cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
266
Views
1
Helpful
3
Replies

“Authentication attempt timed out" when connecting Cisco SSL VPN

keith-mk-li
Level 1
Level 1

 

Dear All,

               Would like to seek for your support on the following, we have experienced that some devices receiving “Authentication attempt timed out” when connecting Cisco AnyConnect, and i have

checked in ISE -> live logs, I do not see any incoming logs related with the user id appearing in ISE, it seems the authentication traffics doesn’t reach the ISE, just wonder if you have experienced similar problem, I’m not sure this is an issue with the workstation itself or Cisco AnyConnect problem.

 

Below is what we have done but the issue still exist, unless we reinstall the OS to get rid of the issue, anything to check in the vpn appliance ? or its related with workstation issue ? any help would be appreciated

 

Things have test

 

  • Switched to other window profiles and connect Cisco AnyConnect (not work)
  • Reinstall Cisco AnyConnect (not work)
  • Install different Cisco AnyConnect version (not work)

 

from the event viewer i seeing the following

The description for Event ID 259 from source cscan cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.
 
If the event originated on another computer, the display information had to be saved with the event.
 
The following information was included with the event:
 
Function: log_cb_desktop
Thread Id: 0x4AC0
File: c:\temp\build\thehoff\phoenix_mr60.883937951967\phoenix_mr6\posture\asa\cscan\scan_system.c
Line: 446
Level: warn
 
Could not enumerate any more Products. Error : 5

 

Keith

 
 
3 Replies 3

capture traffic in OUTside interface see if the FW see any traffic from Anyconnect 

MHM

Do you have any security product on those endpoints that might affect AnyConnect outbound traffic? do they have any different GPO policies compared to the other endpoints that do not have this issue?

I would recommend installing Wireshark on one of the affected endpoints and run some packet capture and check if you see any initial negotiation between AnyConnect and the remote headend. That will also tell you if the remote headend responds with anything back to the client.