12-02-2025 06:56 AM
Hi All
Anyconnect users in our organization can no longer access the gateway and getting the following error " Connection attempt has failed due to server communication errors .Please retry the connection ."
This has started happening with no apparent reason as no changes were made prior to that . I have verified and confirmed that the trustpoint certificate is valid , the clock on the server is fine . The gateway is also reachable .
The encryption cyphers used are considered weak ssl encryption aes256-sha1 aes128-sha1 as the appliance cannot support stronger alternatives . This has worked fine until now though .
Please find below the event logs form the Anyconnect client .
Function: CTransportCurlStatic::SendRequest
File: c:\temp\build\thehoff\phoenix_mr80.403803346583\phoenix_mr8\vpn\api\ctransportcurlstatic.cpp
Line: 2181
CURL error: 35 = OpenSSL SSL_connect: SSL_ERROR_SYSCALL in connection to vpn.company.net:443
Function: CTransportCurlStatic::SendRequest
File: c:\temp\build\thehoff\phoenix_mr80.403803346583\phoenix_mr8\vpn\api\ctransportcurlstatic.cpp
Line: 2319
Invoked Function: curl_easy_perform
Return Code: -29949908 (0xFE37002C)
Description: CTRANSPORT_ERROR_SSL_HANDSHAKE
35 : Error
Function: ConnectIfc::sendRequest
File: c:\temp\build\thehoff\phoenix_mr80.403803346583\phoenix_mr8\vpn\api\connectifc.cpp
Line: 3333
Invoked Function: CTransport::SendRequest
Return Code: -29949908 (0xFE37002C)
Description: CTRANSPORT_ERROR_SSL_HANDSHAKE
Function: ConnectIfc::connect
File: c:\temp\build\thehoff\phoenix_mr80.403803346583\phoenix_mr8\vpn\api\connectifc.cpp
Line: 486
Invoked Function: ConnectIfc::sendRequest
Return Code: -29949908 (0xFE37002C)
Description: CTRANSPORT_ERROR_SSL_HANDSHAKE
Can you please advise of what could be wrong here ?
Thanks
12-02-2025 08:21 AM
What anyconnect software version are your clients using?
Collect the DART report on a local client where the connection is failing and check the logs, that will hopefully provide more of a clue.
Run some debugs and provide the output - "debug webvpn anyconnect 255" - remember to disable after you've collected the logs.
Provide the output of "show run webvpn" and "show ssl"
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide