cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1389
Views
10
Helpful
7
Comments
ronald.su
Level 1
Level 1

hello, 

tricky thing, we using ASA and anyconnect for the remote user access. but lots of users report anyconnect will disconnect and reconnect at the first beginnging, it will happen 1 times and then will become stable. won't disconnect again.

I test lots of times, everytime I connected, and it will disconnect and reconnect 1 minute and 3 seconds, after that , it will become stable , won't disconnect again, no matter how long I connected.

and we got 2 ASA,

ASA1 is ASA5515-X 9.12(4) located at Hongkong

ASA2 is ASA5515-X  9.1(2) located at Singapore

some user using Anyconnect 3.1 , some is 4.8 

no matter what anyconnect client version and no matter which ASA connect to , everytime! it will reconnect after 63 second, no more and no less.

the client log :

10/15/2020
2:22:15 PM Ready to connect.
2:22:20 PM Contacting ASA1.mydomain.com.
2:22:25 PM User credentials entered.
2:22:30 PM User credentials entered.
2:22:30 PM Establishing VPN session...
2:22:31 PM The AnyConnect Downloader is performing update checks...
2:22:31 PM Checking for profile updates...
2:22:31 PM Checking for customization updates...
2:22:31 PM Performing any required updates...
2:22:31 PM The AnyConnect Downloader updates have been completed.
2:22:31 PM Establishing VPN - Initiating connection...
2:22:31 PM Establishing VPN session...
2:22:31 PM Establishing VPN - Examining system...
2:22:31 PM Establishing VPN - Activating VPN adapter...
2:22:32 PM Establishing VPN - Configuring system...
2:22:32 PM Establishing VPN...
2:22:32 PM Connected to ASA1.mydomain.com.
2:23:35 PM Reconnecting to ASA1.mydomain.com...
2:23:35 PM Establishing VPN - Examining system...
2:23:41 PM Establishing VPN - Activating VPN adapter...
2:23:42 PM Establishing VPN - Configuring system...
2:23:42 PM Establishing VPN...
2:23:42 PM Connected to ASA1.mydomain.com.
2:23:42 PM Reconnecting to ASA1.mydomain.com...
2:23:42 PM Establishing VPN - Examining system...
2:23:42 PM Establishing VPN - Activating VPN adapter...
2:23:42 PM Establishing VPN - Configuring system...
2:23:42 PM Establishing VPN...
2:23:42 PM Connected to ASA1.mydomain.com.

 

 

10/15/2020
2:38:17 PM Contacting ASA2.mydomain.com.
2:38:29 PM User credentials entered.
2:38:29 PM Establishing VPN session...
2:38:30 PM The AnyConnect Downloader is performing update checks...
2:38:30 PM Checking for profile updates...
2:38:30 PM Checking for customization updates...
2:38:30 PM Performing any required updates...
2:38:30 PM The AnyConnect Downloader updates have been completed.
2:38:30 PM Establishing VPN - Initiating connection...
2:38:30 PM Establishing VPN session...
2:38:32 PM Establishing VPN - Examining system...
2:38:32 PM Establishing VPN - Activating VPN adapter...
2:38:32 PM Establishing VPN - Configuring system...
2:38:33 PM Establishing VPN...
2:38:33 PM Connected to ASA2.mydomain.com.
2:39:36 PM Reconnecting to ASA2.mydomain.com...
2:39:36 PM Establishing VPN - Examining system...
2:39:42 PM Establishing VPN - Activating VPN adapter...
2:39:43 PM Establishing VPN - Configuring system...
2:39:43 PM Establishing VPN...
2:39:43 PM Connected to ASA2.mydomain.com.
2:39:44 PM Reconnecting to ASA2.mydomain.com...
2:39:44 PM Establishing VPN - Examining system...
2:39:44 PM Establishing VPN - Activating VPN adapter...
2:39:44 PM Establishing VPN - Configuring system...
2:39:44 PM Establishing VPN...
2:39:44 PM Connected to ASA2.mydomain.com.

 

 

7 Comments

I would check the ASA logs at the time the client get disconnected, as well as the clients logs.

ronald.su
Level 1
Level 1

I monitor log via asdm, nothing found...if there have any debug mode can help to locate the issue?

I think looking specifically at the Syslog 113019 would be a good start. That Syslog message would show you the reasons why the session got disconnected. It might be something wrong on the client side, looking at the client event viewer would also be useful.

Milos_Jovanovic
VIP Alumni
VIP Alumni

Hi,

I had similar issues in the past, and most frequent, it is related to DTLS. Make sure your ASA is reachable on UDP/443 as well as on TCP/443.

AnyConnect is initially trying to connect to TCP/443 for management channel, but, at the same time, it will try to bring up UDP/443 for data channel. If it is unable to build it, it will reconnect (in about 60s) in order to realize it won't have different channels, at which it will works stable.

I saw this behavior when ASA was behind a router (either NAT or ACL drop).

You can also check if DTLS is running on your ASA with sh asp table socket.

Alternatively, you could go and disable DTLS, but I wouldn't recommend this, as it can have its impact (you'll see huge restrictions in bandwidth from user perspective).

Best regards

Milos_Jovanovic
VIP Alumni
VIP Alumni

And, you should really upgrade both ASA and AnyConnect clients, regardless of this issue, as there are lots of security vulnerabilities on older code.

ronald.su
Level 1
Level 1

@Milos_Jovanovic 

 

awsome !!!! you are right , it's UDP 443 caused it, my ASA is behind a NAT device, and after I allow udp443, the anyconnect become stable !!!!

thanks!

Milos_Jovanovic
VIP Alumni
VIP Alumni

Glad to hear that it helped

Please mark this thread as solved, in order to help others.

Thanks

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: