05-04-2017 09:35 AM - edited 02-21-2020 09:16 PM
hello, vpn guru.
Our clients have cisco asa 5505.
asa is configured for vpn via Cisco VPN Client (5.0.07.0440) - everything worked like a charm for years.
Now clients get Windows 10, installed Cisco AnyConnect Secure Mobility client (3.1.06073) and can't connect to workplace.
"Login failed". Thats it.
Any suggestions?
thanks and sorry for my english
05-04-2017 01:59 PM
"Login failed" could show up if your AAA authentication fails when using Anyconnect. I have also seen when you do not have enough licenses to use Anyconnect with. Are you using the same AAA server that was being used for the Cisco VPN client? Please post a sanitized config of the ASA here.
05-04-2017 07:06 PM
Hi,
enable term mon on ASA and share the logs when you try to connect to AnyConnect
05-05-2017 06:42 AM
If I am understanding the original post correctly they were using the IPsec VPN client and it was working until they got to Windows 10, and the IPsec client would not install or work on Windows 10. So they shifted to AnyConnect. There is certainly a possibility that the configuration for AnyConnect SSL VPN on the ASA is not correct. So some details of the ASA configuration would be quite helpful. But we also need to consider the possibility that as they shifted from IPsec client (which does not require specific license) to AnyConnect client (which does require specific license) that they have not purchased the required license. Can the original poster provide clarification about these possibilities?
HTH
Rick
05-08-2017 11:26 PM
Thanks a lot, guys for response.
there is so many questions from you, i event dont know what to say. Coz i am not sure how to "post a sanitized config" or how to "clarificate licence question".
But i woul like to ask you - its even possible to make working vpn connection with this infrastructure:
Client side has windows 10 with Cisco Cisco AnyConnect Secure Mobility Client and "server" side has cisco asa 5505? coz you know this asa 5505 is pretty old piece of hardware.
thanks
05-09-2017 06:37 AM
You should be able to use the ASA5505 provided you use the right software versions and have the right licenses to support Anyconnect use. I noticed that the first supported Anyconnect release for Windows 10 is the 3.1.10010. You are running a few releases behind this, so you may want to upgrade this and test again.
http://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect31/release/notes/anyconnect31rn.html#pgfId-320051
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide