<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Cisco AnyConnect VPN Overview</title>
	<atom:link href="http://blog.ine.com/2009/01/03/cisco-anyconnect-vpn-overview/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.ine.com/2009/01/03/cisco-anyconnect-vpn-overview/</link>
	<description>Helping you become a Cisco Certified Internetwork Expert</description>
	<lastBuildDate>Wed, 28 Jul 2010 22:47:55 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: LEB</title>
		<link>http://blog.ine.com/2009/01/03/cisco-anyconnect-vpn-overview/comment-page-1/#comment-17843</link>
		<dc:creator>LEB</dc:creator>
		<pubDate>Sun, 04 Jan 2009 20:54:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=435#comment-17843</guid>
		<description>One problem with AnyConnect is that since it uses SSL, it is vulnerable for a Man in The Middle attack. 

I have tested this myself, and was quite easily able to get both username and password by doing MiTM. 

Granted, I had to click accept on the certificate error that was presented, but normally users do this anyway. 

But with the new MD5 exploit for certificates, this can quite quickly become critical for an organization. 

So, yes, AnyConnect is quite nice, but I would reccomend either using token based authentication, or having the ASA request a client certificate to mitigate this attack. 

-Erik</description>
		<content:encoded><![CDATA[<p>One problem with AnyConnect is that since it uses SSL, it is vulnerable for a Man in The Middle attack. </p>
<p>I have tested this myself, and was quite easily able to get both username and password by doing MiTM. </p>
<p>Granted, I had to click accept on the certificate error that was presented, but normally users do this anyway. </p>
<p>But with the new MD5 exploit for certificates, this can quite quickly become critical for an organization. </p>
<p>So, yes, AnyConnect is quite nice, but I would reccomend either using token based authentication, or having the ASA request a client certificate to mitigate this attack. </p>
<p>-Erik</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anthony Sequeira, #15626</title>
		<link>http://blog.ine.com/2009/01/03/cisco-anyconnect-vpn-overview/comment-page-1/#comment-17832</link>
		<dc:creator>Anthony Sequeira, #15626</dc:creator>
		<pubDate>Sun, 04 Jan 2009 18:52:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=435#comment-17832</guid>
		<description>Ahh - I just noticed that I did not complete the post - sorry!!! Thanks again for the heads up. Copy/Paste error.</description>
		<content:encoded><![CDATA[<p>Ahh &#8211; I just noticed that I did not complete the post &#8211; sorry!!! Thanks again for the heads up. Copy/Paste error.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anthony Sequeira</title>
		<link>http://blog.ine.com/2009/01/03/cisco-anyconnect-vpn-overview/comment-page-1/#comment-17831</link>
		<dc:creator>Anthony Sequeira</dc:creator>
		<pubDate>Sun, 04 Jan 2009 18:48:11 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=435#comment-17831</guid>
		<description>Hi pitt2k!

Thanks for the query and feedback. I am trying to keep the posts shorter and more direct. I will add a conclusion - and will post a follow up blog today on issues with the client install. Look for it later today or tonight.

Thanks again.</description>
		<content:encoded><![CDATA[<p>Hi pitt2k!</p>
<p>Thanks for the query and feedback. I am trying to keep the posts shorter and more direct. I will add a conclusion &#8211; and will post a follow up blog today on issues with the client install. Look for it later today or tonight.</p>
<p>Thanks again.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pitt2k</title>
		<link>http://blog.ine.com/2009/01/03/cisco-anyconnect-vpn-overview/comment-page-1/#comment-17818</link>
		<dc:creator>pitt2k</dc:creator>
		<pubDate>Sun, 04 Jan 2009 14:19:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=435#comment-17818</guid>
		<description>Anthony,

Does it require administrative rights on the client to install or use this software?

P.S. Seems the article is unfinished.</description>
		<content:encoded><![CDATA[<p>Anthony,</p>
<p>Does it require administrative rights on the client to install or use this software?</p>
<p>P.S. Seems the article is unfinished.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
