cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3014
Views
0
Helpful
4
Replies

AnyConnect 3.1.05152 Cannot Select Group

Micheal Hobday
Level 1
Level 1

Hello,

I have recently upgraded to 3.1.05152 of the anyconnect client and we now have an issue when trying to select a group, the client just refreshes back to the top group. If you have upgraded from an older version any groups that you have used before to connect will work but you cannot select an option that you have not used before.

ASA Version is 8.4(2)

Log from client device below, does not matter which OS is used.

Jan 30 10:54:18 client device acvpnui[5379]: Initiating VPN connection to the secure gateway https://vpnfdqn

Jan 30 10:54:19 client device acvpnui[5379]: Function: getUserName File: ../../vpn/Api/CTransportCurlStatic.cpp Line: 1939 PasswordEntry username is username

Jan 30 10:54:19 client device acvpnui[5379]: Function: PeerCertVerifyCB File: ../../vpn/Api/CTransportCurlStatic.cpp Line: 857 Return success from VerifyServerCertificate

Jan 30 10:54:19 client device acvpnui[5379]: The following error message was received from the secure gateway: VPN Server could not parse request.

Jan 30 10:54:19 client device acvpnui[5379]: Function: connect File: ../../vpn/Api/ConnectMgr.cpp Line: 2071 Encountered ServerRequestParseError, Fall back to using AggAuth version 1

Jan 30 10:54:19 client device acvpnui[5379]: Function: getUserName File: ../../vpn/Api/CTransportCurlStatic.cpp Line: 1939 PasswordEntry username is username

Jan 30 10:54:19 client device acvpnui[5379]: Function: PeerCertVerifyCB File: ../../vpn/Api/CTransportCurlStatic.cpp Line: 857 Return success from VerifyServerCertificate

Jan 30 10:54:20 client device acvpnui[5379]: Function: ProcessPromptData File: ../../vpn/Api/SDIMgr.cpp Line: 257 Processing initial RSA token challenge received from secure gateway.

Jan 30 10:54:20 client device acvpnui[5379]: Function: getPreference File: ../../vpn/Api/PreferenceInfoBase.cpp Line: 269 Invoked Function: getPreference Return Code: 0 (0x00000000) Description: Invalid preference 11

Jan 30 10:54:20 client device acvpnui[5379]: Function: processMainPageDataForRSA File: ../../vpn/Api/SDIMgr.cpp Line: 1070 Invoked Function: PreferenceMgr::getPreference Return Code: -30343157 (0xFE31000B) Description: PREFERENCEMGR_ERROR_PREFERENCE_NOT_FOUND RSASecurIDIntegration

Jan 30 10:54:20 client device acvpnui[5379]: Function: processMainPageDataForRSA File: ../../vpn/Api/SDIMgr.cpp Line: 1197 RSA Token software not available

Jan 30 10:54:20 client device acvpnui[5379]: Function: LogTokenType File: ../../vpn/Api/SDIMgr.cpp Line: 1342 Method invoked from:   Function processMainPageDataForRSA   Line 1198 RSA Token Type is: "hardware" RSA Authentication mode is: "automatic".

Jan 30 10:54:20 client device acvpnui[5379]: Message type prompt sent to the user: Awaiting user input.

4 Replies 4

freddysmertz
Level 1
Level 1

Any update on this? We are running into the same issue with Macs and Windows boxes.

Hello Fred,

Not yet, I have tried different java versions/making sure tunnel lock isn't on/administrator rights. Next step is remove all java and anyconnect software and fresh install. If we install an older version and connect and then let the firewall update to the latest version, then we can use the group we selected originally to connect but cannot choose any other group. If just install the latest version it just defaults back to the top option.

Micheal

AnyConnect is selecting the group that is set as defaultGroup in the preferences file. Changing the group name to any other group available on the VPN-Gateway will let you use that group from the client (after completely restarting the AnyConnect Client).

Deleting the preferences file will let you chose the group in the client itself.

This crude workaround was tested under Win64 only.

Cheers, S

Hello Micheal,

I think you are hitting a new bug:

CSCum89178  - AC 3.1.05152 for Windows - Unable to select tunnel-group from drop down

Workaround:

Upgrade to 9.1 code.

HTH.