<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	
	xmlns:georss="http://www.georss.org/georss"
	xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#"
	>

<channel>
	<title>SSL Archives - Think Netsec</title>
	<atom:link href="https://www.thinknetsec.com/tag/ssl/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.thinknetsec.com/tag/ssl/</link>
	<description>Think Network Security</description>
	<lastBuildDate>Thu, 10 Aug 2017 03:55:40 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.7.1</generator>

<image>
	<url>https://www.thinknetsec.com/wp-content/uploads/2017/08/cropped-ThinkNetsec-Full-Logo-1-32x32.png</url>
	<title>SSL Archives - Think Netsec</title>
	<link>https://www.thinknetsec.com/tag/ssl/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">133674323</site>	<item>
		<title>Anyconnect SBL (Start Before Logon)</title>
		<link>https://www.thinknetsec.com/anyconnect-sbl-start-before-logon/</link>
					<comments>https://www.thinknetsec.com/anyconnect-sbl-start-before-logon/#respond</comments>
		
		<dc:creator><![CDATA[John Finnegan]]></dc:creator>
		<pubDate>Wed, 02 Aug 2017 20:06:52 +0000</pubDate>
				<category><![CDATA[ASA]]></category>
		<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[AnyConnect]]></category>
		<category><![CDATA[SBL]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[VPN]]></category>
		<guid isPermaLink="false">http://34.230.49.182/?p=84</guid>

					<description><![CDATA[<p>AnyConnect SBL is to allow users to connect to the VPN before signing into their Laptop/Desktop. This is useful for companies that want all of their Laptops to use Active Directory to sign into the laptop but need a secure way to reach the AD Server. AnyConnect SBL Requirements Must<a class="moretag" href="https://www.thinknetsec.com/anyconnect-sbl-start-before-logon/"> Read more&#8230;</a></p>
<p>The post <a href="https://www.thinknetsec.com/anyconnect-sbl-start-before-logon/">Anyconnect SBL (Start Before Logon)</a> appeared first on <a href="https://www.thinknetsec.com">Think Netsec</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>AnyConnect SBL is to allow users to connect to the VPN before signing into their Laptop/Desktop. This is useful for companies that want all of their Laptops to use Active Directory to sign into the laptop but need a secure way to reach the AD Server.</p>
<h1 id="StartBeforeLogonwithAnyConnectclient-Requirements">AnyConnect SBL Requirements</h1>
<ul>
<li>Must be using the AnyConnect client and the user must be using a Windows 7 or XP machine. This does not work with 8+ from what I have tested.</li>
</ul>
<h1 id="StartBeforeLogonwithAnyConnectclient-Instructions">Instructions</h1>
<ol>
<li><span class="confluence-link">Create the default configuration for the AnyConnect VPN</span>.<br />
<strong><img decoding="async" class="alignnone size-full wp-image-167" src="http://www.thinknetsec.com/wp-content/uploads/2017/08/information.png" alt="" width="16" height="16" />Note:</strong> If you plan on using a Self Signed Certificate the FQDN must be the IP of the firewall or the customer must setup a DNS entry for the FQDN.</li>
<li>Upload the <em>SBL.xml</em> page to the firewall.<br />
The key thing to change is the value between the <em>&lt;UseStartBeforeLogon&gt;</em> to <em>true</em>. If you are currently using a xml profile, you can also edit this line, or add, for this configuration to work.</p>
<div class="code panel pdl">
<div class="codeHeader panelHeader pdl hide-border-bottom"><b class=" code-title">SBL XML</b> <span class="collapse-source expand-control"><span class="collapse-source expand-control"><span class="expand-control-text">file:<br />
<div id="accordions-138" class="accordions-138 accordions" data-accordions={&quot;lazyLoad&quot;:false,&quot;id&quot;:&quot;138&quot;,&quot;event&quot;:&quot;click&quot;,&quot;collapsible&quot;:&quot;true&quot;,&quot;heightStyle&quot;:&quot;content&quot;,&quot;animateStyle&quot;:&quot;swing&quot;,&quot;animateDelay&quot;:1000,&quot;navigation&quot;:true,&quot;active&quot;:999,&quot;expandedOther&quot;:&quot;no&quot;}>
                <div class="items" >
    
            <div post_id="138" itemcount="0"  header_id="header-1501812234657" id="header-1501812234657" style="" class="accordions-head head1501812234657 border-none" toggle-text="" main-text="SignOn.xml">
                                    <span id="accordion-icons-1501812234657" class="accordion-icons">
                        <span class="accordion-icon-active accordion-plus"><i class="fa fa-chevron-up"></i></span>
                        <span class="accordion-icon-inactive accordion-minus"><i class="fa fa-chevron-down"></i></span>
                    </span>
                    <span id="header-text-1501812234657" class="accordions-head-title">SignOn.xml</span>
                            </div>
            <div class="accordion-content content1501812234657 ">
                <pre><?xml version="1.0" encoding="UTF-8"?>
<AnyConnectProfile xmlns="http://schemas.xmlsoap.org/encoding/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://schemas.xmlsoap.org/encoding/ AnyConnectProfile.xsd">
<ClientInitialization>
<UseStartBeforeLogon UserControllable="true">true</UseStartBeforeLogon>
<AutomaticCertSelection UserControllable="true">true</AutomaticCertSelection>
<ShowPreConnectMessage>false</ShowPreConnectMessage>
<CertificateStore>All</CertificateStore>
<CertificateStoreOverride>false</CertificateStoreOverride>
<ProxySettings>Native</ProxySettings>
<AllowLocalProxyConnections>false</AllowLocalProxyConnections>
<AuthenticationTimeout>12</AuthenticationTimeout>
<AutoConnectOnStart UserControllable="true">false</AutoConnectOnStart>
<MinimizeOnConnect UserControllable="true">true</MinimizeOnConnect>
<LocalLanAccess UserControllable="true">false</LocalLanAccess>
<ClearSmartcardPin UserControllable="true">true</ClearSmartcardPin>
<IPProtocolSupport>IPv4,IPv6</IPProtocolSupport>
<AutoReconnect UserControllable="false">true
<AutoReconnectBehavior UserControllable="false">DisconnectOnSuspend</AutoReconnectBehavior>
</AutoReconnect>
<AutoUpdate UserControllable="false">true</AutoUpdate>
<RSASecurIDIntegration UserControllable="false">Automatic</RSASecurIDIntegration>
<WindowsLogonEnforcement>SingleLocalLogon</WindowsLogonEnforcement>
<WindowsVPNEstablishment>LocalUsersOnly</WindowsVPNEstablishment>
<AutomaticVPNPolicy>false</AutomaticVPNPolicy>
<PPPExclusion UserControllable="false">Automatic
<PPPExclusionServerIP UserControllable="false"></PPPExclusionServerIP>
</PPPExclusion>
<EnableScripting UserControllable="false">false</EnableScripting>
<EnableAutomaticServerSelection UserControllable="true">false
<AutoServerSelectionImprovement>20</AutoServerSelectionImprovement>
<AutoServerSelectionSuspendTime>4</AutoServerSelectionSuspendTime>
</EnableAutomaticServerSelection>
<RetainVpnOnLogoff>false
</RetainVpnOnLogoff>
</ClientInitialization>
</AnyConnectProfile></pre>
            </div>
    </div>



            </div></span></span></span></div>
<div class="codeContent panelContent pdl hide-toolbar show-border-top"></div>
</div>
</li>
<li>Add the <em>SBL.xml</em> file to the webvpn settings.
<div class="code panel pdl">
<div class="codeContent panelContent pdl">
<div id="highlighter_456445" class="syntaxhighlighter nogutter text">
<table border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td class="code">
<div class="container" title="Hint: double-click to select code">
<div class="container" title="Hint: double-click to select code">
<div class="container" title="Hint: double-click to select code">
<div class="line number2 index1 alt1">
<p>ASA 8.x Code<br />
<code>webvpn</code><br />
<code>svc profiles SBL disk0:/SBL.xml</code></p>
<p>ASA 9.x Code<br />
<code>webvpn</code><code><br />
anyconnect profiles SignOn disk0:/SBL.xml</code></p>
</div>
</div>
</div>
</div>
<div class="container" title="Hint: double-click to select code"></div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</li>
<li>Add this profile along with the <em>vpngina</em> module to that group-policy that you applied to your AnyConnect VPN tunnel-group.
<div class="code panel pdl">
<div class="codeContent panelContent pdl">
<div>
<div id="highlighter_269549" class="syntaxhighlighter nogutter text">
<table border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td class="code">
<div></div>
<div>ASA 8.x Code</div>
<div class="container" title="Hint: double-click to select code">
<div class="container" title="Hint: double-click to select code">
<div class="line number1 index0 alt2">
<table border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td class="code">
<div class="container" title="Hint: double-click to select code">
<div class="line number1 index0 alt2"><code class="text plain">group-policy &lt;groupname&gt; attributes</code></div>
<div class="line number2 index1 alt1"><code class="text plain">webvpn</code></div>
<div class="line number3 index2 alt2"><code class="text plain">svc modules value vpngina</code></div>
<div class="line number4 index3 alt1"><code class="text plain">svc profiles value SignOn</code></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
<div class="line number4 index3 alt1">ASA 9.x Code</div>
</div>
</div>
<div class="container" title="Hint: double-click to select code">
<div class="line number4 index3 alt1">
<table border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td class="code">
<div class="container" title="Hint: double-click to select code">
<div class="line number1 index0 alt2"><code class="text plain">group-policy &lt;groupname&gt; attributes</code></div>
<div class="line number2 index1 alt1"><code class="text plain">webvpn</code></div>
<div class="line number3 index2 alt2"><code class="text plain">anyconnect modules value vpngina</code></div>
<div class="line number4 index3 alt1"><code class="text plain">anyconnect profiles value SBL</code></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
</li>
<li>Connect to the VPN as a new session to make sure that your new profile gets pushed from the Firewall.</li>
<li>If you used an Authorized Certificate &#8211; proceed to step 8, otherwise, follow step 9 for Self Signed Certificates</li>
<li>
<h4 id="StartBeforeLogonwithAnyConnectclient-SelfSignedCertificatesteps">Self Signed Certificate steps</h4>
<ol>
<li>Go to https://&lt;Firewall IP&gt;</li>
<li>Click on the <em>Lock</em> icon in the URL. Click <em>more information</em> then click <em>view certificate</em>.</li>
<li>Go to the <em>details</em> tab and click <em>export</em>. Save it as a X.509 certificate with chain (PEM) (*.crt,*.pem).</li>
<li>Run <em>Microsoft Management Console</em>, by entering &#8220;<em>mmc&#8221;</em> in the <em>run</em> or <em>search</em> box (requires administrator permissions).</li>
<li>In the <em>MMC</em> utility go to <em>file</em> and click on <em>add/remove snap-in</em>.</li>
<li>You will want to add the <em>certificates</em> snap, and set it to <em>computer</em> then <em>local computer</em>.</li>
<li>Open <em>trusted root certificates</em> and right click on <em>certificates</em> and click <em>import</em>.</li>
<li>Locate the file you saved earlier, then import that file.</li>
<li>Save the configuration. The name doesn&#8217;t matter.</li>
</ol>
</li>
<li>Reboot the machine. Once rebooted you can click on switch users and see the following icon:<br />
<h1 id="StartBeforeLogonwithAnyConnectclient-Requirements"><img decoding="async" class="alignnone size-full wp-image-166" src="http://www.thinknetsec.com/wp-content/uploads/2017/08/SBL_button.jpg" alt="" width="255" height="168" /></h1>
</li>
<li>Use this button to login to the VPN before logging into the OS.</li>
</ol>
<p>&nbsp;</p>
<p>The post <a href="https://www.thinknetsec.com/anyconnect-sbl-start-before-logon/">Anyconnect SBL (Start Before Logon)</a> appeared first on <a href="https://www.thinknetsec.com">Think Netsec</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.thinknetsec.com/anyconnect-sbl-start-before-logon/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">84</post-id>	</item>
	</channel>
</rss>
