cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5024
Views
5
Helpful
18
Replies

ASA 9.18.3. cannot access Client Profile

gaigl
Level 3
Level 3

Hello,

while trying new Cisco Secure Client 5, on Firepower 21xx (same on FPR4112) with ASA 9.18.3.56 and ASDM 7.19.1.95 I can't access the Profile Editor: if I click on the "Secure Client Profile" ASDM still shows me the Client Images.

I've tried to remove the 5.x Clients, but nothing happens, tried with ver 5.1.0.136 and 5.0.05040.

on the CLI I see the profile:

 

 anyconnect profiles ACME-PROFILE.TEST disk0:/acme-profile.test.xml

 

18 Replies 18

another Test:

under "Secure Client Software" I replaced V4-(Anyconnect) with V5-(Secure Client) Image, so there's only a V5 Package, that's working fine (we cannot use this config in Prod, because Updates should be done via Softwaredistribution).

So for me it looks like the ASDM doesn't like a V4 Image and a V5 Image at the same time under Secure Client Software.

Would be fine if someone could confirm

PeterLMSD
Level 1
Level 1

I have duplicated exactly the same issue running on an 5506-X and ASAv 9.18(3)56 on VMWare workstation in my lab.

  • ASA 9.16(4)62 or 9.18(3)56 (yes it's not supported on the 5506-X but it works)
asa9-16-4-42-lfbff-k8.SPA
asa9-18-3-56-lfbff-k8.SPA
  • ASDM 7.18(1)161 or 7.19(1)95 or 7.20(1)
asdm-7181-161.bin
asdm-7191-95.bin
asdm-7201.bin

With the software image shown in the order it is configured as Client Software. Each time you change around the configuration you need to fully restart ASDM to make sure it's working or not.

  Working combinations. 

Option 1:
- anyconnect-win-4.10.01075-webdeploy-k9.pkg

Option 2:
- cisco-secure-client-win-5.0.05040-webdeploy-k9.pkg

Option 3:
- anyconnect-win-4.10.01075-webdeploy-k9.pkg
- cisco-secure-client-win-5.0.05040-webdeploy-k9.pkg

Option 4:
- cisco-secure-client-win-5.0.05040-webdeploy-k9.pkg
- anyconnect-win-4.10.01075-webdeploy-k9.pkg

Option 5:
- cisco-secure-client-win-5.1.0.136-webdeploy-k9.pkg

As above if I have only Secure Client 5.1 on it's own it works fine. Retested and it doesn't work if Secure Client 5.0 and 5.1, so moved that into the not working combinations.

Not working combinations

Option 1:
- anyconnect-win-4.10.01075-webdeploy-k9.pkg
- cisco-secure-client-win-5.1.0.136-webdeploy-k9.pkg

Option 2:
- cisco-secure-client-win-5.1.0.136-webdeploy-k9.pkg
- anyconnect-win-4.10.01075-webdeploy-k9.pkg

Option 3:
- anyconnect-win-4.10.01075-webdeploy-k9.pkg
- cisco-secure-client-win-5.0.05040-webdeploy-k9.pkg
- cisco-secure-client-win-5.1.0.136-webdeploy-k9.pkg

Option 4:
- cisco-secure-client-win-5.0.05040-webdeploy-k9.pkg
- cisco-secure-client-win-5.1.0.136-webdeploy-k9.pkg

It appears to me if you have the AnyConnect 4 and / or Secure Client 5.0 and Secure Client 5.1 as configured images then the AnyConnect Client Profile tab in ASDM just won't work.

This also happens with the latest versions of ASDM 7.18(1)161, 7.19(1)95 and 7.20(1)

And some screenshots to show the problem.

PeterLMSD_1-1701296436829.png

Then clicking on AnyConnect Client Profile and it doesn't work. Notice how the screen is still showing the Client Software versions

 PeterLMSD_2-1701296477235.png

Then if I only have Secure Client 5.1 (or 5.0 and 5.1)

PeterLMSD_3-1701296509207.png

And now I can edit the Client Profile and the profile can be edited.

PeterLMSD_4-1701296530334.png

And the version of the AnyConnect VPN Client Profile Editor version and select "About" if I only have 5.1 image running the version that is shown in Profile Editor is 5.1.0134.

PeterLMSD_0-1701373135364.png

PeterLMSD
Level 1
Level 1

Just noticed that 5.1.1.42 has been released.

If I have the Windows and Mac versions loaded then I have the problem again.

anyconnect image disk0:/cisco-secure-client-win-5.1.1.42-webdeploy-k9.pkg 1 regex "Windows NT"
anyconnect image disk0:/cisco-secure-client-macos-5.1.1.42-webdeploy-k9.pkg 2 regex "Intel Mac OS X"

If I remove the second entry for Mac OS and have a single Windows entry then restart ASDM it works.

Cisco AnyConnect VPN Client
Profile Editor Version 5.1.0134
Copyright 2009-2023 Cisco Systems, Inc. All Rights Reserved

Update: Just found if I upgrade to ASDM 9.20.2 it works again.

gaigl
Level 3
Level 3

I think, it's solved with ASDM 9.20.2

my Combination:

anyconnect win 4.10.07061

secure client win 5.1.1.42

is fine, I can edit and validate client-profile