System information
12
Release Notes for Cisco VPN 3000 Series Concentrator, Release 3.6 Through 3.6.8.B
OL-5637-02
Usage Notes
Browser Interoperability Issues
The following sections describe known behaviors and issues with the indicated Web browsers.
VPN 3000 Concentrator Fully Supports Only Netscape and Internet Explorer
Currently, the VPN 3000 Concentrator fully supports only Netscape and Internet Explorer. If you are
using Internet Explorer, use version 5.0, Service Pack 2 or higher. Using other browsers might cause
unacceptable behavior; for example, if you attempt to use an unsupported Web browser to manage the
VPN 3000 Concentrator, clicking any of the links might return you to the login screen. (CSCdx87630).
Internet Explorer 4.x Browser Issues
The following are known issues with Internet Explorer 4.X and the VPN Concentrator Manager (the
HTML management interface). To avoid these problems, use the latest version of Internet Explorer (at
least version 5.0).
• If you encounter a script error when you try to save your configuration file using Internet Explorer
4.0, reinstall Internet Explorer 4.0, or upgrade to a later version of Internet Explorer. Reinstalling
Internet Explorer fixes the problem.
• If you plan to upgrade the firmware on multiple VPN Concentrators at the same time from the same
PC, use the version of Internet Explorer on the Cisco VPN 3000 software distribution media or
newer. Using an earlier version could cause a failure in one or more of the upgrades.
• When connecting to the VPN Concentrator using SSL with Internet Explorer 4.0 (v4.72.2106.8),
you might receive a message box saying, “This page contains both secure and non-secure items. Do
you want to download the non-secure items?” Select Yes. There really are no non-secure items on
the page and the problem is with Internet Explorer 4.0. If you upgrade to Internet Explorer 4.0
Service Pack 1 or Service Pack 2, you should not see this error message again.
After adding a new SSL certificate, you might have to restart the browser to use the new certificate.
VPN Client Used with Zone Labs Integrity Agent Uses Port 5054
VPN Clients, when used with the Zone Labs Integrity Agent, are put into a “restricted state” upon
connection to the Integrity Server if a port other than 5054 is used. The restricted state simply means the
VPN Client is able to communicate only with the Integrity Server; all other traffic is blocked
(CSCdw50994).
Workaround:
Do one of the following:
• Configure the VPN Concentrator and the Integrity Server to use port 5054 when communicating
with each other.
• Edit the WEB.XML file in the Integrity directory and search for 5054 (the port that Integrity
uses/looks for). Change it to 5000, save, and restart the Integrity Server.