09-10-2019 07:45 AM
Hello everyone,
I have a Cisco ASA configured with Dual ISP failover. The failover and failback after first ISP port shutdown and turning back on, works fine. I have a concern about Anyconnect connections after failover. Is there a way for ASA to disconnect all Anyconnect users after failback to main ISP automatically?
By "automatically" I mean that I don't have to intervene and kill all the connections by myslef but ASA detects that main ISP is back on line and kills all second ISP Anyconnect connections.
Thanks,
Ramin
Solved! Go to Solution.
09-10-2019 01:04 PM
I think you could automate that with an Embedded Event Manager script.
09-10-2019 09:26 AM
When you clear the AnyConnect sessions, you also disturb your users work. I prefer in these scenarios to let the users continue their work on the secondary ISP connection and when they connect the next time they'll again use the primary connection.
All in all, it seems to me more user-friendly.
09-10-2019 12:31 PM
True, but our second connection (which is really our 3rd connection has bandwidth limit (1GB)) and we need to keep our monthly bandwidth for a real disaster.
Thanks
09-10-2019 01:04 PM
I think you could automate that with an Embedded Event Manager script.
10-17-2019 01:04 PM
Thanks Karsten, I tied the event manager to interface status change from up to down Syslog (411002) with "noconfirm" option which immediately kills all Anyconnect connections.
Thanks for the hint.
Ramin
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide