<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco AnyConnect - cannot have more than 6 users connected in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/cisco-anyconnect-cannot-have-more-than-6-users-connected/m-p/4049348#M5298</link>
    <description>&lt;P&gt;Here are the steps to gather the DART logs.&amp;nbsp; Will be helpful in determining the issue.&amp;nbsp; It will contain a lot of information you may not want posted to the entire community so I would suggest opening a TAC case with this information if this is not in a lab.&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-collect-the-dart-bundle-for-anyconnect/ta-p/3156025" target="_blank"&gt;https://community.cisco.com/t5/security-documents/how-to-collect-the-dart-bundle-for-anyconnect/ta-p/3156025&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Matt&lt;/P&gt;</description>
    <pubDate>Fri, 20 Mar 2020 15:33:12 GMT</pubDate>
    <dc:creator>Matthew Franks</dc:creator>
    <dc:date>2020-03-20T15:33:12Z</dc:date>
    <item>
      <title>Cisco AnyConnect - cannot have more than 6 users connected</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-anyconnect-cannot-have-more-than-6-users-connected/m-p/4048429#M5291</link>
      <description>&lt;P&gt;Hello Cisco Community!!&lt;/P&gt;&lt;P&gt;I have an ASA5512 running 9.1(2) firmware with 4.x anyconnect software package and with 250 remote access vpn licenses installed but only 6 users can connect at a time. There seems to be no vpn session limit set in group-policy for vpn.. not sure what the root cause could be..we have 6 users connect..and the 7th is unable to..regardless of device or Anyconnect version...when 1 of the 6 existing users disconnect, the 7th user is then able to connect(making it the 6th user)..any insight would be greatly appreciated!&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2020 01:04:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-anyconnect-cannot-have-more-than-6-users-connected/m-p/4048429#M5291</guid>
      <dc:creator>roliveira11</dc:creator>
      <dc:date>2020-03-19T01:04:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AnyConnect - cannot have more than 6 users connected</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-anyconnect-cannot-have-more-than-6-users-connected/m-p/4048746#M5292</link>
      <description>&lt;P&gt;look if you have this command configured:&lt;/P&gt;
&lt;PRE&gt;asa# show run vpn-sessiondb
vpn-sessiondb max-anyconnect-premium-or-essentials-limit 6&lt;/PRE&gt;
&lt;P&gt;If yes, just remove it.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2020 15:14:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-anyconnect-cannot-have-more-than-6-users-connected/m-p/4048746#M5292</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2020-03-19T15:14:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AnyConnect - cannot have more than 6 users connected</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-anyconnect-cannot-have-more-than-6-users-connected/m-p/4048928#M5293</link>
      <description>&lt;P&gt;Hello! Thank you for the reply! The setting was set to INHERIT on the group policy.. we've since hardset it to 250.. and still only 6 users can connect.. when attempting to do debugs on anyconnect.. I see none.. attempting to do captures on outside interface for my public IP coming in, still see nothing.. but when one of the 6 users disconnect.. 1 user is then able to connect no problem.. bringing the total to 6 users again.. so so strange.. Below are some outputs Ive gathered.. hopefully they're helpful!!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;HNC# show vpn-sessiondb summary&lt;BR /&gt;---------------------------------------------------------------------------&lt;BR /&gt;VPN Session Summary&lt;BR /&gt;---------------------------------------------------------------------------&lt;BR /&gt;Active : Cumulative : Peak Concur : Inactive&lt;BR /&gt;----------------------------------------------&lt;BR /&gt;AnyConnect Client : 6 : 511 : 8 : 0&lt;BR /&gt;SSL/TLS/DTLS : 6 : 511 : 8 : 0&lt;BR /&gt;Clientless VPN : 0 : 12 : 3&lt;BR /&gt;Browser : 0 : 12 : 3&lt;BR /&gt;Site-to-Site VPN : 1 : 2694 : 2&lt;BR /&gt;IKEv1 IPsec : 1 : 2694 : 2&lt;BR /&gt;---------------------------------------------------------------------------&lt;BR /&gt;Total Active and Inactive : 7 Total Cumulative : 3217&lt;BR /&gt;Device Total VPN Capacity : 250&lt;BR /&gt;Device Load : 3%&lt;BR /&gt;---------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;HNC# show vpn-sessiondb license-summary&lt;BR /&gt;---------------------------------------------------------------------------&lt;BR /&gt;VPN Licenses and Configured Limits Summary&lt;BR /&gt;---------------------------------------------------------------------------&lt;BR /&gt;Status : Capacity : Installed : Limit&lt;BR /&gt;-----------------------------------------&lt;BR /&gt;AnyConnect Premium : DISABLED : 250 : 2 : 250&lt;BR /&gt;AnyConnect Essentials : ENABLED : 250 : 250 : 250&lt;BR /&gt;Other VPN (Available by Default) : ENABLED : 250 : 250 : 250&lt;BR /&gt;Shared License Server : DISABLED&lt;BR /&gt;Shared License Participant : DISABLED&lt;BR /&gt;AnyConnect for Mobile : DISABLED(Requires Premium or Essentials)&lt;BR /&gt;Advanced Endpoint Assessment : DISABLED(Requires Premium)&lt;BR /&gt;AnyConnect for Cisco VPN Phone : DISABLED&lt;BR /&gt;VPN-3DES-AES : ENABLED&lt;BR /&gt;VPN-DES : ENABLED&lt;BR /&gt;---------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;---------------------------------------------------------------------------&lt;BR /&gt;VPN Licenses Usage Summary&lt;BR /&gt;---------------------------------------------------------------------------&lt;BR /&gt;All : Peak : Eff. :&lt;BR /&gt;In Use : In Use : Limit : Usage&lt;BR /&gt;---------------------------------&lt;BR /&gt;AnyConnect Essentials : : 6 : 8 : 250 : 2%&lt;BR /&gt;Anyconnect Client : : 6 : 8 : 250 : 2%&lt;BR /&gt;&amp;lt;--- More ---&amp;gt; Clientless VPN : : 0 : 3 : 250 : 0%&lt;BR /&gt;Other VPN : : 1 : 2 : 250 : 0%&lt;BR /&gt;L2TP Clients&lt;BR /&gt;Site-to-Site VPN : : 1 : 2 : 250 : 0%&lt;BR /&gt;---------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;HNC#&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;HNC# show version&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 9.12(1)&lt;BR /&gt;Firepower Extensible Operating System Version 2.6(1.113)&lt;BR /&gt;Device Manager Version 7.12(1)&lt;/P&gt;&lt;P&gt;Compiled on Wed 13-Mar-19 13:53 PDT by builders&lt;BR /&gt;System image file is "disk0:/asa9-12-1-smp-k8.bin"&lt;BR /&gt;Config file at boot was "startup-config"&lt;/P&gt;&lt;P&gt;HNC up 148 days 7 hours&lt;/P&gt;&lt;P&gt;Hardware: ASA5512, 4096 MB RAM, CPU Clarkdale 2800 MHz, 1 CPU (2 cores)&lt;BR /&gt;ASA: 1666 MB RAM, 1 CPU (1 core)&lt;BR /&gt;Internal ATA Compact Flash, 4096MB&lt;BR /&gt;BIOS Flash MX25L6445E @ 0xffbb0000, 8192KB&lt;/P&gt;&lt;P&gt;Encryption hardware device : Cisco ASA Crypto on-board accelerator (revision 0x1)&lt;BR /&gt;Boot microcode : CNPx-MC-BOOT-2.00&lt;BR /&gt;SSL/IKE microcode : CNPx-MC-SSL-SB-PLUS-0005&lt;BR /&gt;IPSec microcode : CNPx-MC-IPSEC-MAIN-0026&lt;BR /&gt;Number of accelerators: 1&lt;BR /&gt;Baseboard Management Controller (revision 0x1) Firmware Version: 2.4&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;0: Int: Internal-Data0/0 : address is 6412.25e4.00a0, irq 11&lt;BR /&gt;&amp;lt;--- More ---&amp;gt; 1: Ext: GigabitEthernet0/0 : address is 6412.25e4.00a4, irq 10&lt;BR /&gt;&amp;lt;--- More ---&amp;gt; 2: Ext: GigabitEthernet0/1 : address is 6412.25e4.00a1, irq 10&lt;BR /&gt;3: Ext: GigabitEthernet0/2 : address is 6412.25e4.00a5, irq 5&lt;BR /&gt;4: Ext: GigabitEthernet0/3 : address is 6412.25e4.00a2, irq 5&lt;BR /&gt;5: Ext: GigabitEthernet0/4 : address is 6412.25e4.00a6, irq 10&lt;BR /&gt;6: Ext: GigabitEthernet0/5 : address is 6412.25e4.00a3, irq 10&lt;BR /&gt;7: Int: Internal-Data0/1 : address is 0000.0001.0002, irq 0&lt;BR /&gt;8: Int: Internal-Control0/0 : address is 0000.0001.0001, irq 0&lt;BR /&gt;9: Int: Internal-Data0/2 : address is 0000.0001.0003, irq 0&lt;BR /&gt;10: Ext: Management0/0 : address is 6412.25e4.00a0, irq 0&lt;BR /&gt;11: Int: Internal-Data0/3 : address is 0000.0100.0001, irq 0&lt;/P&gt;&lt;P&gt;Licensed features for this platform:&lt;BR /&gt;Maximum Physical Interfaces : Unlimited perpetual&lt;BR /&gt;Maximum VLANs : 50 perpetual&lt;BR /&gt;Inside Hosts : Unlimited perpetual&lt;BR /&gt;Failover : Disabled perpetual&lt;BR /&gt;Encryption-DES : Enabled perpetual&lt;BR /&gt;Encryption-3DES-AES : Enabled perpetual&lt;BR /&gt;Security Contexts : 2 perpetual&lt;BR /&gt;Carrier : Disabled perpetual&lt;BR /&gt;AnyConnect Premium Peers : 2 perpetual&lt;BR /&gt;AnyConnect Essentials : 250 perpetual&lt;BR /&gt;Other VPN Peers : 250 perpetual&lt;BR /&gt;Total VPN Peers : 250 perpetual&lt;BR /&gt;&amp;lt;--- More ---&amp;gt; AnyConnect for Mobile : Disabled perpetual&lt;BR /&gt;AnyConnect for Cisco VPN Phone : Disabled perpetual&lt;BR /&gt;Advanced Endpoint Assessment : Disabled perpetual&lt;BR /&gt;Shared License : Disabled perpetual&lt;BR /&gt;Total TLS Proxy Sessions : 2 perpetual&lt;BR /&gt;Botnet Traffic Filter : Disabled perpetual&lt;BR /&gt;IPS Module : Disabled perpetual&lt;BR /&gt;Cluster : Disabled perpetual&lt;/P&gt;&lt;P&gt;This platform has a Base license.&lt;/P&gt;&lt;P&gt;Serial Number: FCH1812JMKU&lt;BR /&gt;Configuration register is 0x1&lt;/P&gt;&lt;P&gt;Image type : Release&lt;BR /&gt;Key version : A&lt;/P&gt;&lt;P&gt;Configuration last modified by enable_15 at 14:27:42.655 EDT Wed Mar 18 2020&lt;BR /&gt;HNC#&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;HNC# show run webvpn&lt;BR /&gt;webvpn&lt;BR /&gt;enable OUTSIDE&lt;BR /&gt;hsts&lt;BR /&gt;enable&lt;BR /&gt;max-age 31536000&lt;BR /&gt;include-sub-domains&lt;BR /&gt;no preload&lt;BR /&gt;anyconnect-essentials&lt;BR /&gt;anyconnect image disk0:/anyconnect-macosx-i386-2.5.2014-k9.pkg 2&lt;BR /&gt;anyconnect image disk0:/anyconnect-win-4.7.02036-webdeploy-k9.pkg 4&lt;BR /&gt;anyconnect profiles AnyConnectPCF disk0:/anyconnectpcf.xml&lt;BR /&gt;anyconnect profiles MacVPN_client_profile disk0:/MacVPN_client_profile.xml&lt;BR /&gt;anyconnect enable&lt;BR /&gt;tunnel-group-list enable&lt;BR /&gt;cache&lt;BR /&gt;disable&lt;BR /&gt;error-recovery disable&lt;BR /&gt;HNC#&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;HNC# show run vpn-sessiondb&lt;BR /&gt;vpn-sessiondb max-other-vpn-limit 250&lt;BR /&gt;vpn-sessiondb max-anyconnect-premium-or-essentials-limit 250&lt;BR /&gt;HNC#&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;enable OUTSIDE&lt;BR /&gt;hsts&lt;BR /&gt;enable&lt;BR /&gt;max-age 31536000&lt;BR /&gt;include-sub-domains&lt;BR /&gt;no preload&lt;BR /&gt;anyconnect-essentials&lt;BR /&gt;anyconnect image disk0:/anyconnect-macosx-i386-2.5.2014-k9.pkg 2&lt;BR /&gt;anyconnect image disk0:/anyconnect-win-4.7.02036-webdeploy-k9.pkg 4&lt;BR /&gt;anyconnect profiles AnyConnectPCF disk0:/anyconnectpcf.xml&lt;BR /&gt;anyconnect profiles MacVPN_client_profile disk0:/MacVPN_client_profile.xml&lt;BR /&gt;anyconnect enable&lt;BR /&gt;tunnel-group-list enable&lt;BR /&gt;cache&lt;BR /&gt;disable&lt;BR /&gt;error-recovery disable&lt;BR /&gt;group-policy GroupPolicy_MacVPN internal&lt;BR /&gt;group-policy GroupPolicy_MacVPN attributes&lt;BR /&gt;wins-server none&lt;BR /&gt;dns-server value 192.168.16.10&lt;BR /&gt;vpn-tunnel-protocol ikev2 ssl-client&lt;BR /&gt;default-domain value hnc.local&lt;BR /&gt;webvpn&lt;BR /&gt;anyconnect profiles value MacVPN_client_profile type user&lt;BR /&gt;group-policy Anyconnect internal&lt;BR /&gt;group-policy Anyconnect attributes&lt;BR /&gt;wins-server none&lt;BR /&gt;dns-server value 192.168.16.10&lt;BR /&gt;vpn-tunnel-protocol ikev1 ikev2 ssl-client ssl-clientless&lt;BR /&gt;split-tunnel-policy tunnelspecified&lt;BR /&gt;split-tunnel-network-list value MainNetwork&lt;BR /&gt;default-domain value hnc.local&lt;BR /&gt;webvpn&lt;BR /&gt;anyconnect profiles value AnyConnectPCF type user&lt;BR /&gt;dynamic-access-policy-record No_Access&lt;BR /&gt;action terminate&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;username focus password ***** pbkdf2 privilege 15&lt;BR /&gt;username cisco password ***** encrypted&lt;BR /&gt;tunnel-group DefaultL2LGroup ipsec-attributes&lt;BR /&gt;ikev1 pre-shared-key *****&lt;BR /&gt;tunnel-group Anyconnect type remote-access&lt;BR /&gt;tunnel-group Anyconnect general-attributes&lt;BR /&gt;address-pool POOL&lt;BR /&gt;authentication-server-group LDAP&lt;BR /&gt;default-group-policy Anyconnect&lt;BR /&gt;tunnel-group Anyconnect webvpn-attributes&lt;BR /&gt;group-alias Anyconnect enable&lt;BR /&gt;tunnel-group MacVPN type remote-access&lt;BR /&gt;tunnel-group MacVPN general-attributes&lt;BR /&gt;address-pool POOL&lt;BR /&gt;authentication-server-group LDAP&lt;BR /&gt;default-group-policy GroupPolicy_MacVPN&lt;BR /&gt;tunnel-group MacVPN webvpn-attributes&lt;BR /&gt;group-alias MacVPN enable&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;parameters&lt;BR /&gt;message-length maximum client auto&lt;BR /&gt;message-length maximum 512&lt;BR /&gt;no tcp-inspection&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;class inspection_default&lt;BR /&gt;inspect dns preset_dns_map&lt;BR /&gt;inspect ftp&lt;BR /&gt;inspect h323 h225&lt;BR /&gt;inspect h323 ras&lt;BR /&gt;inspect rsh&lt;BR /&gt;inspect rtsp&lt;BR /&gt;inspect sqlnet&lt;BR /&gt;inspect skinny&lt;BR /&gt;inspect sunrpc&lt;BR /&gt;inspect xdmcp&lt;BR /&gt;inspect sip&lt;BR /&gt;inspect netbios&lt;BR /&gt;inspect tftp&lt;BR /&gt;inspect ip-options&lt;BR /&gt;inspect icmp&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context&lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;Cryptochecksum:0ed8f5b1956b59dd39308849dd6b8262&lt;BR /&gt;: end&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2020 20:46:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-anyconnect-cannot-have-more-than-6-users-connected/m-p/4048928#M5293</guid>
      <dc:creator>roliveira11</dc:creator>
      <dc:date>2020-03-19T20:46:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AnyConnect - cannot have more than 6 users connected</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-anyconnect-cannot-have-more-than-6-users-connected/m-p/4048991#M5296</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;Can you post the DART logs from AnyConnect?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Cristian Matei.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2020 22:47:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-anyconnect-cannot-have-more-than-6-users-connected/m-p/4048991#M5296</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2020-03-19T22:47:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AnyConnect - cannot have more than 6 users connected</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-anyconnect-cannot-have-more-than-6-users-connected/m-p/4049252#M5297</link>
      <description>&lt;P&gt;I'll have to figure out how to retrieve the DART logs&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2020 15:36:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-anyconnect-cannot-have-more-than-6-users-connected/m-p/4049252#M5297</guid>
      <dc:creator>roliveira11</dc:creator>
      <dc:date>2020-03-20T15:36:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AnyConnect - cannot have more than 6 users connected</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-anyconnect-cannot-have-more-than-6-users-connected/m-p/4049348#M5298</link>
      <description>&lt;P&gt;Here are the steps to gather the DART logs.&amp;nbsp; Will be helpful in determining the issue.&amp;nbsp; It will contain a lot of information you may not want posted to the entire community so I would suggest opening a TAC case with this information if this is not in a lab.&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-collect-the-dart-bundle-for-anyconnect/ta-p/3156025" target="_blank"&gt;https://community.cisco.com/t5/security-documents/how-to-collect-the-dart-bundle-for-anyconnect/ta-p/3156025&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Matt&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2020 15:33:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-anyconnect-cannot-have-more-than-6-users-connected/m-p/4049348#M5298</guid>
      <dc:creator>Matthew Franks</dc:creator>
      <dc:date>2020-03-20T15:33:12Z</dc:date>
    </item>
  </channel>
</rss>

