN users. In this way you can enable Accounting on the AAA server which will give you all authentication logs.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shiva</title>
		<link>http://www.tech21century.com/how-to-configure-anyconnect-ssl-vpn-on-cisco-asa-5500/comment-page-1/#comment-17840</link>
		<dc:creator>Shiva</dc:creator>
		<pubDate>Fri, 20 Jan 2012 03:09:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech21century.com/?p=305#comment-17840</guid>
		<description>Hi,

I have ASA Firewall and need to capture the VPN authentication logs/events on the firewall.
 
Currently these type of logs are not getting generated on the Firewall.
 
Can you please let me know what changes needs to be done on the firewall in order to capture these logs.</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>I have ASA Firewall and need to capture the VPN authentication logs/events on the firewall.</p>
<p>Currently these type of logs are not getting generated on the Firewall.</p>
<p>Can you please let me know what changes needs to be done on the firewall in order to capture these logs.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BlogAdmin</title>
		<link>http://www.tech21century.com/how-to-configure-anyconnect-ssl-vpn-on-cisco-asa-5500/comment-page-1/#comment-17778</link>
		<dc:creator>BlogAdmin</dc:creator>
		<pubDate>Mon, 16 Jan 2012 16:12:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech21century.com/?p=305#comment-17778</guid>
		<description>Hi SF,

unfortunately I have not encountered something similar before. Hope that someone can shed some light on this. Maybe there is a solution if you make Kaspersky to bypass checking of the active-x application that anyconnect ssl is downloading on the user&#039;s computer.</description>
		<content:encoded><![CDATA[<p>Hi SF,</p>
<p>unfortunately I have not encountered something similar before. Hope that someone can shed some light on this. Maybe there is a solution if you make Kaspersky to bypass checking of the active-x application that anyconnect ssl is downloading on the user&#8217;s computer.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SF</title>
		<link>http://www.tech21century.com/how-to-configure-anyconnect-ssl-vpn-on-cisco-asa-5500/comment-page-1/#comment-17772</link>
		<dc:creator>SF</dc:creator>
		<pubDate>Mon, 16 Jan 2012 11:16:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech21century.com/?p=305#comment-17772</guid>
		<description>After following the above configuration example, I manged to setup VPN on ASA, however when the remote PC was trying to establish the connection, it failed and ASA generated below log.


5 Jan 16 2012 09:28:11 722010    Group  User  IP  SVC Message: 16/ERROR: Failed to fully establish a connection to the secure gateway (proxy authentication, handshake, bad cert, etc.)..

However when tried with different PC it worked and reliased it was the Kaspersky AV was causing the issue.

As per the following link, Cisco recommends to remove AV but that is not the longer term solution. Therefore I wolud like to know whether anyone else has  come across this issue and whether there is a concrete resolution for this. 


http://www.cisco.com/en/US/docs/security/vpn_client/anyconnect/anyconnect25/administration/guide/ac08managemonitortbs.html</description>
		<content:encoded><![CDATA[<p>After following the above configuration example, I manged to setup VPN on ASA, however when the remote PC was trying to establish the connection, it failed and ASA generated below log.</p>
<p>5 Jan 16 2012 09:28:11 722010    Group  User  IP  SVC Message: 16/ERROR: Failed to fully establish a connection to the secure gateway (proxy authentication, handshake, bad cert, etc.)..</p>
<p>However when tried with different PC it worked and reliased it was the Kaspersky AV was causing the issue.</p>
<p>As per the following link, Cisco recommends to remove AV but that is not the longer term solution. Therefore I wolud like to know whether anyone else has  come across this issue and whether there is a concrete resolution for this. </p>
<p><a href="http://www.cisco.com/en/US/docs/security/vpn_client/anyconnect/anyconnect25/administration/guide/ac08managemonitortbs.html" rel="nofollow">http://www.cisco.com/en/US/docs/security/vpn_client/anyconnect/anyconnect25/administration/guide/ac08managemonitortbs.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BlogAdmin</title>
		<link>http://www.tech21century.com/how-to-configure-anyconnect-ssl-vpn-on-cisco-asa-5500/comment-page-1/#comment-15320</link>
		<dc:creator>BlogAdmin</dc:creator>
		<pubDate>Mon, 17 Oct 2011 05:37:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech21century.com/?p=305#comment-15320</guid>
		<description>Hello,
 
From 8.3 ASA version and later, Cisco has changed how NAT is configured. Because I don&#039;t have time to put a full configuration again, try to find how to use &quot;nat 0&quot; on version 8.4 and just substitute this to the config above.</description>
		<content:encoded><![CDATA[<p>Hello,</p>
<p>From 8.3 ASA version and later, Cisco has changed how NAT is configured. Because I don&#8217;t have time to put a full configuration again, try to find how to use &#8220;nat 0&#8243; on version 8.4 and just substitute this to the config above.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: asa_newb</title>
		<link>http://www.tech21century.com/how-to-configure-anyconnect-ssl-vpn-on-cisco-asa-5500/comment-page-1/#comment-15314</link>
		<dc:creator>asa_newb</dc:creator>
		<pubDate>Sun, 16 Oct 2011 22:40:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech21century.com/?p=305#comment-15314</guid>
		<description>Can someone please post the full how to config an ASA 5505 with Anyconnect on version 8.4(1) or change this how to for 8.4(1).  I am new and would like to get this ASA up and running ASAP.  

Error I get:
nat (inside) 0 access-list NONAT
ERROR: This syntax of nat command has been deprecated.
Please refer to &quot;help nat&quot; command for more details.

Thanks in advance.</description>
		<content:encoded><![CDATA[<p>Can someone please post the full how to config an ASA 5505 with Anyconnect on version 8.4(1) or change this how to for 8.4(1).  I am new and would like to get this ASA up and running ASAP.  </p>
<p>Error I get:<br />
nat (inside) 0 access-list NONAT<br />
ERROR: This syntax of nat command has been deprecated.<br />
Please refer to &#8220;help nat&#8221; command for more details.</p>
<p>Thanks in advance.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: alf</title>
		<link>http://www.tech21century.com/how-to-configure-anyconnect-ssl-vpn-on-cisco-asa-5500/comment-page-1/#comment-15084</link>
		<dc:creator>alf</dc:creator>
		<pubDate>Sun, 25 Sep 2011 19:41:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.tech21century.com/?p=305#comment-15084</guid>
		<description>Hi to everyone who&#039;s reading this blog. Go get that ASA book from blogadmin, no questions asked! It has helped me tremendeous, i am now working remote into my home network from miles away! Those exampels does work, if you are following them.

cheers.
/alf</description>
		<content:encoded><![CDATA[<p>Hi to everyone who&#8217;s reading this blog. Go get that ASA book from blogadmin, no questions asked! It has helped me tremendeous, i am now working remote into my home network from miles away! Those exampels does work, if you are following them.</p>
<p>cheers.<br />
/alf</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using disk: enhanced

Served from: www.tech21century.com @ 2012-02-10 09:17:55 -->
