<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA5525: Anyconnect was not able to establish a connection to the in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5525-anyconnect-was-not-able-to-establish-a-connection-to-the/m-p/4446044#M1082782</link>
    <description>&lt;P&gt;This is a lab setup.&amp;nbsp; I will finish the config and then put it into production.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried everything you suggested and then started getting the same error I had at the beginning of this thread. "AnyConnect was not able to establish a connection to the specified secure gateway."&amp;nbsp; However, I found the source of that problem which was in the client profile.&amp;nbsp; if you are doing IPSec you have to uncheck the "ASA gateway" check box in the server list section of the client config.&amp;nbsp; You can see this if you go to ASDM (see attached image).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since this was the original question in this thread I'll mark this as my answer.&amp;nbsp; Thanks for everyone's assistance in troubleshooting this.&lt;/P&gt;</description>
    <pubDate>Fri, 13 Aug 2021 12:28:10 GMT</pubDate>
    <dc:creator>dreyerpj</dc:creator>
    <dc:date>2021-08-13T12:28:10Z</dc:date>
    <item>
      <title>ASA5525: Anyconnect was not able to establish a connection to the specified secure gateway.</title>
      <link>https://community.cisco.com/t5/network-security/asa5525-anyconnect-was-not-able-to-establish-a-connection-to-the/m-p/4434528#M1082308</link>
      <description>&lt;P&gt;Specifications-&lt;/P&gt;&lt;P&gt;Hardware:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ASA5525&lt;/P&gt;&lt;P&gt;Software:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ASA9.14(1)30&lt;/P&gt;&lt;P&gt;Anyconnect Client:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4.10.00093&lt;/P&gt;&lt;P&gt;Desktop:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Windows 10&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have an ASA5525 firewall that I am trying to configure to allow remote VPN using IPSec (ikev2) for a friend of mine.&amp;nbsp; I have not done any configuration of firewalls for many years so I am a bit rusty.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have an issue where I cannot VPN into the ASA firewall remotely from the Internet.&amp;nbsp; I can go to the web interface, login with local credentials, and download the latest Anyconnect client for windows. However, when I try to VPN using the Anyconnect client with those same local credentials, I get past the initial login password prompt but receive the following error: “Anyconnect was not able to establish a connection to the specified secure gateway. Please try connecting again.”&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I’ve searched the web and checked the posted fixes I’ve found but the problem persists (see list of potential fixes below) so I presume that I am missing something in the configuration for VPN and/or IPSec.&amp;nbsp; If anyone out there can help, I would appreciate it.&amp;nbsp; My config file is shown below.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Check LAN Settings on the desktop to make sure the option "Use automatic configure script" is unchecked.&lt;/LI&gt;&lt;LI&gt;Disable Antivirus and test the VPN&lt;/LI&gt;&lt;LI&gt;Disable firewall and test the VPN&lt;/LI&gt;&lt;LI&gt;Stop Internet Connection Service (not running on my system)&lt;/LI&gt;&lt;LI&gt;Disable Internet Connection Sharping (never enabled on my system)&lt;/LI&gt;&lt;LI&gt;Update the appropriate VPN registry item to remove “@oem20.inf,%vpnva_Desc%” in the text.&lt;/LI&gt;&lt;LI&gt;Tried alternate connections (wifi vs hardwired)&lt;/LI&gt;&lt;LI&gt;configure the ASA profile (.xml file) to be configured for "AllowRemoteUsers"&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Fri, 16 Jul 2021 17:09:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5525-anyconnect-was-not-able-to-establish-a-connection-to-the/m-p/4434528#M1082308</guid>
      <dc:creator>dreyerpj</dc:creator>
      <dc:date>2021-07-16T17:09:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5525: Anyconnect was not able to establish a connection to the specified secure gateway.</title>
      <link>https://community.cisco.com/t5/network-security/asa5525-anyconnect-was-not-able-to-establish-a-connection-to-the/m-p/4434600#M1082310</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1224816"&gt;@dreyerpj&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does the client computer trust the certificate? You can export from the ASA and import to the client. Make sure you've specified the correct FQDN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You say you are connecting using ikev2, I assume you've configured the anyconnect profile on the client computer to select IPSec, correct?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jul 2021 19:25:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5525-anyconnect-was-not-able-to-establish-a-connection-to-the/m-p/4434600#M1082310</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-07-16T19:25:09Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5525: Anyconnect was not able to establish a connection to the specified secure gateway.</title>
      <link>https://community.cisco.com/t5/network-security/asa5525-anyconnect-was-not-able-to-establish-a-connection-to-the/m-p/4434637#M1082315</link>
      <description>&lt;P&gt;Your tunnel-group configuration is incorrect.&amp;nbsp; You are referencing IKEv1 and not IKEv2&lt;/P&gt;
&lt;PRE class="bp-text bp-text-plain hljs bp-is-scrollable" tabindex="0"&gt;&lt;CODE class="bp-text-code txt"&gt;tunnel-group VPNPROFILE ipsec-attributes
 ikev1 trust-point SELF_TRUSTPOINT&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;Your SSL configuration does not reference the outside interface.&amp;nbsp; ssl trust-point SELF-TRUSTPOINT outside&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And a side note, your twice NAT / no NAT configuration is not correct.&amp;nbsp; all your NAT statements reference INSIDE1 interface, the other two should reference INSIDE2 and INSIDE3 respectively&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;** I accidentally clicked on I have this problem too...which I do not&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jul 2021 21:07:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5525-anyconnect-was-not-able-to-establish-a-connection-to-the/m-p/4434637#M1082315</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2021-07-16T21:07:35Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5525: Anyconnect was not able to establish a connection to the specified secure gateway.</title>
      <link>https://community.cisco.com/t5/network-security/asa5525-anyconnect-was-not-able-to-establish-a-connection-to-the/m-p/4434641#M1082316</link>
      <description>&lt;P&gt;Thanks for those..&amp;nbsp; I was changing from ikev1 to ikev2 and missed those. I'll give those try and report back.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for the twice nat, that's what I get when I cut and paste statements.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; I've fixed those as well.&amp;nbsp; Thanks,&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jul 2021 21:35:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5525-anyconnect-was-not-able-to-establish-a-connection-to-the/m-p/4434641#M1082316</guid>
      <dc:creator>dreyerpj</dc:creator>
      <dc:date>2021-07-16T21:35:12Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5525: Anyconnect was not able to establish a connection to the specified secure gateway.</title>
      <link>https://community.cisco.com/t5/network-security/asa5525-anyconnect-was-not-able-to-establish-a-connection-to-the/m-p/4434642#M1082317</link>
      <description>&lt;P&gt;Thanks for the info. The client does not block connections to untrusted servers and the client is configured for IPSec.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jul 2021 21:30:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5525-anyconnect-was-not-able-to-establish-a-connection-to-the/m-p/4434642#M1082317</guid>
      <dc:creator>dreyerpj</dc:creator>
      <dc:date>2021-07-16T21:30:20Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5525: Anyconnect was not able to establish a connection to the specified secure gateway.</title>
      <link>https://community.cisco.com/t5/network-security/asa5525-anyconnect-was-not-able-to-establish-a-connection-to-the/m-p/4436181#M1082388</link>
      <description>&lt;P&gt;I changed everything you suggested and still receive the same error message of "Anyconnect was unable to establish a connection to the specified secure gateway." (Connection attempt has failed.)&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jul 2021 17:20:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5525-anyconnect-was-not-able-to-establish-a-connection-to-the/m-p/4436181#M1082388</guid>
      <dc:creator>dreyerpj</dc:creator>
      <dc:date>2021-07-20T17:20:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5525: Anyconnect was not able to establish a connection to the specified secure gateway.</title>
      <link>https://community.cisco.com/t5/network-security/asa5525-anyconnect-was-not-able-to-establish-a-connection-to-the/m-p/4436199#M1082392</link>
      <description>&lt;P&gt;Did you also add the ssl trust-point configuration?&lt;/P&gt;
&lt;P&gt;could you post an up to date full configuration of the ASA (remove any public IPs, usernames and passwords) snd also the output of show disk0 or dir whichever you prefere.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jul 2021 17:40:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5525-anyconnect-was-not-able-to-establish-a-connection-to-the/m-p/4436199#M1082392</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2021-07-20T17:40:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5525: Anyconnect was not able to establish a connection to the specified secure gateway.</title>
      <link>https://community.cisco.com/t5/network-security/asa5525-anyconnect-was-not-able-to-establish-a-connection-to-the/m-p/4436619#M1082403</link>
      <description>&lt;P&gt;Yes, I did add the ssl trust-point as you suggested.&amp;nbsp; Thank you for asking.&amp;nbsp; I've attached my running config as well as the show disk0 output.&amp;nbsp; Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jul 2021 12:17:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5525-anyconnect-was-not-able-to-establish-a-connection-to-the/m-p/4436619#M1082403</guid>
      <dc:creator>dreyerpj</dc:creator>
      <dc:date>2021-07-21T12:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5525: Anyconnect was not able to establish a connection to the specified secure gateway.</title>
      <link>https://community.cisco.com/t5/network-security/asa5525-anyconnect-was-not-able-to-establish-a-connection-to-the/m-p/4437523#M1082437</link>
      <description>&lt;P&gt;Is this a lab setup or a production environment?&lt;/P&gt;
&lt;P&gt;Looks as though your tunnel-group configuration is not correct&lt;/P&gt;
&lt;PRE class="bp-text bp-text-plain hljs bp-is-scrollable" tabindex="0"&gt;&lt;CODE class="bp-text-code txt"&gt;tunnel-group VPNPROFILE webvpn-attributes
 group-alias VPNPROFILE enable
tunnel-group VPNPROFILE ipsec-attributes
 ikev2 local-authentication certificate SELF_TRUSTPOINT&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;remove the ipsec-attributes and under webvpnb-attributes add &lt;STRONG&gt;authentication certificate&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jul 2021 20:12:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5525-anyconnect-was-not-able-to-establish-a-connection-to-the/m-p/4437523#M1082437</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2021-07-22T20:12:07Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5525: Anyconnect was not able to establish a connection to the</title>
      <link>https://community.cisco.com/t5/network-security/asa5525-anyconnect-was-not-able-to-establish-a-connection-to-the/m-p/4446044#M1082782</link>
      <description>&lt;P&gt;This is a lab setup.&amp;nbsp; I will finish the config and then put it into production.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried everything you suggested and then started getting the same error I had at the beginning of this thread. "AnyConnect was not able to establish a connection to the specified secure gateway."&amp;nbsp; However, I found the source of that problem which was in the client profile.&amp;nbsp; if you are doing IPSec you have to uncheck the "ASA gateway" check box in the server list section of the client config.&amp;nbsp; You can see this if you go to ASDM (see attached image).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since this was the original question in this thread I'll mark this as my answer.&amp;nbsp; Thanks for everyone's assistance in troubleshooting this.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2021 12:28:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5525-anyconnect-was-not-able-to-establish-a-connection-to-the/m-p/4446044#M1082782</guid>
      <dc:creator>dreyerpj</dc:creator>
      <dc:date>2021-08-13T12:28:10Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5525: Anyconnect was not able to establish a connection to the</title>
      <link>https://community.cisco.com/t5/network-security/asa5525-anyconnect-was-not-able-to-establish-a-connection-to-the/m-p/4591551#M1089182</link>
      <description>&lt;P&gt;Hello，Where is the server list in the picture in ASDM&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 10:09:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5525-anyconnect-was-not-able-to-establish-a-connection-to-the/m-p/4591551#M1089182</guid>
      <dc:creator>xuhongfei</dc:creator>
      <dc:date>2022-04-13T10:09:34Z</dc:date>
    </item>
  </channel>
</rss>

