cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5793
Views
40
Helpful
21
Replies

Cisco AnyConnect unable to connect with Apple devices

wynneitmgr
Level 3
Level 3

Up until a couple weeks ago we had no issues connecting Apple devices (iPhones and iPads) to our VPN using Cisco AnyConnect. It seems now we cannot connect unless we are on a PC or Android device (tablet or smartphone). So all VPN connections are working fine except on Apple. Does anybody know of anything going on recently with Cisco and Apple? Thank you for any help.

 

VPN1.jpeg

21 Replies 21

Ok, so that sounds like the apple device isn't even attempting to connect to the ASA and the ASA isn't rejection the connection. It sounds like it is more of a local issue with the device itself, try removing the anyconnect client and trying again.

Turn off the debugs "undebug all" and disable the logging "no logging enable"

@Rob Ingram 

 

So it isn't just one Apple device, it is ANY Apple device. I have several iPads and a couple iPhones that cannot connect but no issue with PCs or Android tablets and/or phones.

 

The errors in the iPad logs are:

Connection attempt has failed.

Unable to contact (IP address)

Connection attempt has failed due to server communication errors.

 

VPNLOGS.jpgVPNLOGS2.jpg

Ok understood - the fact you see debugs for the Android but not the apple devices indicates that the apple devices are not even reaching the ASA. I'd recommend calling TAC for further assistance.

@Rob Ingram 

 

I opened a case with Cisco TAC. Not sure if they will help me since it is a software issue. Normally I thought you had to have a support contract for TAC to help you. I know we have warranties, etc on our Firewall, Switch, and Cisco servers.

If it's an AnyConnect problem they should be able to help debug it with you, it could well be a bug with that version on the apple devices.

HTH

@Rob Ingram 

 

I talked with Cisco TAC and they said they will not help me troubleshoot AnyConnect without a contract. So not sure what to do now.

I am not sure it's an easy issue to resolve without the assistance of TAC.

 

Can you purchase a support contract, I don't think it should cost much for your ASA. You can then re-contact TAC and they can help you.