取消
显示结果 
搜索替代 
您的意思是: 
cancel
4866
查看次数
0
有帮助
2
回复

登陆不了VPN

Hmeng207
Level 1
Level 1

XP系统cisco VPN登陆不了 总数报错 The vpn client was unable to modify the ip forwarding table a vpn... 是哪里出问题

1 个已接受解答

已接受的解答

ilay
VIP
VIP

按照报错信息可以从cisco的bug库中搜索到一个类似的bug,有可能是系统ipv6 feature的原因,受影响的版本是3.1(495),如果你的anyconnect版本还有系统恰好符合这个bug描述的话,可以尝试更换一个anyconnect的版本 (https://bst.cloudapps.cisco.com/bugsearch/bug/CSCud73928 )  <--- bug url

 

如果按照bug中的临时解决办法,卸载了ipv6,重启重装anyconnect仍旧不能解决的话,可以将一些连接的message收集上来再做分析。

//可以参考下图查看message和 anyconnect 版本

2021-07-15-408.png

 

 

在原帖中查看解决方案

2 条回复2

ilay
VIP
VIP

按照报错信息可以从cisco的bug库中搜索到一个类似的bug,有可能是系统ipv6 feature的原因,受影响的版本是3.1(495),如果你的anyconnect版本还有系统恰好符合这个bug描述的话,可以尝试更换一个anyconnect的版本 (https://bst.cloudapps.cisco.com/bugsearch/bug/CSCud73928 )  <--- bug url

 

如果按照bug中的临时解决办法,卸载了ipv6,重启重装anyconnect仍旧不能解决的话,可以将一些连接的message收集上来再做分析。

//可以参考下图查看message和 anyconnect 版本

2021-07-15-408.png

 

 

Problem

While attempting to connect to a clients AnyConnect, this happened;

图像_2021-07-15_150620.png

The VPN client was unable to successfully verify the IP forwarding table modifications. A VPN connection will not be established.

Or on older clients, you may see;

The VPN client was unable to modify the IP forwarding table. A VPN connection will not be established. Please restart your computer or device, then try again.

Solution

I was trying to connect from my house, I’d used this connection before from work and it was fine. I worked my way round the problem got my work finished, then re-looked at it the next time I was working from home.

The problem is actually quite simple, take a look at the IP I was using in my house.

图像_2021-07-15_150814.png

Then take a look at the VPN Pool addresses that get allocated to the remote VPN clients (they overlap);

show run | incl pool

图像_2021-07-15_150901.png

Note: This assumes you are using an ‘IP Pool’, If you are using an external DHCP server at the ‘Head end’ then you will need to check/change the scope there.

AnyConnect – Using a Windows DHCP Server to Lease IP Addresses to the Remote Clients

I fixed the problem by simply changing the ‘pool’ so it didn’t overlap.

图像_2021-07-15_150953.png

WARNING: If you have any routing going on behind your firewall (i.e you have layer 3 switches internally, routing between networks or VLANS) you may need to change them to route the ‘new’ AnyConnect subnet back to the firewall.

Update: Solution Windows 10

If you are experiencing this problem on Windows 10, and the above solution is not applicable, consider deleting the following two files;

C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\routechangesv4.bin
C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\routechangesv6.bin

图像_2021-07-15_151039.png

 

Refer to:https://www.petenetlive.com/kb/article/0001646

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Rps-Cheers | If it solves your problem, please mark as answer. Thanks !
快捷链接