cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
Announcements
Choose one of the topics below to view our ISE Resources to help you on your journey with ISE

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

44511
Views
2
Helpful
10
Replies
Contributor

AnyConnect keeps reconnecting

Greetings,

Running into an issue with AnyConnect constantly reconnecting to wireless. I have ISE set to recheck posture every 7 days and this started popping up after the WLC's were updated to 8.2.110.0.

Anyone know of a setting to check as it's driving us nuts.

Thanks,

1 ACCEPTED SOLUTION

Accepted Solutions
Highlighted
Cisco Employee

Re: AnyConnect keeps reconnecting

Cisco AnyConnect Secure Mobility Client Administrator Guide, Release 4.0 - Configure Posture [Cisco AnyConnect Secure …

  • IP Address ChangeFor the optimal user experience, set the values below to our recommendations.
    • VLAN detection interval—Interval at which the agent tries to detect VLAN changes before refreshing the client IP address. The valid range is 0 to 900 seconds, and the recommended value is 5 seconds.
    • Ping or ARP—The method for detecting IP address changes. The recommended setting is ARP.
    • Maximum timeout for ping—The ping timeout from 1 to 10 seconds.
    • Enable agent IP refresh—Check to enable VLAN change detection.
    • DHCP renew delay—The number of seconds the agent waits after an IP refresh. Configure this value when you have Enable Agent IP Refresh enabled. If this value is not 0, the agent will do an IP refresh during this expected transition. If a VPN is detected during the refresh, the refresh will be disabled. The valid values are 0 to 60 seconds, and the recommended value is 5 seconds.
    • DHCP release delay— The number of seconds the agent delays doing an IP refresh. Configure this value when you have Enable Agent IP Refresh enabled. If this value is not 0, the agent will do an IP refresh during this expected transition. If a VPN is detected during the refresh, the refresh will be disabled. The valid values are 0 to 60 seconds, and the recommended value is 5 seconds.
    • Network transition delay—The timeframe (in seconds) for which the agent suspends network monitoring so that it can wait for a planned IP change. The recommended value is 5 seconds.

View solution in original post

10 REPLIES 10
Highlighted
Cisco Employee

Re: AnyConnect keeps reconnecting

Hi Dustin,

Are you using Anyconnect NAM or posture(compliance module)? Since you mentioned posture, is the AC popping up to do posture and failing?. Please make sure your redirect ACL is correctly applied and the ACL name downloaded from ISE is the same in WLC.

Run debugs on ISE using endpoint debug to see what is happening. You can also gather AC logs and look at the logs to see where it is getting stuck.

Finally if this is the only client having the problem, reboot and see if the problem goes away.

Please open a case with TAC if your initial troubleshooting does not fix it.

Thanks

Krishnan

Highlighted
Contributor

Re: AnyConnect keeps reconnecting

No, getting multiple clients started this.

Use AC NAM and ISE posture. I have it re-posture every 7 days. ISE shows fine and compliant. WLC does show the reconnecting. May be due to the admin disabling ping over wireless, Trying to see if that is the issue.

Highlighted
Contributor

Re: AnyConnect keeps reconnecting

So, re-enabling ping seems to have fixed the issue. Not sure what AnyConnect is trying to ping, but with it off it says there is a connection error and tries to reconnect. Having ping allowed seems to have stopped the flapping.

Highlighted
Cisco Employee

Re: AnyConnect keeps reconnecting

Anyconnect NAM does not send pings. May be something else is happening on the PC. Please check using wireshark what is causing it.

Highlighted
Beginner

Re: AnyConnect keeps reconnecting

I am using MAC - can I please know how to do these changes, I meant, which file(s) to edit and what to edit.

 

My Cisco Anyconnect installation location is 

/opt/cisco/anyconnect

 

I am getting every few seconds reconnecting when using Cisco Anyconnect ver 4.6. I have tried using different Internet providers.

Highlighted
VIP Advocate

Re: AnyConnect keeps reconnecting

This section and specifically this topic relate to network access control.  The AnyConnect module being discussed here is the network access manager (NAM), which performs 802.1x functions for endpoints onboarding to the internal network. The reconnecting / reauthentication is not the same as VPN access. 

So it sounds like your question is related to the AnyConnect core remote access VPN functions.  For that you will want to create a thread in the Network Security forum that deals with ASA/AC/FTD.
https://community.cisco.com/t5/network-security/bd-p/discussions-network-security

 

 

Highlighted
Cisco Employee

Re: AnyConnect keeps reconnecting

Cisco AnyConnect Secure Mobility Client Administrator Guide, Release 4.0 - Configure Posture [Cisco AnyConnect Secure …

  • IP Address ChangeFor the optimal user experience, set the values below to our recommendations.
    • VLAN detection interval—Interval at which the agent tries to detect VLAN changes before refreshing the client IP address. The valid range is 0 to 900 seconds, and the recommended value is 5 seconds.
    • Ping or ARP—The method for detecting IP address changes. The recommended setting is ARP.
    • Maximum timeout for ping—The ping timeout from 1 to 10 seconds.
    • Enable agent IP refresh—Check to enable VLAN change detection.
    • DHCP renew delay—The number of seconds the agent waits after an IP refresh. Configure this value when you have Enable Agent IP Refresh enabled. If this value is not 0, the agent will do an IP refresh during this expected transition. If a VPN is detected during the refresh, the refresh will be disabled. The valid values are 0 to 60 seconds, and the recommended value is 5 seconds.
    • DHCP release delay— The number of seconds the agent delays doing an IP refresh. Configure this value when you have Enable Agent IP Refresh enabled. If this value is not 0, the agent will do an IP refresh during this expected transition. If a VPN is detected during the refresh, the refresh will be disabled. The valid values are 0 to 60 seconds, and the recommended value is 5 seconds.
    • Network transition delay—The timeframe (in seconds) for which the agent suspends network monitoring so that it can wait for a planned IP change. The recommended value is 5 seconds.

View solution in original post

Highlighted
Contributor

Re: AnyConnect keeps reconnecting

Thanks, default in the config is ping. Changed to arp.

Highlighted
Beginner

Re: AnyConnect keeps reconnecting

How and where do I perform these actions? 

Highlighted
Beginner

Re: AnyConnect keeps reconnecting

This seems geared towards Windows type software. I posted this same issue for my macbook pro. Has there been cases, solutions regarding macbooks?  

 

Here is my post:

https://community.cisco.com/t5/identity-services-engine-ise/cisco-anyconnect-constantly-reconnecting-on-macbook-pro/td-p/3869047