cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
578
Views
0
Helpful
2
Replies

AnyConnect Users unable to change their password themselves.

michael090608
Level 1
Level 1

Hello, 

I have recently migrated my ASA to a new 5545. I noticed that since after this migration, users are unable to change their password themselves when it expires. I am talking about users who are connecting through AnyConnect.
Anyone knows what I have to do in order to get this back ?
Right now if a password expires, the Admin has to reset it for the user. 

 

Thanks a lot.

2 Replies 2

@michael090608 do you have the password-management command configured under the tunnel group?

When you configure the password-management command, the ASA notifies the remote user at login that the user’s current password is about to expire or has expired. The ASA then offers the user the opportunity to change the password. If the current password has not yet expired, the user can still log in using that password.

https://www.cisco.com/c/en/us/td/docs/security/asa/asa94/config-guides/cli/vpn/asa-94-vpn-config/vpn-groups.html