Cisco 5505 Administration Guide - Page 24

In Response to a Microsoft Internet Explorer Security Alert Window - show connected vpn

Page 24 highlights

Before You Install the AnyConnect Client Chapter 2 Common AnyConnect VPN Client Installation and Configuration Procedures Recommendation: Administrators should import the root certificate that was used to sign that server certificate (for example, their own certificate authority or cacert.org) into every client machine out of band via E-mail, website, floppy disk, and so on. • Scenario B: The user gets the server certificate for the security appliance from the certificate authority that sits on the security appliance. The user sees the Security Alert pop-up on the first connection attempt but never thereafter until he or she switches to a different security appliance and back. Recommendation: Administrators should import the root certificate of the certificate authority that sits on the security appliance into every client machine out of band via E-mail, website, floppy disk, and so on. • Scenario C: the security appliance is at default configuration and certificates haven't been configured. When at default, the security appliance generates a self-signed server certificate that the AnyConnect client does not trust. The user sees the Security Alert pop-up on the first connection attempt but never thereafter until he or she switches to a different security appliance and back. Recommendation: Administrators should correctly configure certificates on their security appliance before attempting client connections to them. In Response to a Microsoft Internet Explorer "Security Alert" Window The following procedure explains how to install a self-signed certificate as a trusted root certificate on a client in response to a Microsoft Internet Explorer Security Alert window. This window opens when you establish a Microsoft Internet Explorer connection to a security appliance that is not recognized as a trusted site. The upper half of the Security Alert window shows the following text: Information you exchange with this site cannot be viewed or changed by others. However, there is a problem with the site's security certificate. The security certificate was issued by a company you have not chosen to trust. View the certificate to determine whether you want to trust the certifying authority. Install the certificate as a trusted root certificate as follows: Step 1 Step 2 Step 3 Step 4 Step 5 Step 6 Step 7 Step 8 Click View Certificate in the Security Alert window. The Certificate window opens. Click Install Certificate. The Certificate Import Wizard Welcome opens. Click Next. The Certificate Import Wizard - Certificate Store window opens. Select "Automatically select the certificate store based on the type of certificate." Click Next. The Certificate Import Wizard - Completing window opens. Click Finish. Another Security Warning window prompts "Do you want to install this certificate?" Click Yes. The Certificate Import Wizard window indicates the import is successful. Click OK to close this window. Cisco AnyConnect VPN Client Administrator Guide 2-6 OL-12950-012

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118

2-6
Cisco AnyConnect VPN Client Administrator Guide
OL-12950-012
Chapter 2
Common AnyConnect VPN Client Installation and Configuration Procedures
Before You Install the AnyConnect Client
Recommendation: Administrators should import the root certificate that was used to sign that server
certificate (for example, their own certificate authority or cacert.org) into every client machine out
of band via E-mail, website, floppy disk, and so on.
Scenario B
: The user gets the server certificate for the security appliance from the certificate
authority that sits on the security appliance.
The user sees the Security Alert pop-up on the first connection attempt but never thereafter until he
or she switches to a different security appliance and back.
Recommendation: Administrators should import the root certificate of the certificate authority that
sits on the security appliance into every client machine out of band via E-mail, website, floppy disk,
and so on.
Scenario C
: the security appliance is at default configuration and certificates haven't been
configured.
When at default, the security appliance generates a self-signed server certificate that the
AnyConnect client does not trust.
The user sees the Security Alert pop-up on the first connection attempt but never thereafter until he
or she switches to a different security appliance and back.
Recommendation: Administrators should correctly configure certificates on their security appliance
before attempting client connections to them.
In Response to a Microsoft Internet Explorer “Security Alert” Window
The following procedure explains how to install a self-signed certificate as a trusted root certificate on
a client in response to a Microsoft Internet Explorer Security Alert window. This window opens when
you establish a Microsoft Internet Explorer connection to a security appliance that is not recognized as
a trusted site. The upper half of the Security Alert window shows the following text:
Information you exchange with this site cannot be viewed or changed by others.
However, there is a problem with the site's security certificate. The security
certificate was issued by a company you have not chosen to trust. View the certificate
to determine whether you want to trust the certifying authority.
Install the certificate as a trusted root certificate as follows:
Step 1
Click View Certificate in the Security Alert window.
The Certificate window opens.
Step 2
Click Install Certificate.
The Certificate Import Wizard Welcome opens.
Step 3
Click Next.
The Certificate Import Wizard – Certificate Store window opens.
Step 4
Select “Automatically select the certificate store based on the type of certificate.”
Step 5
Click Next.
The Certificate Import Wizard – Completing window opens.
Step 6
Click Finish.
Step 7
Another Security Warning window prompts “Do you want to install this certificate?” Click Yes.
The Certificate Import Wizard window indicates the import is successful.
Step 8
Click OK to close this window.