cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2987
Views
0
Helpful
4
Replies

Anyconnect dual ISP

eandcciscoadmin
Frequent Visitor
Frequent Visitor

Hello everyone,

I have a Cisco ASA configured with Dual ISP failover. The failover and failback after first ISP port shutdown and turning back on, works fine. I have a concern about Anyconnect connections after failover. Is there a way for  ASA to disconnect all Anyconnect users after failback to main ISP automatically?

By "automatically" I mean that I don't have to intervene and kill all the connections by myslef but ASA detects that main ISP is back on line and kills all second ISP Anyconnect connections.

Thanks,

Ramin

1 Accepted Solution

Accepted Solutions

I think you could automate that with an Embedded Event Manager script.

--
If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.

View solution in original post

4 Replies 4

When you clear the AnyConnect sessions, you also disturb your users work. I prefer in these scenarios to let the users continue their work on the secondary ISP connection and when they connect the next time they'll again use the primary connection.

All in all, it seems to me more user-friendly.

--
If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.

True, but our second connection (which is really our 3rd connection has bandwidth limit (1GB)) and we need to keep our monthly bandwidth for a real disaster.

Thanks

I think you could automate that with an Embedded Event Manager script.

--
If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.

Thanks Karsten, I tied the event manager to interface status change from up to down Syslog (411002) with "noconfirm" option which immediately kills all Anyconnect connections.

Thanks for the hint.

Ramin

Review Cisco Networking for a $25 gift card