cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4450
Views
0
Helpful
2
Replies

Anyconnect SSL VPN Problem

shen dong
Level 1
Level 1

Hi there,

some Anyconnect Users experience frequent disconnects:

Oct  9 14:10:08 fw : %ASA-4-113019: Group = A, Username = W, IP = a.b.c.d, Session disconnected. Session Type: SSL, Duration: 0h:03m:44s, Bytes xmt: 555379, Bytes rcv: 479046, Reason: Connection Preempted
Oct  9 14:14:49 fw : %ASA-4-113019: Group = A, Username = W, IP = a.b.c.d, Session disconnected. Session Type: SSL, Duration: 0h:04m:41s, Bytes xmt: 705887, Bytes rcv: 586615, Reason: Connection Preempted
Oct  9 14:26:18 fw : %ASA-4-113019: Group = A, Username = W, IP = a.b.c.d, Session disconnected. Session Type: SSL, Duration: 0h:11m:29s, Bytes xmt: 660791, Bytes rcv: 653513, Reason: Connection Preempted

When placing "ping -t <destination through the tunnel>" the Anyconnect session is not disconnected. The idle timeout is set to 60 min.

Can anyone give me a hint?

thank you .

Software  Versions:

Cisco Anyconnect Secure Mobility Client, Version 3.1.05182

# sh ver

Cisco Adaptive Security Appliance Software Version 9.1(4)
Device Manager Version 7.3(1)101

Compiled on Thu 05-Dec-13 19:37 by builders
System image file is "disk0:/asa914-k8.bin"
Config file at boot was "startup-config"

# up 23 days 9 hours
failover cluster up 1 year 124 days

Hardware:   ASA5520, 2048 MB RAM, CPU Pentium 4 Celeron 2000 MHz,
Internal ATA Compact Flash, 256MB
BIOS Flash M50FW080 @ 0xfff00000, 1024KB

Encryption hardware device : Cisco ASA-55xx on-board accelerator (revision 0x0)
                             Boot microcode        : CN1000-MC-BOOT-2.00
                             SSL/IKE microcode     : CNLite-MC-SSLm-PLUS-2_05
                             IPSec microcode       : CNlite-MC-IPSECm-MAIN-2.09
                             Number of accelerators: 1



20150112160231.jpg

2 Replies 2

admin11111
Level 4
Level 4

i have been seeing this issue for two years, with multiple ASA's any resolution?

admin11111
Level 4
Level 4

vpn session is byyond the limit .  Use this command:  vpn-simultaneous-logins 5000