<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Anyconnect VPN issues in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4944249#M1105209</link>
    <description>&lt;P&gt;This profile was working on both the primary asa and the secondary up to last week.&amp;nbsp; It just stopped working.&amp;nbsp; The only other thing that I can think of is that I issued a new cert for the vpn, but I put that in the indentity certs and assigned it to the outside interfaces.&amp;nbsp; And, the other anyconnect profiles are fine.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 19 Oct 2023 12:47:36 GMT</pubDate>
    <dc:creator>trilerian1</dc:creator>
    <dc:date>2023-10-19T12:47:36Z</dc:date>
    <item>
      <title>Anyconnect VPN issues</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4943246#M1105186</link>
      <description>&lt;P&gt;Having a weird issue with anyconnect VPN.&amp;nbsp; I am running 2 5545 ASAs in HA.&amp;nbsp; If I am on my secondary ASA a specific vpn profile works just fine.&amp;nbsp; However if I failover to my primary ASA, Anyconnect comes back with the following error.&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; AnyConnect was not able to establish a connection to the specified secure gateway.&amp;nbsp; Please try connecting again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other profiles however seem to work.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 19:30:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4943246#M1105186</guid>
      <dc:creator>trilerian1</dc:creator>
      <dc:date>2023-10-18T19:30:33Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect VPN issues</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4943255#M1105187</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/907769"&gt;@trilerian1&lt;/a&gt; any reason why the secondary was active in the first place? Was there an issue with the primary that caused a failover and this is not resolved? Run "show failover history" and "show failover" and provide the output.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 19:36:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4943255#M1105187</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-10-18T19:36:41Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect VPN issues</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4943261#M1105188</link>
      <description>&lt;P&gt;Actually, the primary had to have the control license updated, for some reason that had expired. Cisco TAC was confused as to why...&amp;nbsp; So was I, to be honest.&amp;nbsp; But why would that affect only 1 anyconnect profile?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 19:43:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4943261#M1105188</guid>
      <dc:creator>trilerian1</dc:creator>
      <dc:date>2023-10-18T19:43:17Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect VPN issues</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4944048#M1105197</link>
      <description>&lt;P&gt;Control licenses (for ASA Firepower service modules) are non-expiring. Also, they should not (in any case I can think of) affect AnyConnect remote access VPN at all. &lt;/P&gt;
&lt;P&gt;I have seen issues with HA setups referring to xml profiles where one member does not have the profile files, causing the VPN to fail to establish for that connection profile.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 08:17:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4944048#M1105197</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2023-10-19T08:17:25Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect VPN issues</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4944221#M1105206</link>
      <description>&lt;P&gt;As mentioned by Marvin.&lt;/P&gt;
&lt;P&gt;Keep in mind that XML profiles created aren't replicated between devices in a HA-pair. Make sure every time you change XML settings, that you copy the changes to the standby unit as well.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 11:38:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4944221#M1105206</guid>
      <dc:creator>AViftrup</dc:creator>
      <dc:date>2023-10-19T11:38:41Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect VPN issues</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4944249#M1105209</link>
      <description>&lt;P&gt;This profile was working on both the primary asa and the secondary up to last week.&amp;nbsp; It just stopped working.&amp;nbsp; The only other thing that I can think of is that I issued a new cert for the vpn, but I put that in the indentity certs and assigned it to the outside interfaces.&amp;nbsp; And, the other anyconnect profiles are fine.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 12:47:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4944249#M1105209</guid>
      <dc:creator>trilerian1</dc:creator>
      <dc:date>2023-10-19T12:47:36Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect VPN issues</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4944250#M1105210</link>
      <description>&lt;P&gt;I generally make changes in the ASDM.&amp;nbsp; I also manage some FTDs, and I guess I am just used to pulling up a GUI for changes.&lt;/P&gt;&lt;P&gt;But regardless, we normally run on the primary ASA and I use the vpn everyday since I am remote.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 12:51:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4944250#M1105210</guid>
      <dc:creator>trilerian1</dc:creator>
      <dc:date>2023-10-19T12:51:07Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect VPN issues</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4944894#M1105239</link>
      <description>&lt;P&gt;Run a debug webvpn and then connect to AnyConnect, anything that stands out in the output?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 10:09:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4944894#M1105239</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2023-10-20T10:09:28Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect VPN issues</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4944914#M1105242</link>
      <description>&lt;P&gt;Just keep in mind, even if you're doing changes on the active unit. If you change XML configuration (profile editor either standalone or through ASDM) the XML profiles aren't automatically replicated to the standby peer.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 10:55:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4944914#M1105242</guid>
      <dc:creator>AViftrup</dc:creator>
      <dc:date>2023-10-20T10:55:42Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect VPN issues</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4945073#M1105249</link>
      <description>&lt;P&gt;I understand, but we generally run on the primary.&amp;nbsp; This worked on the primary and stopped working for whatever reason.&amp;nbsp; Now this tunnel only connects on the secondary.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The funny thing, I can connect while the secondary is active, then do a no failover active and stay connected.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 14:33:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4945073#M1105249</guid>
      <dc:creator>trilerian1</dc:creator>
      <dc:date>2023-10-20T14:33:51Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect VPN issues</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4945771#M1105284</link>
      <description>&lt;P&gt;While the primary ASA is active run a "dubug webvpn" and then connect to AnyConnect, and monitor the debug output to see if anything stands out.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 06:50:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4945771#M1105284</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2023-10-23T06:50:35Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect VPN issues</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4945807#M1105289</link>
      <description>&lt;P&gt;can I see&lt;/P&gt;
&lt;P&gt;show version&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 07:27:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4945807#M1105289</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-10-23T07:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect VPN issues</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4946218#M1105306</link>
      <description>&lt;P&gt;Cisco Adaptive Security Appliance Software Version 9.12(4)54&lt;BR /&gt;SSP Operating System Version 2.6(1.260)&lt;BR /&gt;Device Manager Version 7.18(1)152&lt;/P&gt;&lt;P&gt;Compiled on Wed 12-Oct-22 04:54 GMT by builders&lt;BR /&gt;System image file is "disk0:/asa9-12-4-54-smp-k8.bin"&lt;BR /&gt;Config file at boot was "startup-config"&lt;/P&gt;&lt;P&gt;XXXXXXX-01 up 261 days 11 hours&lt;BR /&gt;failover cluster up 3 years 76 days&lt;/P&gt;&lt;P&gt;Hardware: ASA5545, 12288 MB RAM, CPU Lynnfield 2659 MHz, 1 CPU (8 cores)&lt;BR /&gt;ASA: 6487 MB RAM, 1 CPU (1 core)&lt;BR /&gt;Internal ATA Compact Flash, 8192MB&lt;BR /&gt;BIOS Flash MX25L6445E @ 0xffbb0000, 8192KB&lt;/P&gt;&lt;P&gt;Encryption hardware device : Cisco ASA Crypto on-board accelerator (revision 0x1)&lt;BR /&gt;Boot microcode : CNPx-MC-BOOT-2.00&lt;BR /&gt;SSL/IKE microcode : CNPx-MC-SSL-SB-PLUS-0005&lt;BR /&gt;IPSec microcode : CNPx-MC-IPSEC-MAIN-0026&lt;BR /&gt;Number of accelerators: 1&lt;BR /&gt;Baseboard Management Controller (revision 0x1) Firmware Version: 2.4&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;0: Int: Internal-Data0/0 : address is 2c33.11, irq 11&lt;BR /&gt;1: Ext: GigabitEthernet0/0 : address is 2c33.11, irq 5&lt;BR /&gt;2: Ext: GigabitEthernet0/1 : address is 2c33.11, irq 5&lt;BR /&gt;3: Ext: GigabitEthernet0/2 : address is 2c33.11 irq 10&lt;BR /&gt;4: Ext: GigabitEthernet0/3 : address is 2c33.11, irq 10&lt;BR /&gt;5: Ext: GigabitEthernet0/4 : address is 2c33.11, irq 5&lt;BR /&gt;6: Ext: GigabitEthernet0/5 : address is 2c33.11, irq 5&lt;BR /&gt;7: Ext: GigabitEthernet0/6 : address is 2c33.11, irq 10&lt;BR /&gt;8: Ext: GigabitEthernet0/7 : address is 2c33.11 irq 10&lt;BR /&gt;9: Int: Internal-Data0/1 : address is 0000.0001.0002, irq 0&lt;BR /&gt;10: Int: Internal-Control0/0 : address is 0000.0001.0001, irq 0&lt;BR /&gt;11: Int: Internal-Data0/2 : address is 0000.0001.0003, irq 0&lt;BR /&gt;12: Ext: Management0/0 : address is 2c33.11, irq 0&lt;BR /&gt;13: Int: Internal-Data0/3 : address is 0000.0100.0001, irq 0&lt;/P&gt;&lt;P&gt;Licensed features for this platform:&lt;BR /&gt;Maximum Physical Interfaces : Unlimited perpetual&lt;BR /&gt;Maximum VLANs : 300 perpetual&lt;BR /&gt;Inside Hosts : Unlimited perpetual&lt;BR /&gt;Failover : Active/Active perpetual&lt;BR /&gt;Encryption-DES : Enabled perpetual&lt;BR /&gt;Encryption-3DES-AES : Enabled perpetual&lt;BR /&gt;Security Contexts : 2 perpetual&lt;BR /&gt;Carrier : Disabled perpetual&lt;BR /&gt;AnyConnect Premium Peers : 2 perpetual&lt;BR /&gt;AnyConnect Essentials : Disabled perpetual&lt;BR /&gt;Other VPN Peers : 2500 perpetual&lt;BR /&gt;Total VPN Peers : 2500 perpetual&lt;BR /&gt;AnyConnect for Mobile : Disabled perpetual&lt;BR /&gt;AnyConnect for Cisco VPN Phone : Disabled perpetual&lt;BR /&gt;Advanced Endpoint Assessment : Disabled perpetual&lt;BR /&gt;Shared License : Disabled perpetual&lt;BR /&gt;Total TLS Proxy Sessions : 2 perpetual&lt;BR /&gt;Botnet Traffic Filter : Disabled perpetual&lt;BR /&gt;IPS Module : Disabled perpetual&lt;BR /&gt;Cluster : Enabled perpetual&lt;BR /&gt;Cluster Members : 2 perpetual&lt;/P&gt;&lt;P&gt;This platform has an ASA5545 VPN Premium license.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Failover cluster licensed features for this platform:&lt;BR /&gt;Maximum Physical Interfaces : Unlimited perpetual&lt;BR /&gt;Maximum VLANs : 300 perpetual&lt;BR /&gt;Inside Hosts : Unlimited perpetual&lt;BR /&gt;Failover : Active/Active perpetual&lt;BR /&gt;Encryption-DES : Enabled perpetual&lt;BR /&gt;Encryption-3DES-AES : Enabled perpetual&lt;BR /&gt;Security Contexts : 4 perpetual&lt;BR /&gt;Carrier : Disabled perpetual&lt;BR /&gt;AnyConnect Premium Peers : 2500 perpetual&lt;BR /&gt;AnyConnect Essentials : Disabled perpetual&lt;BR /&gt;Other VPN Peers : 2500 perpetual&lt;BR /&gt;Total VPN Peers : 2500 perpetual&lt;BR /&gt;AnyConnect for Mobile : Enabled perpetual&lt;BR /&gt;AnyConnect for Cisco VPN Phone : Enabled perpetual&lt;BR /&gt;Advanced Endpoint Assessment : Enabled perpetual&lt;BR /&gt;Shared License : Disabled perpetual&lt;BR /&gt;Total TLS Proxy Sessions : 4 perpetual&lt;BR /&gt;Botnet Traffic Filter : Disabled perpetual&lt;BR /&gt;IPS Module : Disabled perpetual&lt;BR /&gt;Cluster : Enabled perpetual&lt;/P&gt;&lt;P&gt;This platform has an ASA5545 VPN Premium license.&lt;/P&gt;&lt;P&gt;Serial Number: ##########&lt;BR /&gt;Running Permanent Activation Key: #############################&lt;BR /&gt;Configuration register is 0x1&lt;/P&gt;&lt;P&gt;Image type : Release&lt;BR /&gt;Key version : A&lt;/P&gt;&lt;P&gt;Configuration last modified by enable_1 at 14:33:37.682 EDT Wed Oct 18 2023&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 15:17:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4946218#M1105306</guid>
      <dc:creator>trilerian1</dc:creator>
      <dc:date>2023-10-23T15:17:49Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect VPN issues</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4946220#M1105307</link>
      <description>&lt;P&gt;I will have to get someone else to help with this as I can't really debug my own session when I can't see the firewall...&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 15:19:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4946220#M1105307</guid>
      <dc:creator>trilerian1</dc:creator>
      <dc:date>2023-10-23T15:19:39Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect VPN issues</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4946244#M1105310</link>
      <description>&lt;P&gt;Note you only have the two built-in free AnyConnect licenses. If you attempt to connect a third session it will give an error on the client similar to what you have reported.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 16:02:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4946244#M1105310</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2023-10-23T16:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect VPN issues</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4946253#M1105312</link>
      <description>&lt;P&gt;Yes but peer (active HA FW) have license for 2500 and it appear in vpn peer.&lt;/P&gt;
&lt;P&gt;So if he access to active then he have up to 2500. When failed then the license will hosted by standby and also he Wil get up to 2500.&lt;/P&gt;
&lt;P&gt;The issue I think when failover the detection is not fast that why anyconnect failed since license not hosted until failover completed done.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/907769"&gt;@trilerian1&lt;/a&gt;&amp;nbsp;do you change hello timer of HA?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 16:09:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4946253#M1105312</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-10-23T16:09:49Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect VPN issues</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4957040#M1105732</link>
      <description>&lt;P&gt;I just want to say that this issue seems to have fixed itself with no intervention by me.&amp;nbsp; I did a failover back to my primary ASA today and was able to connect to the vpn with the correct profile afterwards.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Honestly, I got nothing.&amp;nbsp; PFM, y'all know it is a thing.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2023 16:04:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4957040#M1105732</guid>
      <dc:creator>trilerian1</dc:creator>
      <dc:date>2023-11-10T16:04:53Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect VPN issues</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4957098#M1105743</link>
      <description>&lt;P&gt;Could you be missing anyconnect files, certificate, client profile, etc, on the standby device?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2023 17:46:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4957098#M1105743</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2023-11-10T17:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect VPN issues</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4957100#M1105744</link>
      <description>&lt;P&gt;The secondary worked fine.&amp;nbsp; It was the primary that was having issues. And it is working on the primary now.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2023 17:48:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-vpn-issues/m-p/4957100#M1105744</guid>
      <dc:creator>trilerian1</dc:creator>
      <dc:date>2023-11-10T17:48:40Z</dc:date>
    </item>
  </channel>
</rss>

