cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2583
Views
0
Helpful
4
Replies

Anyconnect dual ISP

eandcciscoadmin
Level 1
Level 1

Hello everyone,

I have a Cisco ASA configured with Dual ISP failover. The failover and failback after first ISP port shutdown and turning back on, works fine. I have a concern about Anyconnect connections after failover. Is there a way for  ASA to disconnect all Anyconnect users after failback to main ISP automatically?

By "automatically" I mean that I don't have to intervene and kill all the connections by myslef but ASA detects that main ISP is back on line and kills all second ISP Anyconnect connections.

Thanks,

Ramin

1 Accepted Solution

Accepted Solutions

I think you could automate that with an Embedded Event Manager script.

View solution in original post

4 Replies 4

When you clear the AnyConnect sessions, you also disturb your users work. I prefer in these scenarios to let the users continue their work on the secondary ISP connection and when they connect the next time they'll again use the primary connection.

All in all, it seems to me more user-friendly.

True, but our second connection (which is really our 3rd connection has bandwidth limit (1GB)) and we need to keep our monthly bandwidth for a real disaster.

Thanks

I think you could automate that with an Embedded Event Manager script.

Thanks Karsten, I tied the event manager to interface status change from up to down Syslog (411002) with "noconfirm" option which immediately kills all Anyconnect connections.

Thanks for the hint.

Ramin

Review Cisco Networking for a $25 gift card