01-13-2016 10:10 AM - edited 02-21-2020 08:37 PM
I am configuring a new connection profile for remote access using IKEv2 instead of ssl. I used the following link for guidelines:
https://supportforums.cisco.com/document/74111/asa-anyconnect-ikev2-configuration-example
It is pretty straightforward but it's not working for me. When I try to connect to the connection profile I get the following error:
"Login denied, unauthorized connection mechanism, contact your administrator"
I haven't configured any DAP records to it's just using the default one that allows all connections. I am not really finding too much information on that error, anyone know what I can do to fix this? Thanks!
Solved! Go to Solution.
01-14-2016 07:01 AM
I have fixed the problem. It was with the xml profile. I had to import it into the "Profile" folder on my local PC. I did this yesterday but I don't think the xml profile was configured correctly. Here is the path to put it in the correct folder on a windows 7 machine:
%PROGRAMDATA%\Cisco\Cisco AnyConnect Secure Mobility Client\Profile
The link I pasted in my original comment has that information. After I pasted it in I changed the XML profile to look like this:
<?xml version="1.0" encoding="UTF-8"?>
<AnyConnectProfile xmlns="http://schemas.xmlsoap.org/encoding/">
<ServerList>
<HostEntry>
<HostName>vpn.customer.com</HostName>
<HostAddress>vpn.customer.com</HostAddress>
<PrimaryProtocol>IPsec</PrimaryProtocol>
</HostEntry>
</ServerList>
</AnyConnectProfile>
It works if I put the IP address in for the <HostAddress> section but then I get a certificate error since the dns lookup is being done by the host file on my local machine. I am not a fan of this as each person who is going to connect in this manner will have to put that xml file in the profile folder. According to the link I was working with, it will automatically install the xml profile in the profile folder if they use the web deployment, I was unable to test this out though as I am getting a JAVA error when trying that method. Either way, the issue is resolved. Thanks for you help Philip!
01-14-2016 12:46 PM
You're welcome. It would be great if you could mark the answer and rate it if you think it is correct. :-)
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide