Astaro security gateway and ical invitations

When I want to reply to an ical invitation from an iCal server behind an Astaro Security Gateway, it's blocked by the Astaro. error 550: address unknown. I can understand that the astaro doesn't like addresses like [email protected]
Has anyone experience with Astaro gateways? Before I take it up with Astaro I want to know what other options I have. I don't know if it's possible to do some regex on the address, or filter by some unique header.
I do not manage the box. I'm just looking for information to provide to the people who do the support.
Help much appreciated.
Server OS 10.6.4

Hi
QM = Quick Mode = Phase 2.
Phase 1 is either Main Mode or aggresive mode.
So by the fact it is getting to QM that suggests phase 1 is working. What you do see if you do a "sh crypto isa sa" on the ASA ?
Can you check the phase 2 settings to ensure they match ie.
1) check your crypto map access-list and make sure that the local and remote subnet you have on your ASA matches the Astaro local and remote subnets
2) Explicitly set PFS in phase 2 and get them to do the same on the Astaro firewall.
HTH
Jon

Similar Messages

  • Astaro security gateway detects Virus in 3.6.6 from indiana.edu site

    Astator gateway reports - The item you have requested is infected by virus. It will not download.
    The gateway does a complete download but then goes through a scanning phase at which time a virus is detected. Download web site - http://mozilla.usse.indiana.edu/pub/mozilla.org/firefox/releases/3.6.6/win32/en-US/Firefox%20Setup%203.6.6.exe
    == This happened ==
    Every time Firefox opened
    == Trying to dowload install file from Indiana.edu site- detects virus in 3.6.6.exe file

    There have been "false postives" reported for a number of Firefox revision numbers by a number of AV/AS scanners.
    Try to download Firefox from here (you may be connected to a mirror site):
    http://www.mozilla.com/en-US/firefox/all.html
    Astaro Support: http://www.astaro.com/support
    Astaro User Forum: http://www.astaro.org/
    <u>'''''Other Issues'''''</u>: ~~red:You have installed plug-ins with known security issues. You should update them immediately.~~
    <u>'''Update Java'''</u>: your ver. 1.6.0.18; current ver. 1.6.0.20 (<u>important security update 04-15-2010</u>)
    (Firefox 3.6 and above requires Java 1.6.0.10 or higher; see: http://support.mozilla.com/en-US/kb/Java-related+issues#Java_does_not_work_in_Firefox_3_6 )
    ''(Windows users: Do the manual update; very easy.)''
    ~~red:Check your version here~~: http://www.mozilla.com/en-US/plugincheck/
    See: '''[http://support.mozilla.com/en-US/kb/Using+the+Java+plugin+with+Firefox#Updates Updating Java]'''
    Do the update with Firefox closed.
    <u>'''Install/Update Adobe Flash Player for Firefox (aka Shockwave Flash)'''</u>: your ver. 10.0 r45; current ver. 10.1 r53 ('''important security update 2010-06-10''')
    ~~red:Check your version here~~: http://www.mozilla.com/en-US/plugincheck/
    See: '''[http://support.mozilla.com/en-US/kb/Managing+the+Flash+plugin#Updating_Flash Updating Flash]'''
    -'''<u>use Firefox to download</u>''' and <u>'''SAVE to your hard drive'''</u> (save to Desktop for easy access)
    -exit Firefox (File > Exit)
    -check to see that Firefox is completely closed (''Ctrl+Alt+Del, choose Task Manager, click Processes tab, if "firefox.exe" is on the list, right-click "firefox.exe" and choose End process, close the Task Manager window'')
    -double-click on the Adobe Flash installer you just downloaded to install/update Adobe Flash
    -when the Flash installation is complete, start Firefox, and test the Flash installation here: http://kb.adobe.com/selfservice/viewContent.do?externalId=tn_15507&sliceId=1
    *<u>'''NOTE: On Vista and Windows 7'''</u> you may need to run the plugin installer as Administrator by starting the installer via the right-click context menu if you do not get an UAC prompt to ask for permission to continue (i.e nothing seems to happen). See this: http://vistasupport.mvps.org/run_as_administrator.htm
    *'''<u>NOTE for IE:</u>''' Firefox and most other browsers use a Plugin. IE uses an ActiveX version of Flash. To install/update the IE ActiveX Adobe Flash Player, same instructions as above, except use IE to download the ActiveX Flash installer. See: [[ActiveX]]
    *Also see: http://kb.mozillazine.org/Flash ~~red:'''''AND'''''~~ [[How do I edit options to add Adobe to the list of allowed sites]]

  • Missing TO-DO and iCal invites

    Hi,
    Two missing features in iPhone 3.0 are the ability to create/edit TO-DO's in Mail, and to accept invitations sent from iCal.
    Any ETA when those pieces will be missing? I do not wish to have a separate to-do list through a 3rd-party app, or have to kludge something for calendar invites.
    Thanks,
    --Jamey

    No ETA - Apple does not generally pre-announce features, and we cannot speculate here.
    You can submit feedback to Apple: http://www.apple.com/feedback/iphone.html.

  • Cisco2851 Any connect was not able to establish a connection to the specified secure gateway and Win7

    Hello ,
    R2811 Route config ssl vpn
    anyconnect-win-2.5.3055-k9.pkg
    windows xp ie6-8 all connection ssl vpn gateway,but win7 not able to establish
    IE browser display
    This website security certificate has a problem.

    asa5500 platform +anyconnect-win-2.5.3055-k9.pkg
    win7 win2000 winxp all connection!
    is why?

  • ICal invitations are sent with work email calendar and respond to personal

    Ical is set up to receive my work calendar called [email protected] Work email is a google webmail account. Office workers send invited to me from google calendar. I can accept these and they DO show on my .mac Ical.
    On Ical, i have a list of standard calendar topics (home, work, school, etc). I have the shared google calendar set up as a second calendar on the ICal application. No problem.
    My VCard has all work information. No personal at all. Work email, etc.
    My email mailboxes for both inbound and sent Are in rank order meaning "work" email is draqgged over ".mac personal" on both scenarios.
    Problem is This: When I create invites for "work calendar" , a new event pops up, "work email" shows as the Calendar and everything looks good and it does go to the invitee.
    1. Invitee receives the invitation and the invite states that it is from the ".mac PERSONAL" calendar
    2. My name shows as the organizer however has my personal email as the default (Not my work email as listed in my VCard)
    3. Most annoying of all, my "[email protected]" email address(If clicked on by the invitee) states my Wifes name on the email address bar.
    I have checked everywhere as to why my wife is showing up as the "owner" or my personal .mac account. Not anywhere on my .me account, .mac account, VCard, etc.
    Help?
    I want to send my invites from my work email account using Ical with the responses showing, and responding to the same work email address. Simple right?

    I have to admit... Im getting frustrated.
    I deleted the shared google calendar. Starting over. I created a work calendar called "MSL" under the "calendars" drop down in ical.
    Created a test event, sent it to a personal account, clicked the link to accept and the link sends me to Entourage? See Below... Says iCal... Link goes to Entourage.
    MSL Packaging and Fulfillment' has invited you to the iCal event: New Event Test, scheduled for December 16, 2009 at 4:00 PM (Eastern Standard Time). To accept or decline this invitation, click the link below.
    I want to:
    1.Sync google calendar with my [email protected] webmail account and my ICAL.
    2. Send invites from my ICAL when using my work address in imail, have them send from my work address, respond to my work address, and show up on google and ical calendars.

  • How to delete previous invitee from apple iCal invite list? When inviting "Joe" an old Email address shows up. This person is literally dead! (may he rest peacefull) and I can't find his Email address to delete anywhere. Not in my address book

    When sending calendar invite to "invitee" an old address appears. This guy is literally dead (may he rest in peace) and has same first name as person I send to all the time. So "dead" guy always pops up. Can't find his address to delete anywhere -- not in previous recipients, not in my address book, does not "auto-populate" when I try to send an Email. Still shows up everytime I want to send iCal invite. Spooky. Help me delete this guy from my iCal invitee options so he can truly rest in peace. Thanks!

    MacBook Pro - where you actually want and thought you were posting?
    https://discussions.apple.com/community/notebooks/macbook_pro 
    https://discussions.apple.com/community/mac_os?view=discussions
    http://www.apple.com/support/macbookpro
    http://www.apple.com/support/ical
    I assume it is in a cache - maybe even on servers.
    http://www.apple.com/support/iphonehttp://www.apple.com/support/mail

  • I have accepted iCal invitations with repeating events and they have since been deleted from the iCal on my Mac but won't delete from my iPhone. Help

    I have accepted iCal invitations with repeating events and they have since been deleted from the iCal on my Mac but won't delete from my iPhone. Help

    I experienced this issue as well.
    Background:
    I had opened an ICS attachment for a repeating event on my iPhone, which added the item to my phone's calendar. I did not have the option to delete the calendar entry from my phone, and the item did not appear on the calendar on my Mac. My phone is currently running iOS 7 (but the problem began quite awhile ago; I don't recall which version of iOS was installed when it started).
    Solution (summary):
    Create a new calendar, move the items that you wish to delete to the new calendar, then delete the new calendar
    Solution (detailed steps):
    Create a new calendar
    On your phone, open the calendar app
    Tap the "Calendars" option at the bottom of the screen
    Tap the "Edit" button in the top left corner
    Scroll to the bottom of the list and tap the "Add Calendar..." option
    Give your new calendar a good name, such as "Delete me"
    Tap "Done" in the top right corner to save the new calendar
    Tap "Done" in the top left corner to finish editing the list of calendars
    Tap "Done" to exit the list of calendars
    Assign all calendar entries that you wish to delete to the calendar you created in step 1
    Tap a calendar entry that you wish to delete
    Tap the "Edit" button in the top right corner
    Scroll down until you see the Calendar field (on an iPhone or iPod it's usually just below the bottom of the screen), then tap the Calendar field to bring up the list of available calendars
    Tap the name of the calendar that you created in step 1 (e.g. "Delete me"); the screen should return to the main calendar entry page
    Tap "Done" in the top right corner of the screen. You may need to then tap the "< Day" button on the top left of the screen to return to the main calendar view
    Repeat the instructions in step 2 for each of the calendar entries that you wish to delete
    Delete the calendar that you created in step 2 (this will delete all calendar entries assigned to this calendar)
    From the main screen in the calendar app, tap the "Calendars" option at the bottom of the screen
    Tap the "Edit" button in the top left corner
    Tap the entry for the calendar that you created in step 2 (e.g. "Delete me")
    Scroll to the bottom of the scren and tap the "Delete Calendar" option. You should be prompted with a warning that explains that "All events associated with this calendar will also be deleted."
    If you're sure that the only items on this calendar are items that you wish to delete, tap the "Delete Calendar" button
    Tap "Done" in the top right corner to exit the Edit Calendars screen
    Tap "Done" to exit the list of calendars. You should now be back at the main view of the calendars app
    Rejoice, your pesky repeating calendar events have been deleted
    At this point all of the items that you assigned to the deleted calendar should be gone
    Repeat the steps above for any entries that you missed
    Post another message to this thread if this did not resolve your problem
    minor edit for clarity made by ScottHooley

  • ICal invites are not received by some people (I know why, but Apple won't fix it)

    I switched to icloud a while back and have the maddening problem of SOME people not receiving invites, and have discovered what causes it (at least in my case):
    If the user you are sending to has an itunes (or apple id) account with that email as the login (and that email is NOT an icloud email) they will never receive the iCal invite! Instead it gets routed to their (non setup) icloud account. If they start using icloud for their calendars with this same external email address as login, they will receive them there (directly on their calendar if it is setup). Apple refuses to forward it to their real email address, the one we are sending it to. I have reported it to Apple several times but they are not inclined to fix it, probably because they want to force external users to use icloud. This is mega frustrating. Many of my friends do not receive invites, forcing me to use Google calendar for events with those friends. I prefer the general interface and look of icloud/ical invites, but I need to be able to actually invite people!

    ssuess wrote:
    Not for me, but let me verify the following type scenario with you:
    1. Your person to invite has a gmail address ([email protected])
    2. That gmail address is their Apple ID/iTunes login name (this is the most important piece)
    3. They may have some icloud service on (like note syncing) but do not use icloud calendaring or mail (or may have signed up for mail but never check it)
    4. Your icloud/ical invite arrives properly in their gmail inbox (at [email protected])?
    Is all the above true? For me, the above scenario results in no email being received at the address I sent it to (number 4), it gets routed/lost in icloud if that is their Apple ID login.
    Like I said, I do not have the issue you have, all my invites are received regardless of the email provider and user ID's I just send to the correct address and that's it. Frankly if what you said was common the service would be useless, but it works for millions. The problem is at your end, not everybody's.
    The login name is just a text string to iCloud, not an address.

  • I had a iPhone 3G and I change it in to a iPhone 4G 32GB! I have 3 apple ID account. The one I used is edited by host and I know my password but it ask me for my security question and I forgot it! It send a veify email the answer the an email to blu

    I had a iPhone 3G and I change it in to a iPhone 4G 32GB! I have 3 apple ID account. The one I used is <edited by host> and I know my password but it ask me for my security question and I forgot it! It send a veify email the answer the an email to <edited by host> and the email <edited by host> that is my other  apple ID and the password work on apple but my yahoo account I forgot my password and security question and it won't   verify to my email on to my apple email. so it  send the answer  to  <edited by host> and I can't get it! So Can u do something? Both account r also on my iCloud. I can open both apple account but it won't let me buy nothing on my <edited by host> ! On my <edited by host> that one dose let my buy thing but I had lot of thing I bought on <edited by host> I  bought lots of movies music and app. I spend lot of money on this account.

    It's a really bad idea to post your email addresess - it's an invitation to spam - and I've asked the Hosts to remove them.
    This is a user-to-user forum and no-one on here can take any direct action. If your Yahoo address is not working that's something you would need to take up with Yahoo - have you checked it by sending yourself an email to it?
    Otherwise you will need to contact Support: go to https://expresslane.apple.com/ and click on 'iTunes' in the center column and then 'iTunes Store' in the right-hand column and proceed from there.

  • Ical invites seen off by 1 hour in Outlook for IST (India Standard Time)

    Hi,
    I have this strange problem since I migrated to MAC recently and started using iCal.  Earlier I was using Thunderbird with Lightning.  I am in the India time zone (IST).  Whenever I create an appointment using iCal and send invites (using MAC Mail) to meeting participants, the Outlook users among the recipients see the meeting at a time that is an hour ahead of the scheduled time. Lightning users get the invite correctly.  Both my Mac and the recipients are using IST timezone.
    Please note that India does not use daylight saving.  I dug into the problem a bit and I have a speculation about what is going wrong.
    India used daylight saving briefly in 1942.  The VTIMEZONE specification generated in the ics by iCal seems to specify that daylight savings is used since May 15, 1942, and standard time is used since Sep 1, 1942.  My speculation is that Outlook interprets this as saying that daylight saving is in force today (July 2013), probably just ignoring the year specification.  Other calendar applications possibly are unaware of this bit of world war II history.
    Any way that I can get iCal to not include the timezone information or to modify its 1942 memory?  Currently, I am creating all appointments using UTC but that's obviously not pleasant.
    Here is a paste of the relevant data in the ics file.
    BEGIN:VTIMEZONE
    TZID:Asia/Kolkata
    BEGIN:STANDARD
    TZOFFSETFROM:+0630
    DTSTART:19420515T000000
    TZNAME:GMT+05:30
    TZOFFSETTO:+0530
    RDATE:19420515T000000
    RDATE:19451015T000000
    END:STANDARD
    BEGIN:DAYLIGHT
    TZOFFSETFROM:+0530
    DTSTART:19420901T000000
    TZNAME:GMT+05:30
    TZOFFSETTO:+0630
    RDATE:19420901T000000
    END:DAYLIGHT
    END:VTIMEZONE

    Hi, any thoughts here?  I tried replacing the system timezone file for IST with a vanilla +0530 GMT offset one (in /var/share/zoneinfo) but that didn't work (even after a reboot).  Does Mail (and other such applications) not use the system timezone definition files?

  • I can no longer send iCal invitations.  I have not changed any settings, passwords or email accounts.  No idea what to do.

    I can no longer send iCal invitations.  I have not changed any settings, passwords or email accounts.  No idea what to do.

    Greetings,
    Questions:
    What happens when you put in an email address in an event? (Make sure the email address is also in your addressbook (Macintosh HD > Applications > Addressbook)
    Are you using calendars that show up under "On My Mac" on the left hand side of iCal or are the calendars under a different heading?
    Troubleshooting:
    Make sure that you can send / receive email in the Apple Mail program.
    Make sure that the email address in Mail > Preferences > Accounts is also on your Addressbook card:Go to Addressbook > Card > Go to My Card -- The email address you are using to send receive messages on your computer should be on this card.
    If that doesn't take care of it:
    1. First make an iCal backup:  Click on each calendar on the left hand side of iCal one at a time highlighting it's name and then going to File Export > Export and saving the resulting calendar file to a logical location for safekeeping.
    2. Go to iCal > Quit iCal
    3. Remove the following to the trash and restart your computer:
    Home > Library > Caches > com.apple.ical
    Home > Library > Calendars > Calendar Cache, Cache, Cache 1, 2, 3, etc. (Do not remove Sync Cache or Theme Cache if present)
    4. Launch iCal and test.
    If the issue persists:
    1. Go to iCal > Quit iCal
    2. Remove the following to the trash and restart your computer:
    Home > Library > Caches > com.apple.ical
    Home > Library > Calendars > Calendar Cache, Cache, Cache 1, 2, 3, etc. (Do not remove Sync Cache or Theme Cache if present)
    Home > Library > Preferences > com.apple.ical (There may be more than one of these. Remove them all.)
    --- NOTE: Removing these files may remove any shared (CalDAV) calendars you may have access to. You will have to re-add those calendars to iCal > Preferences > Accounts.
    3. Launch iCal and test.
    Hope that helps!

  • What's going on with Project "Gateway" and Sybase?

    I've just returned from Teched in Berlin where I followed mostly the mobile track of sessions.
    I've come away alternately energised and confused. Each topic in its own right is clear, but piecing allthe components together is a different matter.
    Has anyone got opinions on the future role of project Gateway? I saw many sessions by Sybase on the SUP and only one which mentioned Gateway. Gateway didn't feature in the mobile strategy slides. However, I have seen material mentioning the future tie-up of the two. If this should happen, then how might they interact? And what future for the co-innovation platform?  Can we draw any conclusions on this yet?
    The instant value mobile apps session CD161 seems to build on top of the SAP Data Protocol (SDP), but thinking back, they didn't mention Gateway in there at all. And the co-innovation platform session was silent on both Gateway and SDP
    So does "Instant Value" equal "Project Gateway"? It can't be since the Sybase guys talk a lot about Instant Value. Are there two interpretations of this term within the organisation?
    Just hoping to kick off a general discussion on this subject. All opinions and replies welcome. Especially from insiders...
    Alex.

    Hi Steffan - good point. I kind of assumed that LMS is another term for Project Gateway... They seem to be addressing the same problem, and the architecture diagrams look qualitatively similar.  The CD121 Sybase slides also talk about the "SAP Mobile Connector", which might be yet another name for the same thing. I think you would know better than me since you've already built that thing you showed at the Demo Jam - what data consumption technology was your demo-ed app using?
    I get the impression that there have been a number of independent development streams within SAP which are only now being brought together. This manifests itself to us as mixed or incomplete messages. It's easy to see how at a teched, each group might be responsible for getting its own message out and not necessarily integrating into the overall message of the mobile strategy.
    So essentially there are two categories of mobile app inthe SAP vision:
    1. Instant Value  and 
    2. Mission Critical.
    Then there are various methods of consuming SAP backend data from our mobile apps:-
    1. Netweaver mobile DOE (via co-innovation platform?)
    2. LMS
    3. Project Gateway
    4. Web services
    5. BAPIs (via JCA)
    (This is five methods, not four, which is another reason why I thought LMS and Gateway were the same thing).
    Then on top (or underneath?) of all this, you have to make a call on whether to make use of the SUP middleware and/or a security product like Afaria.
    So perhaps the most likely combinations look like:-
    Mission Critical apps with SUP ( + Afaria ) + DOE/Gateway
    or
    Instant Value apps with (LMS/Gateway or simply Web services/JCA)
    But if you have a LOT of Instant-value apps to build I guess your landscape could become complicated enough to justify the middleware too.
    Now please someone point out the flaws in this summary!
    Alex.
    Edited by: ajfear on Oct 20, 2010 6:44 PM

  • Anyconnect cannot confirm it is connected to your secure gateway

    Hi,
    I have configured cisco 1941 with anyconnect VPN. I have installed the anyconnect-win-3.1.07021-k9.pkg on the flash memory but it seems something is missing. When i access the router and download the anyconnect, the following message appears on the browser "Failed to get configuration because Anyconnect cannot confirm it is connected to your secure gateway". therefore, i have downloaded manually the anyconnect and tried to access my network. Unfortunately, the application does not connect and the "Anyconnect cannot confirm it is connected to your secure gateway" message appears.
    it can be noticed that i have an android phone which successfuly connects to my network without any problems.
    Please see below my configuration and i will appreciate if someone helps with this....
    crypto pki trustpoint test_trustpoint_config_created_for_sdm
     subject-name [email protected]
     revocation-check crl
    crypto pki trustpoint CRXX
     enrollment selfsigned
     serial-number none
     ip-address none
     revocation-check crl
     rsakeypair CRXX_RSAKey 512
    crypto pki trustpoint euro.lan
     revocation-check crl
     rsakeypair CRXX
    crypto pki certificate chain test_trustpoint_config_created_for_sdm
    crypto pki certificate chain CRXX
     certificate self-signed 01
      3082017A 30820124 A0030201 02020101 300D0609 2A864886 F70D0101 05050030
      1B311930 1706092A 864886F7 0D010902 160A4352 4575726F 73757265 301E170D
      31353033 30373139 32383530 5A170D32 30303130 31303030 3030305A 301B3119
      30170609 2A864886 F70D0109 02160A43 52457572 6F737572 65305C30 0D06092A
      864886F7 0D010101 0500034B 00304802 4100896A 9A2F5ADB 6E1615AA 61ABC513
      2770253F 24F17DC4 A16D8ACD 5C9042C1 476AAAE9 D0E1EDDE 520D3A13 AD895518
      ED63C68E C734628D A6855FFA F9F3B099 AA230203 010001A3 53305130 0F060355
      1D130101 FF040530 030101FF 301F0603 551D2304 18301680 1467308D 8F138842
      4110A886 779CC1D5 D9302A5F FD301D06 03551D0E 04160414 67308D8F 13884241
      10A88677 9CC1D5D9 302A5FFD 300D0609 2A864886 F70D0101 05050003 4100376B
      789B83C7 D8F20FEC CFAC75B4 B71518EE 90078812 D86B5F35 23D54DB0 28C678E1
      BCB33BF5 81D47EE8 7392D4E8 1433CFA9 7157EC64 C9EA2357 EAADCB02 E789
            quit
    crypto pki certificate chain CRXX
     certificate ca 01
      3082030D 30820276 A0030201 02020101 300D0609 2A864886 F70D0101 04050030
      81993133 30310609 2A864886 F70D0109 01162463 68726973 746F666F 726F732E
      70616E61 79694061 74686C6F 697A6F75 2E636F6D 2E637931 10300E06 03550408
      13076E69 636F7369 61310B30 09060355 04061302 63793115 30130603 55040313
      0C657572 6F737572 652E6C61 6E311530 13060355 040B130C 6575726F 73757265
      2E6C616E 31153013 06035504 0A130C65 75726F73 7572652E 6C616E30 1E170D31
      35303330 38303830 3532355A 170D3138 30333037 30383035 32355A30 81993133
      30310609 2A864886 F70D0109 01162463 68726973 746F666F 726F732E 70616E61
      79694061 74686C6F 697A6F75 2E636F6D 2E637931 10300E06 03550408 13076E69
      636F7369 61310B30 09060355 04061302 63793115 30130603 55040313 0C657572
      6F737572 652E6C61 6E311530 13060355 040B130C 6575726F 73757265 2E6C616E
      31153013 06035504 0A130C65 75726F73 7572652E 6C616E30 819F300D 06092A86
      4886F70D 01010105 0003818D 00308189 02818100 C7DFF639 00AAD60E DE260ED6
      87BEF428 A49386A2 5A4A6137 12811855 A8582E12 58ADAB6E 796E97EF 7A67309B
      F8F782BA 4BC027BB E751C271 DB81246E 8B975F40 648E0594 12C6162B 8B85ABB8
      E97732A9 0914C6A4 1AB99A3B 7676FBB7 74D9E2C0 0D5EDF59 CC705BD5 ADE10227
      48EDE22A DA782E6E CE813B71 63327693 2B8A3BA3 02030100 01A36330 61300F06
      03551D13 0101FF04 05300301 01FF300E 0603551D 0F0101FF 04040302 0186301F
      0603551D 23041830 168014D6 85F27FA8 59599438 BD252971 0BD29665 4E2F1930
      1D060355 1D0E0416 0414D685 F27FA859 599438BD 2529710B D296654E 2F19300D
      06092A86 4886F70D 01010405 00038181 00BAD0D8 41D25EE0 8546C804 05B82812
      28AA37A0 93247B1B A405622A 4553E897 B099DAF9 04F818A7 D1BB21D0 0343C186
      D5CCBCB7 6FB89E2F BD75ACB9 7B2FBB1F C5C0EF69 DBFFAB0E EB4F20AD 0DDCDAD5
      8B933B61 E6319A9C F73BD27E 61E90A9A FDD94EF9 0AE82CDA 12BC2D5B C1122649
      59236893 C5A1F5F1 D45C5471 01C87F98 1D
            quit
    crypto vpn anyconnect flash0:/webvpn/anyconnect-win-3.1.07021-k9.pkg sequence 2
    interface Virtual-Template3
     mtu 1406
     ip unnumbered GigabitEthernet0/0.1
    ip local pool SSL_admin_pool 192.168.251.1 192.168.251.254
    ip nat inside source list 100 interface GigabitEthernet0/1 overload
    access-list 100 deny   ip 126.0.0.0 0.0.0.255 192.168.250.0 0.0.0.255
    access-list 100 permit ip any any
    webvpn gateway gateway_1
     hostname CRXX
     ip address 213.X.X.X port 443
     http-redirect port 80
     ssl trustpoint CRXX
     inservice
    webvpn context ADMINS_Policy
     secondary-color white
     title-color #CCCC66
     text-color black
     virtual-template 3
     aaa authentication list ciscocp_vpn_xauth_ml_1
     gateway gateway_1
     ssl authenticate verify all
     inservice
     policy group policy_1
       functions svc-enabled
       svc address-pool "SSL_admin_pool" netmask 255.255.255.255
       svc default-domain "eurosure.lan"
       svc keep-client-installed
       svc dns-server primary 126.0.0.2
       svc dns-server secondary 126.0.0.1
     default-group-policy policy_1

    hello,
    Also, after update windows 8.1, I think, it is no longer work with ssl encryption rc4-sha1 !
    When my config contain the ssl encryption rc4-sha1
    I get the error:
    "Failed to get configuration because AnyConnect cannot confirm it is connected to your secure gateway. Contact your system administrator".
    After I change it to: ssl encryption aes128-sha1, AnyConnect client can connect to ASA."
    WORK!!

  • Removing email address from auto populate box in ICal invites

    I deleted a contact/email address from my address book but his name/email still shows up in ical as choice for invites. His address is not in my mail's "previous recipients" list and is removed from contacts. How do I stop it from being a choice to populate in my ical invite? 

    MacBook Pro - where you actually want and thought you were posting?
    https://discussions.apple.com/community/notebooks/macbook_pro 
    https://discussions.apple.com/community/mac_os?view=discussions
    http://www.apple.com/support/macbookpro
    http://www.apple.com/support/ical
    I assume it is in a cache - maybe even on servers.
    http://www.apple.com/support/iphonehttp://www.apple.com/support/mail

  • Publish RD Gateway and Web Access with One-Time Password (OTP) / Two-factor Authentication WITHOUT ISA/TMG server

    Hi everybody,
    I've been struggeling with this problem for a few weeks now and can't find a way to solve it.
    We have an RD farm (Server 2012) which consists of two Remote Desktop Servers with Connection Broker and Web Access.
    I've recently published a new server, containing RD Gateway and Web Access in our perimeter network.
    Now we've got restrictions that OTP/2FA must be used for the external deployment and we've decided to go for a solution from Gemalto.
    The "program" is called IDConfim and the server is called SA Server (Strong Authentication).
    Also it's important that NO ISA/TMG server is supposed to be used, the OTP/2FA is supposed to work seamless with the Web Access/Gateway.
    After hours discuss we came to a point were their NPS agent setup would be the only way to accomplish our goals.
    The setup is supposed to be like this:
    LAN:
    1 DC (2008 R2)
    RD Farm (2012)
    1 SA Server (2012)
    DMZ:
    RD Gateway/Web Access (2012)
    Were Gateway and Web Access should forward the authentications with NPS to the NPS agent on the SA server.
    When you print your AD account to authenticate you add the 6 digits of OTP which you recieve from you mobile app.
    Initially this seems to work, the Gateway forwards the request to the remote NPS server, BUT only if you write the correct AD password
    (without the OTP extension).
    If you write the correct AD password the authentication is forwarded to out SA Servern and it's beeing rejeced because the password doesn't
    contain the correct OTP extension.
    The problem comes here.
    When you write you AD password along with the OTP extension you get a Windows Security error in the eventlog (On thw Gateway server) like this:
    An account failed to log on.
    Subject:
    Security ID: NULL SID
    Account Name: -
    Account Domain: -
    Logon ID: 0x0
    Logon Type: 3
    Account For Which Logon Failed:
    Security ID: NULL SID
    Account Name: user
    Account Domain: domain
    Failure Information:
    Failure Reason: Unknown username or password.
    Status: 0xc000006d
    Sub Status: 0x0
    Process Information:
    Caller Process ID: 0x0
    Caller Process Name: -
    Network Information:
    Workstation Name: server
    Source Network Address: 192.168.x.x
    Source Port: 63003
    Detailed Authentication Information:
    Logon Process: NtLmSsp
    Authentication Package: NTLM
    Transited Services: -
    Package Name (NTLM only): -
    Key Length: 0
    This event is generated when a logon request fails. It is generated on the computer where access was attempted.
    The Subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.
    The Logon Type field indicates the kind of logon that was requested. The most common types are 2 (interactive) and 3 (network).
    The Process Information fields indicate which account and process on the system requested the logon.
    The Network Information fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.
    The authentication information fields provide detailed information about this specific logon request.
    - Transited services indicate which intermediate services have participated in this logon request.
    - Package name indicates which sub-protocol was used among the NTLM protocols.
    - Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
    What i can see it's a NTLM error, but hey?! aren't we supposed to forward all authentication handeling to the remote NPS server?
    The problem is that no matter what i try the above problem stays there.
    Is it not possible to just forward ALL authentication handeling to a remote server?
    The only solution I've found to get it working someday in the future is this:
    "Remote Desktop Pluggable Authentication and Authorization", which is supposed to be introduced in 2012 R2.
    Also this link describes it:
    http://archive.msdn.microsoft.com/Release/ProjectReleases.aspx?ProjectName=rdsdev&ReleaseId=3745
    Please, bring me some answers before my head explodes! :)
    PS, long question = maybe some errors, ask me if something is unclear.

    Hi,
    Based on our experience, if the NTLM error occurs, please check the password.
    Regards,
    Mike
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

Maybe you are looking for

  • How do I back up phone numbers from Nokia 6350 bef...

    I got so tired of my buggy Nokia 6350 that I went to my service provider's website (AT&T) and bought an iPhone 3GS. When it arrived I read the instructions, found some confusing directions there and am in the process of asking for clarifications in t

  • HT1688 012573005217023 canot activate in version 6.1.3 what is problem pls help

    help

  • Button actions not called.

    I have a fairly complicated edt page (lots of data entry components and 3 tables) with a save and a reset button. Somewhere along the line the button actions stopped being called when I click a button in the browser. The buttons' Events-Action proper

  • Is there a way to save Publish Settings?

    I had a machine crash. My data files and LRCAT are stored on a separate drive so after reloading all the software I just pointed to my current LRCat.  I found out that the publish settings are not stored in the catalog (seems like a smart place to ke

  • Help needed with BRtools/sapdba!!!

    Hi SAP gurus!! We have to perform reorganization as part of archiving post processing activity. pls refer the following link: http://help.sap.com/saphelp_nw70/helpdata/EN/8d/3e4e81462a11d189000000e8323d3a/frameset.htm It says" If data has been archiv