Cisco AnyConnect VPN Client SSL for linux;

View: New views
7 Messages — Rating Filter:   Alert me  

Cisco AnyConnect VPN Client SSL for linux;

by R. DuFresne :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1




This might be slightly off topic, perhaps not.


Does anyone know of a linux client for the Cisco AnyConnect VPN Client SSL
tool?  Prefer one not redhat specific, we use slackware.


Thanks,

Ron DuFresne
- --
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         admin & senior security consultant:  sysinfo.com
                         http://sysinfo.com
Key fingerprint = 9401 4B13 B918 164C 647A  E838 B2DF AFCC 94B0 6629

These things happened. They were glorious and they changed the world...,
and then we fucked up the endgame.    --Charlie Wilson
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)

iD8DBQFKwsTUst+vzJSwZikRAv3GAJsGTCrYxcSzzgTSBNabiSVhGOfJSACeOg5T
qCIgew91ej1VTB6u4wV2LQ0=
=zpP2
-----END PGP SIGNATURE-----
_______________________________________________
firewall-wizards mailing list
firewall-wizards@...
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

Re: Cisco AnyConnect VPN Client SSL for linux;

by Josh Ward :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Hey Ron,

Cisco provides an AnyConnect client that works great under linux.  You
have to upload the image to your ASA/Pix and set it up in the webvpn
configuration.

It works great under Ubuntu and Redhat.  We haven't tested it under
Slackware but it should download and install just fine.

-Josh

R. DuFresne wrote:

> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
>
>
>
> This might be slightly off topic, perhaps not.
>
>
> Does anyone know of a linux client for the Cisco AnyConnect VPN Client SSL
> tool?  Prefer one not redhat specific, we use slackware.
>
>
> Thanks,
>
> Ron DuFresne
> - --
> ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
>         admin & senior security consultant:  sysinfo.com
>                         http://sysinfo.com
> Key fingerprint = 9401 4B13 B918 164C 647A  E838 B2DF AFCC 94B0 6629
>
> These things happened. They were glorious and they changed the world...,
> and then we fucked up the endgame.    --Charlie Wilson
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.5 (GNU/Linux)
>
> iD8DBQFKwsTUst+vzJSwZikRAv3GAJsGTCrYxcSzzgTSBNabiSVhGOfJSACeOg5T
> qCIgew91ej1VTB6u4wV2LQ0=
> =zpP2
> -----END PGP SIGNATURE-----
> _______________________________________________
> firewall-wizards mailing list
> firewall-wizards@...
> https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
>
_______________________________________________
firewall-wizards mailing list
firewall-wizards@...
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

Re: Cisco AnyConnect VPN Client SSL for linux;

by Harry Hoffman :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

OpenConnect

R. DuFresne wrote:

> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
>
>
>
> This might be slightly off topic, perhaps not.
>
>
> Does anyone know of a linux client for the Cisco AnyConnect VPN Client SSL
> tool?  Prefer one not redhat specific, we use slackware.
>
>
> Thanks,
>
> Ron DuFresne
> - --
> ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
>         admin & senior security consultant:  sysinfo.com
>                         http://sysinfo.com
> Key fingerprint = 9401 4B13 B918 164C 647A  E838 B2DF AFCC 94B0 6629
>
> These things happened. They were glorious and they changed the world...,
> and then we fucked up the endgame.    --Charlie Wilson
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.5 (GNU/Linux)
>
> iD8DBQFKwsTUst+vzJSwZikRAv3GAJsGTCrYxcSzzgTSBNabiSVhGOfJSACeOg5T
> qCIgew91ej1VTB6u4wV2LQ0=
> =zpP2
> -----END PGP SIGNATURE-----
> _______________________________________________
> firewall-wizards mailing list
> firewall-wizards@...
> https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
>
_______________________________________________
firewall-wizards mailing list
firewall-wizards@...
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

Re: Cisco AnyConnect VPN Client SSL for linux;

by ArkanoiD :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

IIRC it is basically openvpn with several broken DTLS headers. There was a patch
that enables "cisco-compatible" mode in openvpn.

On Tue, Sep 29, 2009 at 10:39:13PM -0400, R. DuFresne wrote:

> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
>
>
>
> This might be slightly off topic, perhaps not.
>
>
> Does anyone know of a linux client for the Cisco AnyConnect VPN Client SSL
> tool?  Prefer one not redhat specific, we use slackware.
>
>
> Thanks,
>
> Ron DuFresne
> - --

_______________________________________________
firewall-wizards mailing list
firewall-wizards@...
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

Re: Cisco AnyConnect VPN Client SSL for linux;

by Farrukh Haroon :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Slackware is officially supported, please have a look at the following table:

http://www.cisco.com/en/US/docs/security/asa/compatibility/vpn-platforms-82.html#wp126681

Also have a look at the 'linux requirements' section in the release notes:

http://www.cisco.com/en/US/docs/security/vpn_client/anyconnect/anyconnect23/release/notes/anyconnect23rn.html#wp949967

This is the download page:

http://tools.cisco.com/support/downloads/go/Model.x?mdfid=281278373&mdfLevel=Software%20Version/Option&treeName=Security&modelName=Cisco%20AnyConnect%20VPN%20Client%20v2.x&treeMdfId=268438162

Regards

Farrukh Haroon
CCIE Security (#20184)

On Wed, Sep 30, 2009 at 5:39 AM, R. DuFresne <dufresne@...> wrote:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1




This might be slightly off topic, perhaps not.


Does anyone know of a linux client for the Cisco AnyConnect VPN Client SSL
tool?  Prefer one not redhat specific, we use slackware.


Thanks,

Ron DuFresne
- --
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
       admin & senior security consultant:  sysinfo.com
                       http://sysinfo.com
Key fingerprint = 9401 4B13 B918 164C 647A  E838 B2DF AFCC 94B0 6629

These things happened. They were glorious and they changed the world...,
and then we fucked up the endgame.    --Charlie Wilson
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)

iD8DBQFKwsTUst+vzJSwZikRAv3GAJsGTCrYxcSzzgTSBNabiSVhGOfJSACeOg5T
qCIgew91ej1VTB6u4wV2LQ0=
=zpP2
-----END PGP SIGNATURE-----
_______________________________________________
firewall-wizards mailing list
firewall-wizards@...
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


_______________________________________________
firewall-wizards mailing list
firewall-wizards@...
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

Re: Cisco AnyConnect VPN Client SSL for linux;

by R. DuFresne :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Thanks all, looking over openvpn now.  So to get it to work with cisco I
need a patch that kinda breaks it?

I'm not seeing a link for a patch, anyone have such?

Thanks,

Ron DuFresne


On Thu, 1 Oct 2009, ArkanoiD wrote:

> IIRC it is basically openvpn with several broken DTLS headers. There was a patch
> that enables "cisco-compatible" mode in openvpn.
>
> On Tue, Sep 29, 2009 at 10:39:13PM -0400, R. DuFresne wrote:
>> -----BEGIN PGP SIGNED MESSAGE-----
>> Hash: SHA1
>>
>>
>>
>>
>> This might be slightly off topic, perhaps not.
>>
>>
>> Does anyone know of a linux client for the Cisco AnyConnect VPN Client SSL
>> tool?  Prefer one not redhat specific, we use slackware.
>>
>>
>> Thanks,
>>
>> Ron DuFresne
>> - --
>
> _______________________________________________
> firewall-wizards mailing list
> firewall-wizards@...
> https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
>

- --
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         admin & senior security consultant:  sysinfo.com
                         http://sysinfo.com
Key fingerprint = 9401 4B13 B918 164C 647A  E838 B2DF AFCC 94B0 6629

These things happened. They were glorious and they changed the world...,
and then we fucked up the endgame.    --Charlie Wilson
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)

iD8DBQFKxkY7st+vzJSwZikRAsB6AKC5oVz0LcfEosnEzbiTTGugTcUybgCfTE7z
eayl5NLylgH+pMWvOMaKWJc=
=jM5s
-----END PGP SIGNATURE-----
_______________________________________________
firewall-wizards mailing list
firewall-wizards@...
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

Re: Cisco AnyConnect VPN Client SSL for linux;

by ArkanoiD :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Seems that it is buried deep somewhere on the internet, as i cannot google it out anymore -
too many non-relevant pages with same keywords :-(

But there is a separate product:

http://www.infradead.org/openconnect.html

I think i can find out the original patch later - i've sent it to a friend and he says it
still should be somewhere on his work computer, so he will check if it is there
after this weekend.

On Fri, Oct 02, 2009 at 02:28:09PM -0400, R. DuFresne wrote:

> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
>
> Thanks all, looking over openvpn now.  So to get it to work with cisco I
> need a patch that kinda breaks it?
>
> I'm not seeing a link for a patch, anyone have such?
>
> Thanks,
>
> Ron DuFresne
>
>
> On Thu, 1 Oct 2009, ArkanoiD wrote:
>
> >IIRC it is basically openvpn with several broken DTLS headers. There was a
> >patch
> >that enables "cisco-compatible" mode in openvpn.
> >
> >On Tue, Sep 29, 2009 at 10:39:13PM -0400, R. DuFresne wrote:
> >>-----BEGIN PGP SIGNED MESSAGE-----
> >>Hash: SHA1
> >>
> >>
> >>
> >>
> >>This might be slightly off topic, perhaps not.
> >>
> >>
> >>Does anyone know of a linux client for the Cisco AnyConnect VPN Client SSL
> >>tool?  Prefer one not redhat specific, we use slackware.
> >>
> >>
> >>Thanks,
> >>
> >>Ron DuFresne
> >>- --
> >
> >_______________________________________________
> >firewall-wizards mailing list
> >firewall-wizards@...
> >https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
> >
>
> - --
> ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
>         admin & senior security consultant:  sysinfo.com
>                         http://sysinfo.com
> Key fingerprint = 9401 4B13 B918 164C 647A  E838 B2DF AFCC 94B0 6629
>
> These things happened. They were glorious and they changed the world...,
> and then we fucked up the endgame.    --Charlie Wilson
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.5 (GNU/Linux)
>
> iD8DBQFKxkY7st+vzJSwZikRAsB6AKC5oVz0LcfEosnEzbiTTGugTcUybgCfTE7z
> eayl5NLylgH+pMWvOMaKWJc=
> =jM5s
> -----END PGP SIGNATURE-----
>
> email protected and scanned by AdvascanTM - keeping email useful -
> www.advascan.com
>

_______________________________________________
firewall-wizards mailing list
firewall-wizards@...
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards