cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3540
Views
0
Helpful
1
Replies

AnyConnect Always On

rmeans
Level 3
Level 3

I am testing AnyConnect's "always on" feature.  The connect failure policy is working as I expected.  I thought I would others input.  The Automatic VPN policy has been in place for sometime.  Trusted - disconnect.  Untrusted - connect

 

At this point, I enable Always On, Allow VPN disconnect and set the failure policy to Open.  Connection failure policies - grey out.

 

From Cisco documentation. http://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect31/administration/guide/anyconnectadmin31/ac03vpn.html#pgfId-1205144

The fail-open policy permits network connectivity.  Regardless of the connect failure policy, AnyConnect continues to try to establish the VPN connection.

From the "advantage" section of the table.

Grants full network access, letting users continue to perform tasks where access to the Internet or other local network resources are needed.

 

I successfully disconnected and canceled my VPN session.  I expected to be able to continue browsing the internet.  I was not.  I also expected AnyConnect to prompt me again for a username/passwd (from AnyConnect continues to try to establish the VPN connection - above).

 

What am I missing?

1 Reply 1

pjain2
Cisco Employee
Cisco Employee

please see the "Configuring the connect failure policy" section:

http://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect30/administration/guide/anyconnectadmin30/ac03vpn.html#pgfId-1257039

"Open—This setting permits network access by browsers and other applications when the client cannot connect to the ASA. An open connect failure policy does not apply if you enable the Disconnect button and the user clicks Disconnect ."

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: