- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-15-2018 10:48 AM - edited 02-21-2020 07:46 AM
Hello everybody
I have ASA 5540 and its configured for VPN over SSL only. it has been working for 2 years smooth, but since 3 days ago something weird is happening on most of my ios clients who are using cisco anyconnect on their IPhone and IPad. they are receiving " time out error ". Androids are using openconnect , windows and mac are using cisco anyconnect and they are working fine too, its happening on most of ios users.
ping to ASA, trace route ( MTR ) are fine.
any idea ?
best Regards
Yashar
Solved! Go to Solution.
- Labels:
-
NGFW Firewalls
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-22-2018 12:03 PM
Hello All
I have fixed the problem. I was changing the ports though the wizard and it was not working, but I went through command line, and its working now.
webvpn
no enable outside
port 800
enable outside
anyconnect enable
tunnel-group-list enable

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-16-2018 02:01 AM
We could bet that an IOS update hit your clients.
Any chance to test with an older IOS VPN client version?
Also you can consider updating your "VPN server" and hopefully that will match latest Apple IOS vpn client.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-16-2018 02:29 AM
Hello Florin
I tried Legacy anyconnect and same issue. for updating ASA needs contact and I cant download the latest version software. can you help me on IOS if you have the latest one. the one I have is ASA 5540 version 9.1(7).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-16-2018 02:48 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-16-2018 03:02 AM
As I have study on clients during these few days :
1- Anyconnect new version and Legacy is not working on ios only.
2- Anyconnect on windows /Mac and openconnect on android are connecting easy through the same internet that IOS cannot.
3- this problem is happening only for those who are trying to connect from IRAN.
Possibilities:
I thought maybe providers/government has restricted connection to my IP address, but if its restricted why the others are able to connect through same internet with different os; so its not possible my IP is restricted.
they filtered Anyconnect Application to make socket to outside, but why only IOS ? if there is any be restriction on application layer , it should be applied to all cisco apps.
confusing...
do you think changing SSL certs and domain name / IP block helps ?
Thank You
Yashar
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-16-2018 03:43 AM - edited 05-16-2018 03:43 AM
It is most likely as Florin has already mentioned, an iOS software update that has been released for the Apple devices. Do you have an Apple device that has not installed the latest update yet?
Please remember to select a correct answer and rate helpful posts
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-16-2018 05:07 AM
mine is 11.3.1 and connects easy, but the difference is I am not in IRAN. as I checked with few of clients they have 11.2.1 and cant connect.these people with latest version and previous version of IOS were able to connect 4 days ago.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-16-2018 08:54 AM
here is error when connection doesn't establish.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-17-2018 12:52 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-17-2018 10:26 AM
Hello
Yes, I did debug and the cert was completely current, but I found out the SSL connection/signature is resetting every 30 seconds by providers, seems they have filtered my domain name. I ordered for as a new SSL cert and domain name. Im going to swap out the cert and IP block and lets see what happens .
I will update the result here.
Thank You
Best Regards
Yashar
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-17-2018 08:25 PM
Hello everybody,
I have changed the ASA IP and swapped out the cert, but still those who are using anyconnect on ios ( new and legacy version ) are not able to connect.
guys, is it possible Cisco Anyconnct app to be filtered from opening socket outside ?
is there any alternative app/solution ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-18-2018 02:23 PM
It seems to me the issue is Iran has blocked access to your network.
Can you check if port 443 is open and also if you can access the clientless VPN?
Martin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-19-2018 04:29 AM
Dear Martin
Port #443 is blocked by provider ( as I found out ) to solving this problem :
1- I have changed " IPSec Client Service Port " port from 443 to any other numbers (ex: 999)
2- in Anyconnect setting I changed server address from srv.mydomain.com to srv.mydomain.com:999
now clients passes the first step to choosing profile and entering username/password as they couldn't reach to this step before, but I Im facing with another problem :
* when client enter username/password, they receive error " login denied, unauthorized connection mechanisrm, contact your administrator "
any idea ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-19-2018 09:10 AM - edited 05-19-2018 09:43 AM
I debugged radius packets on Billing server and saw the ASA is sending username and password, but instead of password, username again.
totally confused, same radius setting is working fine current profile which is set with srv.mydomain.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-19-2018 10:32 AM
Thought so.
That issue you now have is it would appear the GP is not setup for the correct tunnelling protocol (i.e. SSL VPN Client) in this case.
Can you clarify?
Martin
