cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1217
Views
0
Helpful
9
Replies

Anyconnect VPN is working when the Secondary is the Active FW then Anyconnect VPN is not working when the Primary ASA is Active.

vrian_colaba
Level 1
Level 1

Just wanted to seek help on my issue.

Anyconnect VPN is working when the Secondary is the Active FW then Anyconnect VPN is not working when the Primary ASA is Active.

Thank you.

vrian

9 Replies 9

Marvin Rhoads
Hall of Fame
Hall of Fame

Check to make sure there is an AnyConnect client image (and profile if you are using one) on the disk of both units. You can easily check this by comparing the output from the following commands:

dir disk0:/
failover exec standby dir disk0:/

229 -rwx 23985144 20:14:12 Jul 07 2017 anyconnect-macosx-i386-4.3.01095-k9.pkg
230 -rwx 25162392 20:14:54 Jul 07 2017 anyconnect-win-4.3.01095-k9.pkg

8238202880 bytes total (2858024960 bytes free)

MBSIASA/pri/act#

225 -rwx 14601625 20:11:38 Jul 07 2017 anyconnect-linux-64-4.3.01095-k9.pkg
226 -rwx 23985144 20:11:54 Jul 07 2017 anyconnect-macosx-i386-4.3.01095-k9.pkg
227 -rwx 25162392 20:12:12 Jul 07 2017 anyconnect-win-4.3.01095-k9.pkg
246 -rwx 41846784 21:17:28 Jul 07 2017 asasfr-5500x-boot-6.2.0-2.img

8238202880 bytes total (2858135552 bytes free)

I have an anyconnect client image

OK - that eliminates the most common problem. I'm guessing you truncated the output as you don't show a Linux image on the one unit.

What error do you get when it fails?

Still waiting to upgrade the ASA to 9.8.1.5 interim release

See attached file.

How is your active/standby setup? Do you have more than one outside/WAN link?

I ask because I see some errors about finding the next hop that lead me to think you might have some secondary ISP setup, perhaps without the necessary rules that you have on your other connection.

Yes there is some secondary ISP setup.

We'd need to see moire of the configuration to troubleshoot.

If you're able to attache a sanitized copy, we can review it.

If not, then a TAC case woud be in order.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card