AnyConnect clients randomly disconnect, reconnect
Hello,
We have been using our current configuration for some time, but recently most of the AnyConnect clients randomly loose connection, then reconnect. I have had the ISP and SonicWall look to see if they find any issue, but they do not. I have checked the event viewer on one XP machine and find numerous log entries regarding connection timeouts, etc. I have listed some below. A search of this comunity resulted in only one response that was incomplete.
This entry is listed as Error, Event ID 2, source is vpnagent:
Function: CHttpProbeAsync::OnOpenRequestComplete
File: .\IP\HttpProbeAsync.cpp
Line: 254
Invoked Function: CHttpSessionAsync::OnOpenRequestComplete
Return Code: -31522780 (0xFE1F0024)
Description: SOCKETTRANSPORT_ERROR_CONNECT_TIMEOUT
Another error:
Function: CNetEnvironment::TestNetEnv
File: .\NetEnvironment.cpp
Line: 190
Invoked Function: CNetEnvironment::testNetwork
Return Code: -28901363 (0xFE47000D)
Description: NETENVIRONMENT_ERROR_PROBE_INCOMPLETE:Network Probe could not contact target
This entry is a Warning:
Function: CNetEnvironment::logProbeFailure
File: .\NetEnvironment.cpp
Line: 1068
Invoked Function: CHttpProbeAsync::SendProbe
Return Code: -27787250 (0xFE58000E)
Description: HTTP_PROBE_ASYNC_ERROR_CANNOT_CONNECT
HTTP (host: 198.210.1.1)
Another Warning:
Reconnect reason code 6:
Reconnecting due to the disruption of the VPN connection to the secure gateway.
There are numerous information logs referring to reconnecting, VPN connection re-established, primary SSL connection to the secure gateway is down.
Anyone have ideas on how to troubleshoot this?
Thank you for any suggestions.
Bill,
Were you able to diagnose why this issue was/is occuring? We are experiencing a similar issue with a user in our organization:
Session level reconnect reason code 6:
Disruption of the VPN connection to the secure gateway.
Originates from tunnel level
Function: CSslTunnelTransport::OnTransportInitiateComplete
File: .\SslTunnelTransport.cpp
Line: 363
Invoked Function: CTcpTransport::initiateTransport
Return Code: -31588316 (0xFE1E0024)
Description: SOCKETTRANSPORT_ERROR_CONNECT_TIMEOUT
Similar Messages
-
EA6300 Random Disconnects/Reconnects
I have a newish EA6300 router, and the connection will randomly but often (every 15min or so) drop for a second and then reconnect. The firmware is 1.1.40.153731. I have two laptops in the house and this issue happens on both computers. I also have another wireless router (Zoom N150) and when I connect the computers to that router the connection is stable and never drops. Any idea why I'm getting these random disconnect/reconnect issues with the EA6300? I would very much like to only use the Linksys router because of its superior power, range and ability to handle more devices and traffic, as well as eventual AC capability. However I can't use it as a primary connections because of this issue.
Thanks for the reply. I had already changed the channel and it did seem to improve things. I still get disconnects but they are MUCH less frequent. My next step will be to move the Linksys router away from another wireless router that is nearby that may be causing interference. I have another question. I have used inSSIDer to examine the signal strength of the wireless networks around my home. This is what helped me to know what channel to switch the Linksys router to. But I've noticed that inSSIDer shows two networks when the Linksys router is on. I do not have a 5ghz wireless card in my computer, so only the 2.4ghz band shows as a network. One of the networks is my network that I have named, but the other network is unnamed (no SSID), and this mystery network will occassionally get a big drop in signal strength. I have attached a screen shot. The blue line is my main (named) personal network, an the yellow line is the mystery network that turns on when the router is on. You can see the downward spike in that yellow line that indicates a momentary loss of signal in that mystery network. Any idea why two networks show up? And if their coming from the same router, why would one lose signal while the other doesn't? Again, I don't have an AC network card, so I'm not seeing a 5ghz band so the second one can't be that.
-
Cisco VPN Client Random Disconnects
I am connecting to our ASA5510 via Cisco VPN client version 5.x. I am getting continuous disconnects at random times. I have never had a connection last more than 10 minutes. The disconnects happen when the session is idle and also when the session is active. I have had the connection drop on me in the middle of a file transfer even. I have set the session timeout to unlimited but no help. Does anyone have any ideas?
Thanks,
KenThe reason for that disconnection might be one of the following:
1) You reached an idle timeout.Increase the idle timeout value.
2) Someone cleared the tunnel.check for the tunnel configuration.
3) Your SA has a very short lifetime.
check if isakmp nat-t is enabled.If not enable the same and check for the issue.
check if TunnelEstablished Registry key is set to 0 which is the right one.
Refer the following url for more info on troubleshooting VPN issue:
http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807e0aca.shtml#isalife -
WAP371 clients constantly disconnecting/reconnecting
I have a new WAP371 with firmware 1.1.2.3. It's installed on an interior wall on the second floor of my three-floor house. It receives power over Ethernet from an SG200-08P switch. Each radio has a separate SSID. WPA-Personal is used on both. All traffic is in untagged VLAN 1.
Clients are will not stay connected for longer than a minute or two. The log shows an association, then after usually one or two minutes, the log shows a deauth with the message "Disassociated due to inactivity." Then the very next item in the log is another association from the client. This will persist for a minute or two, and then the cycle repeats, continually and forever. This happens even when there is activity, so "Disassociated due to inactivity" seems wrong.
Following various bits of advice here, I've tried:
various fixed frequencies
all bandwidth options
short guard interval yes and no
protection auto and off
frame burst on and off
fixed multicast rate auto and 54
removed 1 and 2 from legacy rate sets on the 2.4 GHz radio
set broadcast key refresh rate to 0
disabled TSPEC, scheduler, bandwidth utilization, client QoS, Green Ethernet
I'm at a loss to figure out how to fix this. It causes activity on the clients to sputter -- I'm seeing a fair number of retransmissions. Occasionally application connections, like streaming video, will reset. Help please?My name Eric Moyers. I am an Engineer in the Small Business Support Center.
I am sorry to hear that you are experiencing this issue.
I feel that this is an issue that will be difficult to effectively troubleshoot through chatting on the forums. You will get better results for something this complicated by opening a case with one of our engineers directly.
Please call our support center and open a case so that one of them can work directly with you.
http://www.cisco.com/c/en/us/support/web/tsd-cisco-small-business-support-center-contacts.html
If you like you can repost the case number here and I can check in on your case as well.
Eric Moyers
.:|:.:|:. CISCO | Cisco Presales Technical Support | Wireless Subject Matter Expert
Please rate helpful Posts and Let others know when your Question has been answered. -
IChat lately started randomly disconnecting/reconnecting
anyone smart enough to know what this means?
6/21/10 11:03:05 AM iChatAgent[242] [Warning] SocketStream: error Error Domain=NSPOSIXErrorDomain Code=54 UserInfo=0x100227ec0 "The operation couldn’t be completed. Connection reset by peer" occurred on input stream
6/21/10 11:03:05 AM iChatAgent[242] [Warning] XMLStream: error Error Domain=NSPOSIXErrorDomain Code=54 UserInfo=0x100227ec0 "The operation couldn’t be completed. Connection reset by peer" occurred on input
6/21/10 11:03:05 AM iChatAgent[242] [Warning] JConnection: Error: Error Domain=NSPOSIXErrorDomain Code=54 UserInfo=0x100227ec0 "The operation couldn’t be completed. Connection reset by peer"
...and how i get it to stop happening?
i haven't changed anything with my network settings that i can think of.Hi,
If you mean you don't want to Disable SSL you need to know that when the AIM SSL server Fails, iChat resorts to a NON SSL login and iChat has to be Manually reset to use SSL when the server comes back on Line. It does not happen automatically.
If you mean it did not work then also try deleting com.apple.iChat.AIM.plist and restart iChat so it is recreated.
The file is found in your Home Folder/Library/Preferences.
7:51 PM Thursday; June 24, 2010
Please, if posting Logs, do not post any Log info after the line "Binary Images for iChat" -
Hi,
I have a few people who have been saying that their CUPC client randomly disconnects and they can't reconnect for a long time, even through reboots. I have a feeling that it's somehow an LDAP timeout, but I don't know. Regular ethernet and phone connectivity remains normal. I have attached the problem report from one of the people. Can anyone decipher what might be happening?Do you happen to have a timestamp when you saw this issue? There are quite a few log files in here.
--Matt -
AnyConnect Client (3.1.02040) - Windows 8 won't shut down
I've noticed and issue with Windows 8 and AnyConnect Client version 3.1.02040. I've tried various things to try to resolve this issue but have hit a brick wall. Whenever, I run AnyConnect on my Windows 8 PC and then shut it down for the day, the PC won't turn off. I've ensured my AnyConnect client is disconnected and then quit the application and even killed the VPN service.
Has anyone else seen this issue??? Any resolution???I also have the same problem. There is a few things that I have noticed...
1. If you disable the Network List Service and the Network Location awareness Services and reboot, this problem does not occure. However, when you disable these services, you are no longer able to manager you network connections.
2. There are many errors that appear in the cisco anyconnect secure mobility client event log
System
Provider
[ Name]
acvpnagent
EventID
2
[ Qualifiers]
9216
Level
2
Task
1
Keywords
0x80000000000000
TimeCreated
[ SystemTime]
2013-02-28T20:36:21.000000000Z
EventRecordID
942
Channel
Cisco AnyConnect Secure Mobility Client
Computer
PC2578.swgao.int
Security
EventData
Function: CThread::invokeRun File: .\Utility\Thread.cpp Line: 435 Invoked Function: IRunnable::Run Return Code: -32112629 (0xFE16000B) Description: BROWSERPROXY_ERROR_NO_PROXY_FILE
Provider
[ Name]
acvpnagent
EventID
2
[ Qualifiers]
9216
Level
2
Task
1
Keywords
0x80000000000000
TimeCreated
[ SystemTime]
2013-02-28T20:36:21.000000000Z
EventRecordID
940
Channel
Cisco AnyConnect Secure Mobility Client
Computer
PC2578.swgao.int
Security
EventData
Function: CVirtualAdapter::IsVAEnabled File: .\WindowsVirtualAdapter.cpp Line: 2685 Invoked Function: CVirtualAdapter::IsVAEnabled Return Code: -33554423 (0xFE000009) Description: GLOBAL_ERROR_UNEXPECTED Unexpected VA status bits, 25174019
System
Provider
[ Name]
acvpnagent
EventID
2
[ Qualifiers]
9216
Level
3
Task
1
Keywords
0x80000000000000
TimeCreated
[ SystemTime]
2013-02-28T20:36:21.000000000Z
EventRecordID
936
Channel
Cisco AnyConnect Secure Mobility Client
Computer
PC2578.swgao.int
Security
EventData
Function: CVAMgr::cleanupAddress File: .\VAMgr.cpp Line: 2449 Invoked Function: CNetshDeleteAddress::Run Return Code: -31064051 (0xFE26000D) Description: NETSHCOMMAND_ERROR_PARSE_FAILED
I'm not sure what anyconnect is doing, but it appear when disconnecting something is prevting it from resetting all of the network settings. -
WAP321 random disconnecting clients
Hi all,
I'm having problems with my WAP321 that is randomly disconnecting clients. It's not disconnecting all clients, but just a couple of clients. It's random which clients get disconnected and it can be different clients that will be disconnected when it happens a couple times, but they do get disconnected at the same time.
My setup:
Cisco ASA5505
|
Cisco WAP321
|
Cisco 7925 phone - iPhone - Macbook - three IP cam's (different brands) - and some more clients
Last time it occurred I just for sure changed DHCP server from Cisco ASA5505 to two windows servers, now it happened again, my 7925 started beeping (enabled SSID monitoring on it so it alerts when it isn't connected to my Callmanager) and my iPhone couldn't connect to the SSID. My Macbook was still just connected. Retrieved a diagnostics report and checked the logging, rebooted the WAP321 and everything started connecting again.
Noticed screens are scaled so hope it's readable...
The MAC address is my iphone. I turned off the 7925 because the beeping was annoying so no logging from the 7925 trying to connect.
Logging is saying:
assoc request from [mac] BSSID [bssid] SSID LEVELS
STA [mac] deauthed from BSSID [bssid] reason 3: STA is leaving IBSS or ESS
There is nothing wrong with the coverage, the WAP321 is about ten feet from the iPhone and Cisco 7925 phone
Can anybody help me how to best troubleshoot this issue. I'm not familiar with the troubleshoot/debug options available for the WAP321Dear Wesley,
Thank you for reaching the Small Business Support Community.
There is an opened caveat on the latest firmware release, version 1.0.4.2; CSCue24521:
-Symptom: Some clients may lose wireless connection when authenticating via Captive portal.
-Workaround: Reconnect wireless devices.
If this is not the case I'd like to know if you have tried using a different IEEE 802.11 standard, same as a different authentication type. If you are not running the latest firmware release I then suggest you to, and something else I've seen from experience that fixes similar issues is to reset to factory conditions and reconfigure manually.
http://software.cisco.com/download/release.html?mdfid=284152656&softwareid=282463166&release=1.0.1.10
I hope you find this information helpful and please do not hesitate to reach me back of there is any further assistance I may help you with.
Kind regards,
Jeffrey Rodriguez S. .:|:.:|:.
Cisco Customer Support Engineer
*Please rate the Post so other will know when an answer has been found. -
Network drives randomly disconnecting, unable to reconnect
I have been having an issue with network drives randomly disconnecting. When I try and reconnect using the Connect to Server dialog, the share is greyed out. My current workaround has been to open up terminal and run umount /Volume/Share_Name, and I am able to connect again afterwards. This is happening multiple times a day, and across multiple servers. I have poked around the forums and seen some people with similar issues, but the solution of connecting with cifs:// instead of smb:// has not made any difference.
which ultimately means apple didn't do enough testing before releasing the last patch
This is not always, and may not be, the case. What many don't realise is that many 3rd party developers stray from the 802.11 series specifications in an attampt to boost speed and get one up on their competitors. For instance D-Link, amongst others, use a short preamble setting by default in some of their routers to improve performance. However, this is non-standard and when it comes across wireless network adapters that don't support this then you have problems. They assume that their network adapters are being used for "maximum speed and compatibility". Whether Apple should or should not support a short preamble is another subject altogether.
However, I do agree with you in that Apple should put more work into their Airport software. -
AnyConnect client reconnects after 1 minute
AnyConnect client reconnects after 1 minute; WHY
version 3.1.02026
ASA:asa911-k8.bin
[25-4-2013 8:16:11] Establishing VPN session...
[25-4-2013 8:16:11] Checking for profile updates...
[25-4-2013 8:16:11] Checking for product updates...
[25-4-2013 8:16:11] Checking for customization updates...
[25-4-2013 8:16:11] Performing any required updates...
[25-4-2013 8:16:12] Establishing VPN session...
[25-4-2013 8:16:12] Establishing VPN - Initiating connection...
[25-4-2013 8:16:12] Establishing VPN - Examining system...
[25-4-2013 8:16:12] Establishing VPN - Activating VPN adapter...
[25-4-2013 8:16:15] Establishing VPN - Configuring system...
[25-4-2013 8:16:16] Establishing VPN...
[25-4-2013 8:16:16] Connected to my.vpn.com.
[25-4-2013 8:16:16] Connected to my.vpn.com.
[25-4-2013 8:17:19] Reconnecting to my.vpn.com...
[25-4-2013 8:17:19] Establishing VPN - Examining system...
[25-4-2013 8:17:24] Establishing VPN - Activating VPN adapter...
[25-4-2013 8:17:25] Establishing VPN - Configuring system...
[25-4-2013 8:17:25] Establishing VPN...
[25-4-2013 8:17:25] Connected to my.vpn.com.
[25-4-2013 8:17:25] Reconnecting to my.vpn.com...
[25-4-2013 8:17:25] Establishing VPN - Examining system...
[25-4-2013 8:17:25] Establishing VPN - Activating VPN adapter...
[25-4-2013 8:17:25] Establishing VPN - Configuring system...
[25-4-2013 8:17:25] Establishing VPN...
[25-4-2013 8:17:25] Connected to my.vpn.com.
[25-4-2013 8:16:11] Establishing VPN session...
[25-4-2013 8:16:11] Checking for profile updates...
[25-4-2013 8:16:11] Checking for product updates...
[25-4-2013 8:16:11] Checking for customization updates...
[25-4-2013 8:16:11] Performing any required updates...
[25-4-2013 8:16:12] Establishing VPN session...
[25-4-2013 8:16:12] Establishing VPN - Initiating connection...
[25-4-2013 8:16:12] Establishing VPN - Examining system...
[25-4-2013 8:16:12] Establishing VPN - Activating VPN adapter...
[25-4-2013 8:16:15] Establishing VPN - Configuring system...
[25-4-2013 8:16:16] Establishing VPN...
[25-4-2013 8:16:16] Connected to my.vpn.com.
[25-4-2013 8:16:16] Connected to my.vpn.com.
[25-4-2013 8:17:19] Reconnecting to my.vpn.com...
[25-4-2013 8:17:19] Establishing VPN - Examining system...
[25-4-2013 8:17:24] Establishing VPN - Activating VPN adapter...
[25-4-2013 8:17:25] Establishing VPN - Configuring system...
[25-4-2013 8:17:25] Establishing VPN...
[25-4-2013 8:17:25] Connected to my.vpn.com.
[25-4-2013 8:17:25] Reconnecting to my.vpn.com...
[25-4-2013 8:17:25] Establishing VPN - Examining system...
[25-4-2013 8:17:25] Establishing VPN - Activating VPN adapter...
[25-4-2013 8:17:25] Establishing VPN - Configuring system...
[25-4-2013 8:17:25] Establishing VPN...
[25-4-2013 8:17:25] Connected to my.vpn.com.Hello Michael,
The problem here is because we cannot succesfully establish a DTLS tunnel. This could happen because:
- DTLS is blocked somewhere in the path
- A non-default DTLS port is being used
If DTLS is blocked in the middle the issue is because as of ASA Release 9.x and AnyConnect Release 3.x, an optimization has been introduced in the form of distinct Maximum Transition Units (MTUs) that are negotiated for TLS/DTLS between the client/ASA. Previously, the client derived a rough estimate MTU which covered both TLS/DTLS and was obviously less than optimal. Now, the ASA computes the encapsulation overhead for both TLS/DTLS and derives the MTU values accordingly.
As long as DTLS is enabled, the client applies the DTLS MTU (in this case 1418) on the VPN adapter (which is enabled before the DTLS tunnel is established and is needed for routes/filters enforcement), to ensure optimum performance. If the DTLS tunnel cannot be established or it is dropped at some point, the client fails over to TLS and adjusts the MTU on the virtual adapter (VA) to the TLS MTU value (this requires a session level reconnect).
In order to eliminate this visible transition of DTLS > TLS, you can configure a separate tunnel group for TLS only access for users that have trouble with the establishment of the DTLS tunnel (such as due to firewall restrictions).
1. The best option is to set the AnyConnect MTU value to be lower than the TLS MTU, which is then negotiated.
group-policy ac_users_group attributes
webvpn
anyconnect mtu 1300
This makes TLS and DTLS MTU values equal. Reconnections are not seen in this case.
2. The second option is to allow fragmentation.
group-policy ac_users_group attributes
webvpn
anyconnect ssl df-bit-ignore enable
With fragmentation, large packets (whose size exceeds the MTU value) can be fragmented and sent through the TLS tunnel.
3. The third option is to set the Maximum Segment Size (MSS) to 1460 as follows:
sysopt conn tcpmss 1460
In this case, the TLS MTU will be 1427 (RC4/SHA1) which is larger than the DTLS MTU 1418 (AES/SHA1/LZS). This should resolve the issue with TCP from the ASA to the AnyConnect client (thanks to MSS), but large UDP traffic from the ASA to the AnyConnect client might suffer from this as it will be dropped by the AnyConnect client due to the lower AnyConnect client MTU 1418. If sysopt conn tcpmss is modified, it might affect other features such as LAN-to-LAN (L2L) IPSec VPN tunnels.
If DTLS is not blocked in the middle another potential cause for the DTLS failure that DTLS is configured on a non-default port after the WebVPN is enabled (for example, when the webvpn enable outside command is entered). This is due to Cisco bug ID CSCuh61321 and has been seen in Release 9.x where the ASA pushes the non-default port to the client, but continues to listen to the default port. Consequently, the DTLS is not built and AnyConnect reconnects.
The workaround for this problem is:
Disable the WebVPN.
Enter the DTLS port.
Enable the WebVPN.
Regards,
-Gustavo Medina -
We have an RDS environment configured on server 2012 with approx. 20 users connecting for remote app utilization across 4 different locations that are connected via VPN. Server 2012 has great resources from the virtual host so system resource allocation
shouldn't be an issue. I'm thinking these errors are correlating with the performance problems. Any recommendations on how to effectively end these errors or to boost performance?
RDS Log File
Log Name: Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational
Source: Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Date: 3/3/2015 7:47:51 PM
Event ID: 97
Task Category: RemoteFX module
Level: Warning
Keywords:
User: NETWORK SERVICE
Computer: REMOTE1.mzltg.local
Description: The RDP protocol component X.224 detected an error (0) in the protocol stream and the client was disconnected.
System Log Error Log Name: System
Source: Schannel
Date: 3/4/2015 10:42:02 AM
Event ID: 36887
Task Category: None
Level: Error
Keywords:
User: SYSTEM
Computer: REMOTE1.mzltg.local
Description: A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 49.Hi Shane,
Do you have any progress at the moment?
Regarding the TLS error code 49, it indicates a valid certificate was received, but when access control was applied, the sender did not proceed with negotiation.
More information for you:
SSL/TLS Alert Protocol & the Alert Codes
http://blogs.msdn.com/b/kaushal/archive/2012/10/06/ssl-tls-alert-protocol-amp-the-alert-codes.aspx
Best Regards,
Amy
Please remember to mark the replies as answers if they help and un-mark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected] -
Wrt600n / wpc600n random disconnect issues
hi,
i've been running the new AP / cards for a few weeks now, and am seeing some weird behavior on them.
when connected to the AP using either vista (using windows to manage wireless setting), or in xp (using the linksys utility), i'm getting random disconnects. the wireless connection will just drop from 1-10 seconds, then reconnect on it's own.
for these connections, i am forcing the AP and cards to use the n band.
the AP is set to N mode only, and all other settings on the AP are set to Auto. the clients are using all default settings as well, and this issues occurs during web surfing, email, etc. and is repeatable.
any suggestions?
Message Edited by d-rick on 01-20-2008 09:50 AMr u using the linksys adaptor on vista or on xp
if ur using it on vista
please download the drivers for vista from
www.linksys.com/vista
live life king size -
When I first got my phone it worked perfectly fine with the wifi. Although later on I began to have problems connecting it. It will randomly disconnect from the wifi and when I try to retype the password it tells me it is wrong, although it is right. It will eventually work but in its own time, a message will pop up and allow me to type in the password and it will work. But sometimes it takes an hour or more and sometime it takes 10 minutes. I've seen where other people have had this problem but I don't know how to fix it. I'm not sure if it's an issue with my phone or if it's with my wifi. Does anyone know how to fix this?
Does this happen with all Wi-Fi hotspots? A specific one?
Have you tried forgetting the Wi-Fi connection and then reconnecting to it?
What about power cycling the Wi-Fi router? -
Hi everyone,
it's probably just me but I have tried real hard to get a simple AnyConnect setup working in a lab environment on my ASA 5505 at home, without luck. When I connect with the AnyConnect client I get the error message "User not authorized for AnyConnect Client access, contact your administrator". I have searched for this error and tried some of the few solutions out there, but to no avail. I also updated the ASA from 8.4.4(1) to 9.1(1) and ASDM from 6.4(9) to 7.1(1) but still the same problem. The setup of the ASA is straight forward, directly connected to the Internet with a 10.0.1.0 / 24 subnet on the inside and an address pool of 10.0.2.0 / 24 to assign to the VPN clients. Please note that due to ISP restrictions, I'm using port 44455 instead of 443. I had AnyConnect working with the SSL portal, but IKEv2 IPsec is giving me a headache. I have stripped down certificate authentication which I had running before just to eliminate this as a potential cause of the issue. When running debugging, I do not get any error messages - the handshake completes successfully and the local authentication works fine as well.
Please find the current config and debugging output below. I appreciate any pointers as to what might be wrong here.
: Saved
ASA Version 9.1(1)
hostname ASA
domain-name ingo.local
enable password ... encrypted
xlate per-session deny tcp any4 any4
xlate per-session deny tcp any4 any6
xlate per-session deny tcp any6 any4
xlate per-session deny tcp any6 any6
xlate per-session deny udp any4 any4 eq domain
xlate per-session deny udp any4 any6 eq domain
xlate per-session deny udp any6 any4 eq domain
xlate per-session deny udp any6 any6 eq domain
passwd ... encrypted
names
name 10.0.1.0 LAN-10-0-1-x
dns-guard
ip local pool VPNPool 10.0.2.1-10.0.2.10 mask 255.255.255.0
interface Ethernet0/0
switchport access vlan 2
interface Ethernet0/1
interface Ethernet0/2
interface Ethernet0/3
interface Ethernet0/4
interface Ethernet0/5
interface Ethernet0/6
interface Ethernet0/7
interface Vlan1
nameif Internal
security-level 100
ip address 10.0.1.254 255.255.255.0
interface Vlan2
nameif External
security-level 0
ip address dhcp setroute
regex BlockFacebook "facebook.com"
banner login This is a monitored system. Unauthorized access is prohibited.
boot system disk0:/asa911-k8.bin
ftp mode passive
clock timezone PST -8
clock summer-time PDT recurring
dns domain-lookup Internal
dns domain-lookup External
dns server-group DefaultDNS
name-server 10.0.1.11
name-server 75.153.176.1
name-server 75.153.176.9
domain-name ingo.local
object network obj_any
subnet 0.0.0.0 0.0.0.0
object network LAN-10-0-1-x
subnet 10.0.1.0 255.255.255.0
object network Company-IP1
host xxx.xxx.xxx.xxx
object network Company-IP2
host xxx.xxx.xxx.xxx
object network HYPER-V-DUAL-IP
range 10.0.1.1 10.0.1.2
object network LAN-10-0-1-X
access-list 100 extended permit tcp any4 object HYPER-V-DUAL-IP eq 3389 inactive
access-list 100 extended permit tcp object Company-IP1 object HYPER-V-DUAL-IP eq 3389
access-list 100 extended permit tcp object Company-IP2 object HYPER-V-DUAL-IP eq 3389
tcp-map Normalizer
check-retransmission
checksum-verification
no pager
logging enable
logging timestamp
logging list Threats message 106023
logging list Threats message 106100
logging list Threats message 106015
logging list Threats message 106021
logging list Threats message 401004
logging buffered errors
logging trap Threats
logging asdm debugging
logging device-id hostname
logging host Internal 10.0.1.11 format emblem
logging ftp-bufferwrap
logging ftp-server 10.0.1.11 / asa *****
logging permit-hostdown
mtu Internal 1500
mtu External 1500
ip verify reverse-path interface Internal
ip verify reverse-path interface External
icmp unreachable rate-limit 1 burst-size 1
icmp deny any echo External
asdm image disk0:/asdm-711.bin
no asdm history enable
arp timeout 14400
no arp permit-nonconnected
object network obj_any
nat (Internal,External) dynamic interface
object network LAN-10-0-1-x
nat (Internal,External) dynamic interface
object network HYPER-V-DUAL-IP
nat (Internal,External) static interface service tcp 3389 3389
access-group 100 in interface External
timeout xlate 3:00:00
timeout pat-xlate 0:00:30
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
timeout tcp-proxy-reassembly 0:01:00
timeout floating-conn 0:00:00
dynamic-access-policy-record DfltAccessPolicy
aaa-server radius protocol radius
aaa-server radius (Internal) host 10.0.1.11
key *****
radius-common-pw *****
user-identity default-domain LOCAL
aaa authentication ssh console radius LOCAL
http server enable
http LAN-10-0-1-x 255.255.255.0 Internal
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
crypto ipsec ikev2 ipsec-proposal DES
protocol esp encryption des
protocol esp integrity sha-1 md5
crypto ipsec ikev2 ipsec-proposal 3DES
protocol esp encryption 3des
protocol esp integrity sha-1 md5
crypto ipsec ikev2 ipsec-proposal AES
protocol esp encryption aes
protocol esp integrity sha-1 md5
crypto ipsec ikev2 ipsec-proposal AES192
protocol esp encryption aes-192
protocol esp integrity sha-1 md5
crypto ipsec ikev2 ipsec-proposal AES256
protocol esp encryption aes-256
protocol esp integrity sha-1 md5
crypto ipsec security-association pmtu-aging infinite
crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set ikev2 ipsec-proposal AES256 AES192 AES 3DES DES
crypto map External_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP
crypto map External_map interface External
crypto ca trustpoint srv01_trustpoint
enrollment terminal
crl configure
crypto ca trustpoint asa_cert_trustpoint
keypair asa_cert_trustpoint
crl configure
crypto ca trustpoint LOCAL-CA-SERVER
keypair LOCAL-CA-SERVER
crl configure
crypto ca trustpool policy
crypto ca server
cdp-url http://.../+CSCOCA+/asa_ca.crl:44435
issuer-name CN=...
database path disk0:/LOCAL_CA_SERVER/
smtp from-address ...
publish-crl External 44436
crypto ca certificate chain srv01_trustpoint
certificate <output omitted>
quit
crypto ca certificate chain asa_cert_trustpoint
certificate <output omitted>
quit
crypto ca certificate chain LOCAL-CA-SERVER
certificate <output omitted>
quit
crypto ikev2 policy 1
encryption aes-256
integrity sha
group 5 2
prf sha
lifetime seconds 86400
crypto ikev2 policy 10
encryption aes-192
integrity sha
group 5 2
prf sha
lifetime seconds 86400
crypto ikev2 policy 20
encryption aes
integrity sha
group 5 2
prf sha
lifetime seconds 86400
crypto ikev2 policy 30
encryption 3des
integrity sha
group 5 2
prf sha
lifetime seconds 86400
crypto ikev2 policy 40
encryption des
integrity sha
group 5 2
prf sha
lifetime seconds 86400
crypto ikev2 enable External client-services port 44455
crypto ikev2 remote-access trustpoint asa_cert_trustpoint
telnet timeout 5
ssh LAN-10-0-1-x 255.255.255.0 Internal
ssh xxx.xxx.xxx.xxx 255.255.255.255 External
ssh xxx.xxx.xxx.xxx 255.255.255.255 External
ssh timeout 5
ssh version 2
console timeout 0
no vpn-addr-assign aaa
no ipv6-vpn-addr-assign aaa
no ipv6-vpn-addr-assign local
dhcpd dns 75.153.176.9 75.153.176.1
dhcpd domain ingo.local
dhcpd option 3 ip 10.0.1.254
dhcpd address 10.0.1.50-10.0.1.81 Internal
dhcpd enable Internal
threat-detection basic-threat
threat-detection scanning-threat shun except ip-address LAN-10-0-1-x 255.255.255.0
threat-detection statistics access-list
threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400 average-rate 200
dynamic-filter use-database
dynamic-filter enable interface Internal
dynamic-filter enable interface External
dynamic-filter drop blacklist interface Internal
dynamic-filter drop blacklist interface External
ntp server 128.233.3.101 source External
ntp server 128.233.3.100 source External prefer
ntp server 204.152.184.72 source External
ntp server 192.6.38.127 source External
ssl encryption aes256-sha1 aes128-sha1 3des-sha1
ssl trust-point asa_cert_trustpoint External
webvpn
port 44433
enable External
dtls port 44433
anyconnect image disk0:/anyconnect-win-3.1.02026-k9.pkg 1
anyconnect profiles profile1 disk0:/profile1.xml
anyconnect enable
smart-tunnel list SmartTunnelList1 mstsc mstsc.exe platform windows
smart-tunnel list SmartTunnelList1 putty putty.exe platform windows
group-policy DfltGrpPolicy attributes
vpn-tunnel-protocol ikev1 ikev2 l2tp-ipsec ssl-client ssl-clientless
webvpn
anyconnect profiles value profile1 type user
username write.ingo password ... encrypted
username ingo password ... encrypted privilege 15
username tom.tucker password ... encrypted
class-map TCP
match port tcp range 1 65535
class-map type regex match-any BlockFacebook
match regex BlockFacebook
class-map type inspect http match-all BlockDomains
match request header host regex class BlockFacebook
class-map inspection_default
match default-inspection-traffic
policy-map type inspect dns preset_dns_map
parameters
message-length maximum client auto
message-length maximum 1500
id-randomization
policy-map TCP
class TCP
set connection conn-max 1000 embryonic-conn-max 1000 per-client-max 250 per-client-embryonic-max 250
set connection timeout dcd
set connection advanced-options Normalizer
set connection decrement-ttl
policy-map type inspect http HTTP
parameters
protocol-violation action drop-connection log
class BlockDomains
policy-map global_policy
class inspection_default
inspect ftp
inspect h323 h225
inspect h323 ras
inspect rsh
inspect rtsp
inspect esmtp
inspect sqlnet
inspect skinny
inspect sunrpc
inspect xdmcp
inspect sip
inspect netbios
inspect tftp
inspect ip-options
inspect dns preset_dns_map dynamic-filter-snoop
inspect http HTTP
service-policy global_policy global
service-policy TCP interface External
smtp-server 199.185.220.249
privilege cmd level 3 mode exec command perfmon
privilege cmd level 3 mode exec command ping
privilege cmd level 3 mode exec command who
privilege cmd level 3 mode exec command logging
privilege cmd level 3 mode exec command failover
privilege cmd level 3 mode exec command vpn-sessiondb
privilege cmd level 3 mode exec command packet-tracer
privilege show level 5 mode exec command import
privilege show level 5 mode exec command running-config
privilege show level 3 mode exec command reload
privilege show level 3 mode exec command mode
privilege show level 3 mode exec command firewall
privilege show level 3 mode exec command asp
privilege show level 3 mode exec command cpu
privilege show level 3 mode exec command interface
privilege show level 3 mode exec command clock
privilege show level 3 mode exec command dns-hosts
privilege show level 3 mode exec command access-list
privilege show level 3 mode exec command logging
privilege show level 3 mode exec command vlan
privilege show level 3 mode exec command ip
privilege show level 3 mode exec command failover
privilege show level 3 mode exec command asdm
privilege show level 3 mode exec command arp
privilege show level 3 mode exec command ipv6
privilege show level 3 mode exec command route
privilege show level 3 mode exec command ospf
privilege show level 3 mode exec command aaa-server
privilege show level 3 mode exec command aaa
privilege show level 3 mode exec command eigrp
privilege show level 3 mode exec command crypto
privilege show level 3 mode exec command ssh
privilege show level 3 mode exec command vpn-sessiondb
privilege show level 3 mode exec command vpnclient
privilege show level 3 mode exec command vpn
privilege show level 3 mode exec command dhcpd
privilege show level 3 mode exec command blocks
privilege show level 3 mode exec command wccp
privilege show level 3 mode exec command dynamic-filter
privilege show level 3 mode exec command webvpn
privilege show level 3 mode exec command service-policy
privilege show level 3 mode exec command module
privilege show level 3 mode exec command uauth
privilege show level 3 mode exec command compression
privilege show level 3 mode configure command interface
privilege show level 3 mode configure command clock
privilege show level 3 mode configure command access-list
privilege show level 3 mode configure command logging
privilege show level 3 mode configure command ip
privilege show level 3 mode configure command failover
privilege show level 5 mode configure command asdm
privilege show level 3 mode configure command arp
privilege show level 3 mode configure command route
privilege show level 3 mode configure command aaa-server
privilege show level 3 mode configure command aaa
privilege show level 3 mode configure command crypto
privilege show level 3 mode configure command ssh
privilege show level 3 mode configure command dhcpd
privilege show level 5 mode configure command privilege
privilege clear level 3 mode exec command dns-hosts
privilege clear level 3 mode exec command logging
privilege clear level 3 mode exec command arp
privilege clear level 3 mode exec command aaa-server
privilege clear level 3 mode exec command crypto
privilege clear level 3 mode exec command dynamic-filter
privilege cmd level 3 mode configure command failover
privilege clear level 3 mode configure command logging
privilege clear level 3 mode configure command arp
privilege clear level 3 mode configure command crypto
privilege clear level 3 mode configure command aaa-server
prompt hostname context
no call-home reporting anonymous
call-home
profile CiscoTAC-1
no active
destination address http https://tools.cisco.com/its/service/oddce/services/DDCEService
destination address email [email protected]
destination transport-method http
subscribe-to-alert-group diagnostic
subscribe-to-alert-group environment
subscribe-to-alert-group inventory periodic monthly
subscribe-to-alert-group configuration periodic monthly
subscribe-to-alert-group telemetry periodic daily
Cryptochecksum:41a021a28f73c647a2f550ba932bed1a
: end
Many thanks,
IngoHi Jose,
here is what I got now:
ASA(config)# sh run | begin tunnel-group
tunnel-group DefaultWEBVPNGroup general-attributes
address-pool VPNPool
authorization-required
and DAP debugging still the same:
ASA(config)# DAP_TRACE: DAP_open: CDC45080
DAP_TRACE: Username: tom.tucker, aaa.cisco.grouppolicy = DfltGrpPolicy
DAP_TRACE: Username: tom.tucker, aaa.cisco.username = tom.tucker
DAP_TRACE: Username: tom.tucker, aaa.cisco.username1 = tom.tucker
DAP_TRACE: Username: tom.tucker, aaa.cisco.username2 =
DAP_TRACE: Username: tom.tucker, aaa.cisco.tunnelgroup = DefaultWEBVPNGroup
DAP_TRACE: Username: tom.tucker, DAP_add_SCEP: scep required = [FALSE]
DAP_TRACE: Username: tom.tucker, DAP_add_AC:
endpoint.anyconnect.clientversion="3.1.02026";
endpoint.anyconnect.platform="win";
DAP_TRACE: Username: tom.tucker, dap_aggregate_attr: rec_count = 1
DAP_TRACE: Username: tom.tucker, Selected DAPs: DfltAccessPolicy
DAP_TRACE: Username: tom.tucker, DAP_close: CDC45080
Unfortunately, it still doesn't work. Hmmm.. maybe a wipe of the config and starting from scratch can help?
Thanks,
Ingo -
Windows 8.1 Preview not working with AnyConnect Client
I had Windows 8 and was running Cisco AnyConnect client 3.0.10055 perfectly.
I upgraded to the Windows 8.1 preview and it tries to download update and then it fails and disconnects with the following message:
An unknown termination error occurred in the client.
Tried uninstalling and reinstalling the client, no luck.
Any ideas?
Thanks,
EricI had the same issue with windows 8.1 x64. I believe there is an issue with the windows 8.1 update process where it fails to update some of the drivers properly. I have noticed this issue with other windows drivers after the update. Follow the steps below and you VPN should work again.
1. Uninstall Cisco Anyconnect client.
2. Go to Device Manager and Disable Cisco AnyConnect VPN Virtual Miniport Adapter for Windows x64
3. Go to C:\Windows\System32 and rename vpnva64.sys to vpnva64_Old.sys.
4. Reinstall Cisco Anyconnect client.
5. Go to Device Manager, you see duplicated Cisco AnyConnect VPN Virtual Adapters. Uninstall one of them but do not check the option to remove the driver.
6. Apply the registry fix in this blog: http://www.tomontech.com/2012/03/pro-tip-cisco-anyconnect-vpn-client-and-windows-8-consumer-preview/
7. Try to connect again and your Cisco VPN should work.
Maybe you are looking for
-
Selecting the contents of a table(collection) into a strong REF Cursor
I'm trying to roll some data into a table collection and return it as a strong named cursor. I have not been able to do this successfully yet. I have tried casting the table and I couldn't get that to work either. I have included the whole procedure
-
Whenever I attempt to play a wmv file on Media Player I get the round spinning beachball for about 2 minutes and then Media Player pops up and there is a lot of weird Chinese looking writing in the play window and the video does not play. This began
-
I subscribe to comics.com and get a dailiy email of comics. Unfortunately, sometimes Mail does not download the embedded images and leaves the little blue question mark box in the place of the comics. There appears to be no way to force Mail to go ge
-
HT201413 DEP closes iTunes and won't allow it to open. Any suggestions?
I can't open iTunes...I get a message re DEP. Any suggestions on what to do?
-
Will there be a 10.1.3 version of TemplateMaker?
Since it is a "pseudo-official" power toy ... will Oracle (Brian) provide an update there? Thanks. Sascha