I have an ASA5516X running 9.5(3) without a VPN configuration but a user pointed out to me that she needs to reconnect her Anyconnect VPN after computer sleeps when on a WLAN passing traffic through the aforementioned ASA while the problem isn't present at home or other locations. Is there any setting I can adjust in order to allow the VPN to resume?
The thing that pops to mind is that I have a one hour DHCP lease but also a high client turnover so it makes sens to keep it low.
I'm unfortunately not able to provide details about the Anyconnect setup as it's maintained by a 3rd party.
One possibility could be the TCP timeout, which by default is set to 1 hour on the ASA. So if the devices goes to sleep and comes back up after an hour, it might not have an established connection through the ASA, which might require it to start a new connection again. You can set a separate timeout for different traffic flows using MPF on the ASA rather than changing the global default.
I guess what I don't like about it is that the anyconnect TCP connection is over SSL 443 so it will include all https traffic. It might make more sense to add the IP addresses of the VPN servers instead but then it requires manual work every time someone has a different VPN provider. There isn't any way to do this by traffic classification, I noted ipsec-pass-thru is available for inspection but would there be some way of adding different timeout based on that?