AnyConnect clients randomly disconnect, reconnect

Hello,
We have been using our current configuration for some time, but recently most of the AnyConnect clients randomly loose connection, then reconnect. I have had the ISP and SonicWall look to see if they find any issue, but they do not. I have checked the event viewer on one XP machine and find numerous log entries regarding connection timeouts, etc. I have listed some below. A search of this comunity resulted in only one response that was incomplete.
This entry is listed as Error, Event ID 2, source is vpnagent:
Function: CHttpProbeAsync::OnOpenRequestComplete
File: .\IP\HttpProbeAsync.cpp
Line: 254
Invoked Function: CHttpSessionAsync::OnOpenRequestComplete
Return Code: -31522780 (0xFE1F0024)
Description: SOCKETTRANSPORT_ERROR_CONNECT_TIMEOUT
Another error:
Function: CNetEnvironment::TestNetEnv
File: .\NetEnvironment.cpp
Line: 190
Invoked Function: CNetEnvironment::testNetwork
Return Code: -28901363 (0xFE47000D)
Description: NETENVIRONMENT_ERROR_PROBE_INCOMPLETE:Network Probe could not contact target
This entry is a Warning:
Function: CNetEnvironment::logProbeFailure
File: .\NetEnvironment.cpp
Line: 1068
Invoked Function: CHttpProbeAsync::SendProbe
Return Code: -27787250 (0xFE58000E)
Description: HTTP_PROBE_ASYNC_ERROR_CANNOT_CONNECT
HTTP (host: 198.210.1.1)
Another Warning:
Reconnect reason code 6:
Reconnecting due to the disruption of the VPN connection to the secure gateway.
There are numerous information logs referring to reconnecting, VPN connection re-established, primary SSL connection to the secure gateway is down.
Anyone have ideas on how to troubleshoot this?
Thank you for any suggestions.

Bill,
Were you able to diagnose why this issue was/is occuring? We are experiencing a similar issue with a user in our organization:
Session level reconnect reason code 6:
Disruption of the VPN connection to the secure gateway.
Originates from tunnel level
Function: CSslTunnelTransport::OnTransportInitiateComplete
File: .\SslTunnelTransport.cpp
Line: 363
Invoked Function: CTcpTransport::initiateTransport
Return Code: -31588316 (0xFE1E0024)
Description: SOCKETTRANSPORT_ERROR_CONNECT_TIMEOUT

Similar Messages

  • EA6300 Random Disconnects/Reconnects

    I have a newish EA6300 router, and the connection will randomly but often (every 15min or so) drop for a second and then reconnect.  The firmware is 1.1.40.153731.  I have two laptops in the house and this issue happens on both computers.  I also have another wireless router (Zoom N150) and when I connect the computers to that router the connection is stable and never drops.   Any idea why I'm getting these random disconnect/reconnect issues with the EA6300? I would very much like to only use the Linksys router because of its superior power, range and ability to handle more devices and traffic, as well as eventual AC capability.  However I can't use it as a primary connections because of this issue.

    Thanks for the reply.  I had already changed the channel and it did seem to improve things.  I still get disconnects but they are MUCH less frequent.  My next step will be to move the Linksys router away from another wireless router that is nearby that may be causing interference. I have another question.  I have used inSSIDer to examine the signal strength of the wireless networks around my home.  This is what helped me to know what channel to switch the Linksys router to.  But I've noticed that inSSIDer shows two networks when the Linksys router is on.  I do not have a 5ghz wireless card in my computer, so only the 2.4ghz band shows as a network.  One of the networks is my network that I have named, but the other network is unnamed (no SSID), and this mystery network will occassionally get a big drop in signal strength.  I have attached a screen shot.  The blue line is my main (named) personal network, an the yellow line is the mystery network that turns on when the router is on.  You can see the downward spike in that yellow line that indicates a momentary loss of signal in that mystery network.   Any idea why two networks show up?  And if their coming from the same router, why would one lose signal while the other doesn't?  Again, I don't have an AC network card, so I'm not seeing a 5ghz band so the second one can't be that.

  • Cisco VPN Client Random Disconnects

    I am connecting to our ASA5510 via Cisco VPN client version 5.x. I am getting continuous disconnects at random times. I have never had a connection last more than 10 minutes. The disconnects happen when the session is idle and also when the session is active. I have had the connection drop on me in the middle of a file transfer even. I have set the session timeout to unlimited but no help. Does anyone have any ideas?
    Thanks,
    Ken

    The reason for that disconnection might be one of the following:
    1) You reached an idle timeout.Increase the idle timeout value.
    2) Someone cleared the tunnel.check for the tunnel configuration.
    3) Your SA has a very short lifetime.
    check if isakmp nat-t is enabled.If not enable the same and check for the issue.
    check if TunnelEstablished Registry key is set to 0 which is the right one.
    Refer the following url for more info on troubleshooting VPN issue:
    http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807e0aca.shtml#isalife

  • WAP371 clients constantly disconnecting/reconnecting

    I have a new WAP371 with firmware 1.1.2.3. It's installed on an interior wall on the second floor of my three-floor house. It receives power over Ethernet from an SG200-08P switch. Each radio has a separate SSID. WPA-Personal is used on both. All traffic is in untagged VLAN 1.
    Clients are will not stay connected for longer than a minute or two. The log shows an association, then after usually one or two minutes, the log shows a deauth with the message "Disassociated due to inactivity." Then the very next item in the log is another association from the client. This will persist for a minute or two, and then the cycle repeats, continually and forever. This happens even when there is activity, so "Disassociated due to inactivity" seems wrong.
    Following various bits of advice here, I've tried:
    various fixed frequencies
    all bandwidth options
    short guard interval yes and no
    protection auto and off
    frame burst on and off
    fixed multicast rate auto and 54
    removed 1 and 2 from legacy rate sets on the 2.4 GHz radio
    set broadcast key refresh rate to 0
    disabled TSPEC, scheduler, bandwidth utilization, client QoS, Green Ethernet
    I'm at a loss to figure out how to fix this. It causes activity on the clients to sputter -- I'm seeing a fair number of retransmissions. Occasionally application connections, like streaming video, will reset. Help please?

    My name Eric Moyers. I am an Engineer in the Small Business Support Center.
    I am sorry to hear that you are experiencing this issue. 
    I feel that this is an issue that will be difficult to effectively troubleshoot through chatting on the forums. You will get better results for something this complicated by opening a case with one of our engineers directly.
    Please call our support center and open a case so that one of them can work directly with you.
    http://www.cisco.com/c/en/us/support/web/tsd-cisco-small-business-support-center-contacts.html
    If you like you can repost the case number here and I can check in on your case as well. 
    Eric Moyers
    .:|:.:|:. CISCO | Cisco Presales Technical Support | Wireless Subject Matter Expert
    Please rate helpful Posts and Let others know when your Question has been answered.

  • IChat lately started randomly disconnecting/reconnecting

    anyone smart enough to know what this means?
    6/21/10 11:03:05 AM iChatAgent[242] [Warning] SocketStream: error Error Domain=NSPOSIXErrorDomain Code=54 UserInfo=0x100227ec0 "The operation couldn’t be completed. Connection reset by peer" occurred on input stream
    6/21/10 11:03:05 AM iChatAgent[242] [Warning] XMLStream: error Error Domain=NSPOSIXErrorDomain Code=54 UserInfo=0x100227ec0 "The operation couldn’t be completed. Connection reset by peer" occurred on input
    6/21/10 11:03:05 AM iChatAgent[242] [Warning] JConnection: Error: Error Domain=NSPOSIXErrorDomain Code=54 UserInfo=0x100227ec0 "The operation couldn’t be completed. Connection reset by peer"
    ...and how i get it to stop happening?
    i haven't changed anything with my network settings that i can think of.

    Hi,
    If you mean you don't want to Disable SSL you need to know that when the AIM SSL server Fails, iChat resorts to a NON SSL login and iChat has to be Manually reset to use SSL when the server comes back on Line. It does not happen automatically.
    If you mean it did not work then also try deleting com.apple.iChat.AIM.plist and restart iChat so it is recreated.
    The file is found in your Home Folder/Library/Preferences.
    7:51 PM Thursday; June 24, 2010
    Please, if posting Logs, do not post any Log info after the line "Binary Images for iChat"

  • CUPC random disconnect

    Hi,
    I have a few people who have been saying that their CUPC client randomly disconnects and they can't reconnect for a long time, even through reboots.  I have a feeling that it's somehow an LDAP timeout, but I don't know.  Regular ethernet and phone connectivity remains normal.  I have attached the problem report from one of the people.  Can anyone decipher what might be happening?

    Do you happen to have a timestamp when you saw this issue?  There are quite a few log files in here.
    --Matt

  • AnyConnect Client (3.1.02040) - Windows 8 won't shut down

    I've noticed and issue with Windows 8 and AnyConnect Client version 3.1.02040.  I've tried various things to try to resolve this issue but have hit a brick wall.  Whenever, I run AnyConnect on my Windows 8 PC and then shut it down for the day, the PC won't turn off.  I've ensured my AnyConnect client is disconnected and then quit the application and even killed the VPN service.
    Has anyone else seen this issue???   Any resolution???

    I also have the same problem.  There is a few things that I have noticed...
    1.  If you disable the Network List Service and the Network Location awareness Services and reboot, this problem does not occure.  However, when you disable these services, you are no longer able to manager you network connections.
    2.  There are many errors that appear in the cisco anyconnect secure mobility client event log
    System
    Provider
    [ Name]
    acvpnagent
    EventID
    2
    [ Qualifiers]
    9216
    Level
    2
    Task
    1
    Keywords
    0x80000000000000
    TimeCreated
    [ SystemTime]
    2013-02-28T20:36:21.000000000Z
    EventRecordID
    942
    Channel
    Cisco AnyConnect Secure Mobility Client
    Computer
    PC2578.swgao.int
    Security
    EventData
    Function: CThread::invokeRun File: .\Utility\Thread.cpp Line: 435 Invoked Function: IRunnable::Run Return Code: -32112629 (0xFE16000B) Description: BROWSERPROXY_ERROR_NO_PROXY_FILE
    Provider
    [ Name]
    acvpnagent
    EventID
    2
    [ Qualifiers]
    9216
    Level
    2
    Task
    1
    Keywords
    0x80000000000000
    TimeCreated
    [ SystemTime]
    2013-02-28T20:36:21.000000000Z
    EventRecordID
    940
    Channel
    Cisco AnyConnect Secure Mobility Client
    Computer
    PC2578.swgao.int
    Security
    EventData
    Function: CVirtualAdapter::IsVAEnabled File: .\WindowsVirtualAdapter.cpp Line: 2685 Invoked Function: CVirtualAdapter::IsVAEnabled Return Code: -33554423 (0xFE000009) Description: GLOBAL_ERROR_UNEXPECTED Unexpected VA status bits, 25174019
    System
    Provider
    [ Name]
    acvpnagent
    EventID
    2
    [ Qualifiers]
    9216
    Level
    3
    Task
    1
    Keywords
    0x80000000000000
    TimeCreated
    [ SystemTime]
    2013-02-28T20:36:21.000000000Z
    EventRecordID
    936
    Channel
    Cisco AnyConnect Secure Mobility Client
    Computer
    PC2578.swgao.int
    Security
    EventData
    Function: CVAMgr::cleanupAddress File: .\VAMgr.cpp Line: 2449 Invoked Function: CNetshDeleteAddress::Run Return Code: -31064051 (0xFE26000D) Description: NETSHCOMMAND_ERROR_PARSE_FAILED
    I'm not sure what anyconnect is doing, but it appear when disconnecting something is prevting it from resetting all of the network settings.

  • WAP321 random disconnecting clients

    Hi all,
    I'm having problems with my WAP321 that is randomly disconnecting clients. It's not disconnecting all clients, but just a couple of clients. It's random which clients get disconnected and it can be different clients that will be disconnected when it happens a couple times, but they do get disconnected at the same time.
    My setup:
    Cisco ASA5505
    |
    Cisco WAP321
    |
    Cisco 7925 phone - iPhone - Macbook - three IP cam's (different brands) - and some more clients
    Last time it occurred I just for sure changed DHCP server from Cisco ASA5505 to two windows servers, now it happened again, my 7925 started beeping (enabled SSID monitoring on it so it alerts when it isn't connected to my Callmanager) and my iPhone couldn't connect to the SSID. My Macbook was still just connected. Retrieved a diagnostics report and checked the logging, rebooted the WAP321 and everything started connecting again.
    Noticed screens are scaled so hope it's readable...
    The MAC address is my iphone. I turned off the 7925 because the beeping was annoying so no logging from the 7925 trying to connect.
    Logging is saying:
    assoc request from [mac] BSSID [bssid] SSID LEVELS
    STA [mac] deauthed from BSSID [bssid] reason 3: STA is leaving IBSS or ESS
    There is nothing wrong with the coverage, the WAP321 is about ten feet from the iPhone and Cisco 7925 phone
    Can anybody help me how to best troubleshoot this issue. I'm not familiar with the troubleshoot/debug options available for the WAP321

    Dear Wesley,
    Thank you for reaching the Small Business Support Community.
    There is an opened caveat on the latest firmware release, version 1.0.4.2; CSCue24521:
    -Symptom: Some clients may lose wireless connection when authenticating via Captive portal.
    -Workaround: Reconnect wireless devices.
    If this is not the case I'd like to know if you have tried using a different IEEE 802.11 standard, same as a different authentication type.  If you are not running the latest firmware release I then suggest you to, and something else I've seen from experience that fixes similar issues is to reset to factory conditions and reconfigure manually.
    http://software.cisco.com/download/release.html?mdfid=284152656&softwareid=282463166&release=1.0.1.10
    I hope you find this information helpful and please do not hesitate to reach me back of there is any further assistance I may help you with.
    Kind regards,
    Jeffrey Rodriguez S. .:|:.:|:.
    Cisco Customer Support Engineer
    *Please rate the Post so other will know when an answer has been found.

  • Network drives randomly disconnecting, unable to reconnect

    I have been having an issue with network drives randomly disconnecting. When I try and reconnect using the Connect to Server dialog, the share is greyed out. My current workaround has been to open up terminal and run umount /Volume/Share_Name, and I am able to connect again afterwards. This is happening multiple times a day, and across multiple servers. I have poked around the forums and seen some people with similar issues, but the solution of connecting with cifs:// instead of smb:// has not made any difference.

    which ultimately means apple didn't do enough testing before releasing the last patch
    This is not always, and may not be, the case. What many don't realise is that many 3rd party developers stray from the 802.11 series specifications in an attampt to boost speed and get one up on their competitors. For instance D-Link, amongst others, use a short preamble setting by default in some of their routers to improve performance. However, this is non-standard and when it comes across wireless network adapters that don't support this then you have problems. They assume that their network adapters are being used for "maximum speed and compatibility". Whether Apple should or should not support a short preamble is another subject altogether.
    However, I do agree with you in that Apple should put more work into their Airport software.

  • AnyConnect client reconnects after 1 minute

    AnyConnect client reconnects after 1 minute; WHY
    version 3.1.02026
    ASA:asa911-k8.bin
    [25-4-2013 8:16:11] Establishing VPN session...
    [25-4-2013 8:16:11] Checking for profile updates...
    [25-4-2013 8:16:11] Checking for product updates...
    [25-4-2013 8:16:11] Checking for customization updates...
    [25-4-2013 8:16:11] Performing any required updates...
    [25-4-2013 8:16:12] Establishing VPN session...
    [25-4-2013 8:16:12] Establishing VPN - Initiating connection...
    [25-4-2013 8:16:12] Establishing VPN - Examining system...
    [25-4-2013 8:16:12] Establishing VPN - Activating VPN adapter...
    [25-4-2013 8:16:15] Establishing VPN - Configuring system...
    [25-4-2013 8:16:16] Establishing VPN...
    [25-4-2013 8:16:16] Connected to my.vpn.com.
    [25-4-2013 8:16:16] Connected to my.vpn.com.
    [25-4-2013 8:17:19] Reconnecting to my.vpn.com...
    [25-4-2013 8:17:19] Establishing VPN - Examining system...
    [25-4-2013 8:17:24] Establishing VPN - Activating VPN adapter...
    [25-4-2013 8:17:25] Establishing VPN - Configuring system...
    [25-4-2013 8:17:25] Establishing VPN...
    [25-4-2013 8:17:25] Connected to my.vpn.com.
    [25-4-2013 8:17:25] Reconnecting to my.vpn.com...
    [25-4-2013 8:17:25] Establishing VPN - Examining system...
    [25-4-2013 8:17:25] Establishing VPN - Activating VPN adapter...
    [25-4-2013 8:17:25] Establishing VPN - Configuring system...
    [25-4-2013 8:17:25] Establishing VPN...
    [25-4-2013 8:17:25] Connected to my.vpn.com.
    [25-4-2013 8:16:11] Establishing VPN session...
    [25-4-2013 8:16:11] Checking for profile updates...
    [25-4-2013 8:16:11] Checking for product updates...
    [25-4-2013 8:16:11] Checking for customization updates...
    [25-4-2013 8:16:11] Performing any required updates...
    [25-4-2013 8:16:12] Establishing VPN session...
    [25-4-2013 8:16:12] Establishing VPN - Initiating connection...
    [25-4-2013 8:16:12] Establishing VPN - Examining system...
    [25-4-2013 8:16:12] Establishing VPN - Activating VPN adapter...
    [25-4-2013 8:16:15] Establishing VPN - Configuring system...
    [25-4-2013 8:16:16] Establishing VPN...
    [25-4-2013 8:16:16] Connected to my.vpn.com.
    [25-4-2013 8:16:16] Connected to my.vpn.com.
    [25-4-2013 8:17:19] Reconnecting to my.vpn.com...
    [25-4-2013 8:17:19] Establishing VPN - Examining system...
    [25-4-2013 8:17:24] Establishing VPN - Activating VPN adapter...
    [25-4-2013 8:17:25] Establishing VPN - Configuring system...
    [25-4-2013 8:17:25] Establishing VPN...
    [25-4-2013 8:17:25] Connected to my.vpn.com.
    [25-4-2013 8:17:25] Reconnecting to my.vpn.com...
    [25-4-2013 8:17:25] Establishing VPN - Examining system...
    [25-4-2013 8:17:25] Establishing VPN - Activating VPN adapter...
    [25-4-2013 8:17:25] Establishing VPN - Configuring system...
    [25-4-2013 8:17:25] Establishing VPN...
    [25-4-2013 8:17:25] Connected to my.vpn.com.

    Hello Michael,
    The problem here is because we cannot succesfully establish a DTLS tunnel. This could happen because:
    - DTLS is blocked somewhere in the path
    - A non-default DTLS port is being used
    If DTLS is blocked in the middle the issue is because as of ASA Release 9.x and AnyConnect Release 3.x, an optimization has been introduced in the form of distinct Maximum Transition Units (MTUs) that are negotiated for TLS/DTLS between the client/ASA. Previously, the client derived a rough estimate MTU which covered both TLS/DTLS and was obviously less than optimal. Now, the ASA computes the encapsulation overhead for both TLS/DTLS and derives the MTU values accordingly.
    As long as DTLS is enabled, the client applies the DTLS MTU (in this case 1418) on the VPN adapter (which is enabled before the DTLS tunnel is established and is needed for routes/filters enforcement), to ensure optimum performance. If the DTLS tunnel cannot be established or it is dropped at some point, the client fails over to TLS and adjusts the MTU on the virtual adapter (VA) to the TLS MTU value (this requires a session level reconnect).
    In order to eliminate this visible transition of DTLS > TLS,  you can configure a separate tunnel group for TLS only access for users that have trouble with the establishment of the DTLS tunnel (such as due to firewall restrictions).
    1. The best option is to set the AnyConnect MTU value to be lower than the TLS MTU, which is then negotiated.
    group-policy ac_users_group attributes
    webvpn
      anyconnect mtu 1300
    This makes TLS and DTLS MTU values equal. Reconnections are not seen in this case.
    2. The second option is to allow fragmentation.
    group-policy ac_users_group attributes
    webvpn
      anyconnect ssl df-bit-ignore enable
    With fragmentation, large packets (whose size exceeds the MTU value) can be fragmented and sent through the TLS tunnel.
    3. The third option is to set the Maximum Segment Size (MSS) to 1460 as follows:
    sysopt conn tcpmss 1460
    In this case, the TLS MTU will be 1427 (RC4/SHA1) which is larger than the DTLS MTU 1418 (AES/SHA1/LZS). This should resolve the issue with TCP from the ASA to the AnyConnect client (thanks to MSS), but large UDP traffic from the ASA to the AnyConnect client might suffer from this as it will be dropped by the AnyConnect client due to the lower AnyConnect client MTU 1418. If sysopt conn tcpmss is modified, it might affect other features such as LAN-to-LAN (L2L) IPSec VPN tunnels.
    If DTLS is not blocked in the middle another potential cause for the DTLS failure that DTLS is configured on a non-default port after the WebVPN is enabled (for example, when the webvpn enable outside command is entered). This is due to Cisco bug ID CSCuh61321 and has been seen in Release 9.x where the ASA pushes the non-default port to the client, but continues to listen to the default port. Consequently, the DTLS is not built and AnyConnect reconnects.
    The workaround for this problem is:
    Disable the WebVPN.
    Enter the DTLS port.
    Enable the WebVPN.
    Regards,
    -Gustavo Medina

  • RDS 2012 - Slow Perforamance, random disconnects - The RDP protocol component X.224 detected an error (0) in the protocol stream and the client was disconnected.

    We have an RDS environment configured on server 2012 with approx. 20 users connecting for remote app utilization across 4 different locations that are connected via VPN. Server 2012 has great resources from the virtual host so system resource allocation
    shouldn't be an issue. I'm thinking these errors are correlating with the performance problems. Any recommendations on how to effectively end these errors or to boost performance?
    RDS Log File
    Log Name:      Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational
    Source:        Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
    Date:          3/3/2015 7:47:51 PM
    Event ID:      97
    Task Category: RemoteFX module
    Level:         Warning
    Keywords:     
    User:          NETWORK SERVICE
    Computer:      REMOTE1.mzltg.local
    Description: The RDP protocol component X.224 detected an error (0) in the protocol stream and the client was disconnected.
    System Log Error Log Name:      System
    Source:        Schannel
    Date:          3/4/2015 10:42:02 AM
    Event ID:      36887
    Task Category: None
    Level:         Error
    Keywords:     
    User:          SYSTEM
    Computer:      REMOTE1.mzltg.local
    Description: A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 49.

    Hi Shane,
    Do you have any progress at the moment?
    Regarding the TLS error code 49, it indicates a valid certificate was received, but when access control was applied, the sender did not proceed with negotiation.
    More information for you:
    SSL/TLS Alert Protocol & the Alert Codes
    http://blogs.msdn.com/b/kaushal/archive/2012/10/06/ssl-tls-alert-protocol-amp-the-alert-codes.aspx
    Best Regards,
    Amy
    Please remember to mark the replies as answers if they help and un-mark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected]

  • Wrt600n / wpc600n random disconnect issues

    hi,
    i've been running the new AP / cards for a few weeks now, and am seeing some weird behavior on them.
    when connected to the AP using either vista (using windows to manage wireless setting), or in xp (using the linksys utility), i'm getting random disconnects. the wireless connection will just drop from 1-10 seconds, then reconnect on it's own.
    for these connections, i am forcing the AP and cards to use the n band.
    the AP is set to N mode only, and all other settings on the AP are set to Auto. the clients are using all default settings as well, and this issues occurs during web surfing, email, etc. and is repeatable.
    any suggestions?
    Message Edited by d-rick on 01-20-2008 09:50 AM

    r u using the linksys adaptor on vista or on xp
    if ur using it on vista
    please download the drivers for vista from
    www.linksys.com/vista
    live life king size

  • My phone will randomly disconnect from the wifi and when I retype the password it says it is wrong. It will eventually work but I have to wait for a message to pop up on my screen to allow me to retype the wifi password.

    When I first got my phone it worked perfectly fine with the wifi. Although later on I began to have problems connecting it. It will randomly disconnect from the wifi and when I try to retype the password it tells me it is wrong, although it is right. It will eventually work but in its own time, a message will pop up and allow me to type in the password and it will work. But sometimes it takes an hour or more and sometime it takes 10 minutes. I've seen where other people have had this problem but I don't know how to fix it. I'm not sure if it's an issue with my phone or if it's with my wifi. Does anyone know how to fix this?

    Does this happen with all Wi-Fi hotspots?  A specific one?
    Have you tried forgetting the Wi-Fi connection and then reconnecting to it?
    What about power cycling the Wi-Fi router?

  • AnyConnect error " User not authorized for AnyConnect Client access, contact your administrator"

    Hi everyone,
    it's probably just me but I have tried real hard to get a simple AnyConnect setup working in a lab environment on my ASA 5505 at home, without luck. When I connect with the AnyConnect client I get the error message "User not authorized for AnyConnect Client access, contact your administrator". I have searched for this error and tried some of the few solutions out there, but to no avail. I also updated the ASA from 8.4.4(1) to 9.1(1) and ASDM from 6.4(9) to 7.1(1) but still the same problem. The setup of the ASA is straight forward, directly connected to the Internet with a 10.0.1.0 / 24 subnet on the inside and an address pool of 10.0.2.0 / 24 to assign to the VPN clients. Please note that due to ISP restrictions, I'm using port 44455 instead of 443. I had AnyConnect working with the SSL portal, but IKEv2 IPsec is giving me a headache. I have stripped down certificate authentication which I had running before just to eliminate this as a potential cause of the issue. When running debugging, I do not get any error messages - the handshake completes successfully and the local authentication works fine as well.
    Please find the current config and debugging output below. I appreciate any pointers as to what might be wrong here.
    : Saved
    ASA Version 9.1(1)
    hostname ASA
    domain-name ingo.local
    enable password ... encrypted
    xlate per-session deny tcp any4 any4
    xlate per-session deny tcp any4 any6
    xlate per-session deny tcp any6 any4
    xlate per-session deny tcp any6 any6
    xlate per-session deny udp any4 any4 eq domain
    xlate per-session deny udp any4 any6 eq domain
    xlate per-session deny udp any6 any4 eq domain
    xlate per-session deny udp any6 any6 eq domain
    passwd ... encrypted
    names
    name 10.0.1.0 LAN-10-0-1-x
    dns-guard
    ip local pool VPNPool 10.0.2.1-10.0.2.10 mask 255.255.255.0
    interface Ethernet0/0
    switchport access vlan 2
    interface Ethernet0/1
    interface Ethernet0/2
    interface Ethernet0/3
    interface Ethernet0/4
    interface Ethernet0/5
    interface Ethernet0/6
    interface Ethernet0/7
    interface Vlan1
    nameif Internal
    security-level 100
    ip address 10.0.1.254 255.255.255.0
    interface Vlan2
    nameif External
    security-level 0
    ip address dhcp setroute
    regex BlockFacebook "facebook.com"
    banner login This is a monitored system. Unauthorized access is prohibited.
    boot system disk0:/asa911-k8.bin
    ftp mode passive
    clock timezone PST -8
    clock summer-time PDT recurring
    dns domain-lookup Internal
    dns domain-lookup External
    dns server-group DefaultDNS
    name-server 10.0.1.11
    name-server 75.153.176.1
    name-server 75.153.176.9
    domain-name ingo.local
    object network obj_any
    subnet 0.0.0.0 0.0.0.0
    object network LAN-10-0-1-x
    subnet 10.0.1.0 255.255.255.0
    object network Company-IP1
    host xxx.xxx.xxx.xxx
    object network Company-IP2
    host xxx.xxx.xxx.xxx
    object network HYPER-V-DUAL-IP
    range 10.0.1.1 10.0.1.2
    object network LAN-10-0-1-X
    access-list 100 extended permit tcp any4 object HYPER-V-DUAL-IP eq 3389 inactive
    access-list 100 extended permit tcp object Company-IP1 object HYPER-V-DUAL-IP eq 3389
    access-list 100 extended permit tcp object Company-IP2 object HYPER-V-DUAL-IP eq 3389 
    tcp-map Normalizer
      check-retransmission
      checksum-verification
    no pager
    logging enable
    logging timestamp
    logging list Threats message 106023
    logging list Threats message 106100
    logging list Threats message 106015
    logging list Threats message 106021
    logging list Threats message 401004
    logging buffered errors
    logging trap Threats
    logging asdm debugging
    logging device-id hostname
    logging host Internal 10.0.1.11 format emblem
    logging ftp-bufferwrap
    logging ftp-server 10.0.1.11 / asa *****
    logging permit-hostdown
    mtu Internal 1500
    mtu External 1500
    ip verify reverse-path interface Internal
    ip verify reverse-path interface External
    icmp unreachable rate-limit 1 burst-size 1
    icmp deny any echo External
    asdm image disk0:/asdm-711.bin
    no asdm history enable
    arp timeout 14400
    no arp permit-nonconnected
    object network obj_any
    nat (Internal,External) dynamic interface
    object network LAN-10-0-1-x
    nat (Internal,External) dynamic interface
    object network HYPER-V-DUAL-IP
    nat (Internal,External) static interface service tcp 3389 3389
    access-group 100 in interface External
    timeout xlate 3:00:00
    timeout pat-xlate 0:00:30
    timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
    timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
    timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
    timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
    timeout tcp-proxy-reassembly 0:01:00
    timeout floating-conn 0:00:00
    dynamic-access-policy-record DfltAccessPolicy
    aaa-server radius protocol radius
    aaa-server radius (Internal) host 10.0.1.11
    key *****
    radius-common-pw *****
    user-identity default-domain LOCAL
    aaa authentication ssh console radius LOCAL
    http server enable
    http LAN-10-0-1-x 255.255.255.0 Internal
    no snmp-server location
    no snmp-server contact
    snmp-server enable traps snmp authentication linkup linkdown coldstart
    crypto ipsec ikev2 ipsec-proposal DES
    protocol esp encryption des
    protocol esp integrity sha-1 md5
    crypto ipsec ikev2 ipsec-proposal 3DES
    protocol esp encryption 3des
    protocol esp integrity sha-1 md5
    crypto ipsec ikev2 ipsec-proposal AES
    protocol esp encryption aes
    protocol esp integrity sha-1 md5
    crypto ipsec ikev2 ipsec-proposal AES192
    protocol esp encryption aes-192
    protocol esp integrity sha-1 md5
    crypto ipsec ikev2 ipsec-proposal AES256
    protocol esp encryption aes-256
    protocol esp integrity sha-1 md5
    crypto ipsec security-association pmtu-aging infinite
    crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set ikev2 ipsec-proposal AES256 AES192 AES 3DES DES
    crypto map External_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP
    crypto map External_map interface External
    crypto ca trustpoint srv01_trustpoint
    enrollment terminal
    crl configure
    crypto ca trustpoint asa_cert_trustpoint
    keypair asa_cert_trustpoint
    crl configure
    crypto ca trustpoint LOCAL-CA-SERVER
    keypair LOCAL-CA-SERVER
    crl configure
    crypto ca trustpool policy
    crypto ca server
    cdp-url http://.../+CSCOCA+/asa_ca.crl:44435
    issuer-name CN=...
    database path disk0:/LOCAL_CA_SERVER/
    smtp from-address ...
    publish-crl External 44436
    crypto ca certificate chain srv01_trustpoint
    certificate <output omitted>
      quit
    crypto ca certificate chain asa_cert_trustpoint
    certificate <output omitted>
      quit
    crypto ca certificate chain LOCAL-CA-SERVER
    certificate <output omitted>
      quit
    crypto ikev2 policy 1
    encryption aes-256
    integrity sha
    group 5 2
    prf sha
    lifetime seconds 86400
    crypto ikev2 policy 10
    encryption aes-192
    integrity sha
    group 5 2
    prf sha
    lifetime seconds 86400
    crypto ikev2 policy 20
    encryption aes
    integrity sha
    group 5 2
    prf sha
    lifetime seconds 86400
    crypto ikev2 policy 30
    encryption 3des
    integrity sha
    group 5 2
    prf sha
    lifetime seconds 86400
    crypto ikev2 policy 40
    encryption des
    integrity sha
    group 5 2
    prf sha
    lifetime seconds 86400
    crypto ikev2 enable External client-services port 44455
    crypto ikev2 remote-access trustpoint asa_cert_trustpoint
    telnet timeout 5
    ssh LAN-10-0-1-x 255.255.255.0 Internal
    ssh xxx.xxx.xxx.xxx 255.255.255.255 External
    ssh xxx.xxx.xxx.xxx 255.255.255.255 External
    ssh timeout 5
    ssh version 2
    console timeout 0
    no vpn-addr-assign aaa
    no ipv6-vpn-addr-assign aaa
    no ipv6-vpn-addr-assign local
    dhcpd dns 75.153.176.9 75.153.176.1
    dhcpd domain ingo.local
    dhcpd option 3 ip 10.0.1.254
    dhcpd address 10.0.1.50-10.0.1.81 Internal
    dhcpd enable Internal
    threat-detection basic-threat
    threat-detection scanning-threat shun except ip-address LAN-10-0-1-x 255.255.255.0
    threat-detection statistics access-list
    threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400 average-rate 200
    dynamic-filter use-database
    dynamic-filter enable interface Internal
    dynamic-filter enable interface External
    dynamic-filter drop blacklist interface Internal
    dynamic-filter drop blacklist interface External
    ntp server 128.233.3.101 source External
    ntp server 128.233.3.100 source External prefer
    ntp server 204.152.184.72 source External
    ntp server 192.6.38.127 source External
    ssl encryption aes256-sha1 aes128-sha1 3des-sha1
    ssl trust-point asa_cert_trustpoint External
    webvpn
    port 44433
    enable External
    dtls port 44433
    anyconnect image disk0:/anyconnect-win-3.1.02026-k9.pkg 1
    anyconnect profiles profile1 disk0:/profile1.xml
    anyconnect enable
    smart-tunnel list SmartTunnelList1 mstsc mstsc.exe platform windows
    smart-tunnel list SmartTunnelList1 putty putty.exe platform windows
    group-policy DfltGrpPolicy attributes
    vpn-tunnel-protocol ikev1 ikev2 l2tp-ipsec ssl-client ssl-clientless
    webvpn
      anyconnect profiles value profile1 type user
    username write.ingo password ... encrypted
    username ingo password ... encrypted privilege 15
    username tom.tucker password ... encrypted
    class-map TCP
    match port tcp range 1 65535
    class-map type regex match-any BlockFacebook
    match regex BlockFacebook
    class-map type inspect http match-all BlockDomains
    match request header host regex class BlockFacebook
    class-map inspection_default
    match default-inspection-traffic
    policy-map type inspect dns preset_dns_map
    parameters
      message-length maximum client auto
      message-length maximum 1500
      id-randomization
    policy-map TCP
    class TCP
      set connection conn-max 1000 embryonic-conn-max 1000 per-client-max 250 per-client-embryonic-max 250
      set connection timeout dcd
      set connection advanced-options Normalizer
      set connection decrement-ttl
    policy-map type inspect http HTTP
    parameters
      protocol-violation action drop-connection log
    class BlockDomains
    policy-map global_policy
    class inspection_default
      inspect ftp
      inspect h323 h225
      inspect h323 ras
      inspect rsh
      inspect rtsp
      inspect esmtp
      inspect sqlnet
      inspect skinny 
      inspect sunrpc
      inspect xdmcp
      inspect sip 
      inspect netbios
      inspect tftp
      inspect ip-options
      inspect dns preset_dns_map dynamic-filter-snoop
      inspect http HTTP
    service-policy global_policy global
    service-policy TCP interface External
    smtp-server 199.185.220.249
    privilege cmd level 3 mode exec command perfmon
    privilege cmd level 3 mode exec command ping
    privilege cmd level 3 mode exec command who
    privilege cmd level 3 mode exec command logging
    privilege cmd level 3 mode exec command failover
    privilege cmd level 3 mode exec command vpn-sessiondb
    privilege cmd level 3 mode exec command packet-tracer
    privilege show level 5 mode exec command import
    privilege show level 5 mode exec command running-config
    privilege show level 3 mode exec command reload
    privilege show level 3 mode exec command mode
    privilege show level 3 mode exec command firewall
    privilege show level 3 mode exec command asp
    privilege show level 3 mode exec command cpu
    privilege show level 3 mode exec command interface
    privilege show level 3 mode exec command clock
    privilege show level 3 mode exec command dns-hosts
    privilege show level 3 mode exec command access-list
    privilege show level 3 mode exec command logging
    privilege show level 3 mode exec command vlan
    privilege show level 3 mode exec command ip
    privilege show level 3 mode exec command failover
    privilege show level 3 mode exec command asdm
    privilege show level 3 mode exec command arp
    privilege show level 3 mode exec command ipv6
    privilege show level 3 mode exec command route
    privilege show level 3 mode exec command ospf
    privilege show level 3 mode exec command aaa-server
    privilege show level 3 mode exec command aaa
    privilege show level 3 mode exec command eigrp
    privilege show level 3 mode exec command crypto
    privilege show level 3 mode exec command ssh
    privilege show level 3 mode exec command vpn-sessiondb
    privilege show level 3 mode exec command vpnclient
    privilege show level 3 mode exec command vpn
    privilege show level 3 mode exec command dhcpd
    privilege show level 3 mode exec command blocks
    privilege show level 3 mode exec command wccp
    privilege show level 3 mode exec command dynamic-filter
    privilege show level 3 mode exec command webvpn
    privilege show level 3 mode exec command service-policy
    privilege show level 3 mode exec command module
    privilege show level 3 mode exec command uauth
    privilege show level 3 mode exec command compression
    privilege show level 3 mode configure command interface
    privilege show level 3 mode configure command clock
    privilege show level 3 mode configure command access-list
    privilege show level 3 mode configure command logging
    privilege show level 3 mode configure command ip
    privilege show level 3 mode configure command failover
    privilege show level 5 mode configure command asdm
    privilege show level 3 mode configure command arp
    privilege show level 3 mode configure command route
    privilege show level 3 mode configure command aaa-server
    privilege show level 3 mode configure command aaa
    privilege show level 3 mode configure command crypto
    privilege show level 3 mode configure command ssh
    privilege show level 3 mode configure command dhcpd
    privilege show level 5 mode configure command privilege
    privilege clear level 3 mode exec command dns-hosts
    privilege clear level 3 mode exec command logging
    privilege clear level 3 mode exec command arp
    privilege clear level 3 mode exec command aaa-server
    privilege clear level 3 mode exec command crypto
    privilege clear level 3 mode exec command dynamic-filter
    privilege cmd level 3 mode configure command failover
    privilege clear level 3 mode configure command logging
    privilege clear level 3 mode configure command arp
    privilege clear level 3 mode configure command crypto
    privilege clear level 3 mode configure command aaa-server
    prompt hostname context
    no call-home reporting anonymous
    call-home
    profile CiscoTAC-1
      no active
      destination address http https://tools.cisco.com/its/service/oddce/services/DDCEService
      destination address email [email protected]
      destination transport-method http
      subscribe-to-alert-group diagnostic
      subscribe-to-alert-group environment
      subscribe-to-alert-group inventory periodic monthly
      subscribe-to-alert-group configuration periodic monthly
      subscribe-to-alert-group telemetry periodic daily
    Cryptochecksum:41a021a28f73c647a2f550ba932bed1a
    : end
    Many thanks,
    Ingo

    Hi Jose,
    here is what I got now:
    ASA(config)# sh run | begin tunnel-group
    tunnel-group DefaultWEBVPNGroup general-attributes
    address-pool VPNPool
    authorization-required
    and DAP debugging still the same:
    ASA(config)# DAP_TRACE: DAP_open: CDC45080
    DAP_TRACE: Username: tom.tucker, aaa.cisco.grouppolicy = DfltGrpPolicy
    DAP_TRACE: Username: tom.tucker, aaa.cisco.username = tom.tucker
    DAP_TRACE: Username: tom.tucker, aaa.cisco.username1 = tom.tucker
    DAP_TRACE: Username: tom.tucker, aaa.cisco.username2 =
    DAP_TRACE: Username: tom.tucker, aaa.cisco.tunnelgroup = DefaultWEBVPNGroup
    DAP_TRACE: Username: tom.tucker, DAP_add_SCEP: scep required = [FALSE]
    DAP_TRACE: Username: tom.tucker, DAP_add_AC:
    endpoint.anyconnect.clientversion="3.1.02026";
    endpoint.anyconnect.platform="win";
    DAP_TRACE: Username: tom.tucker, dap_aggregate_attr: rec_count = 1
    DAP_TRACE: Username: tom.tucker, Selected DAPs: DfltAccessPolicy
    DAP_TRACE: Username: tom.tucker, DAP_close: CDC45080
    Unfortunately, it still doesn't work. Hmmm.. maybe a wipe of the config and starting from scratch can help?
    Thanks,
    Ingo

  • Windows 8.1 Preview not working with AnyConnect Client

    I had Windows 8 and was running Cisco AnyConnect client 3.0.10055 perfectly.
    I upgraded to the Windows 8.1 preview and it tries to download update and then it fails and disconnects with the following message:
    An unknown termination error occurred in the client.
    Tried uninstalling and reinstalling the client, no luck.
    Any ideas?
    Thanks,
    Eric

    I had the same issue with windows 8.1 x64. I believe there is an issue with the windows 8.1 update process where it fails to update some of the drivers properly. I have noticed this issue with other windows drivers after the update. Follow the steps below and you VPN should work again.
    1. Uninstall Cisco Anyconnect client.
    2. Go to Device Manager and Disable Cisco AnyConnect VPN Virtual Miniport Adapter for Windows x64
    3. Go to C:\Windows\System32 and rename vpnva64.sys to vpnva64_Old.sys.
    4. Reinstall Cisco Anyconnect client.
    5. Go to Device Manager, you see duplicated Cisco AnyConnect VPN Virtual Adapters. Uninstall one of them but do not check the option to remove the driver.
    6. Apply the registry fix in this blog: http://www.tomontech.com/2012/03/pro-tip-cisco-anyconnect-vpn-client-and-windows-8-consumer-preview/
    7. Try to connect again and your Cisco VPN should work. 

Maybe you are looking for