cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4484
Views
5
Helpful
2
Replies

Cisco Anyconnect certificate error.

Folks,

We had some DR testing done withing our network few weeks back. What happened was the Primary site(Dallas) was cutout from the network and applications were made to run from the Backup site(Singapore). One of the observations was that end users were not able to login to the Anyconnect node at the Backup site during this exercise. To give some back ground we have few more site where folks can login to the Anyconnect devices. i.e. Sydney, Frankfurt, Markham etc. Folks could only login to the Anyconnect node which is hosted in Sydney.  All other nodes just threw up an error saying "Your certificate is invalid for this selected group". 

I am trying to find out what could be the error and here is one of the discrepancy that I see.

1) I went to Configuration --> Remote Access VPN --> Network(Client) Access --> AnyConnect Client Profile.

2) The I select the required Profile on the Right Hand Side view and click on Edit.

3) When the profile window pops up I scroll down to VPN --> Certificate Matching and within that Window I look at the place where we enter the Distinguished name(Max 10).

4) Now the node where the login was working i.e. Sydney nothing is mentioned in the Distinguished Name(Max 10) field.

5) The nodes where this was failing we have mentioned to check the certificate and there is a value mentioned in the Pattern field. The value matches the value of the Primary site only.

 

Could this be the reason of the failure?

Is there anything else we can look at?

 

Thanks,

N.

1 Accepted Solution

Accepted Solutions

Abaji Rawool
Level 3
Level 3

Hi,

 

Yes, the certificate match on the profile could be the reason for not picking the right certificate to be matched and sent to ASA for authentication. You can check anyconnect Diagnostic logs (DART) to check the failure.

You can run following debugs on the ASA to check which certificate was sent and why it failed.

debug cry ca messages 255

debug cry ca transactions 255

debug cry ca 255

 

Once the logs are collected you type “undebug all”  to stop the debugs

HTH

Abaji,

 

 

 

 

 

View solution in original post

2 Replies 2

Abaji Rawool
Level 3
Level 3

Hi,

 

Yes, the certificate match on the profile could be the reason for not picking the right certificate to be matched and sent to ASA for authentication. You can check anyconnect Diagnostic logs (DART) to check the failure.

You can run following debugs on the ASA to check which certificate was sent and why it failed.

debug cry ca messages 255

debug cry ca transactions 255

debug cry ca 255

 

Once the logs are collected you type “undebug all”  to stop the debugs

HTH

Abaji,

 

 

 

 

 

Thanks Abaji, the issue happened during one of BCP testing which has been reverted no. I will still check for the logs that you have suggested.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: