cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
448
Views
0
Helpful
3
Replies
ziqex
Beginner

Issue with internet over vpn

Hello,

I am facing the below issue. All other machines can access internal and external pages without issues. One machine can only access internal pages and services.

While checking vpn session on the asav I can see the following for non working machine:

Protocol : AnyConnect-Parent SSL-Tunnel
License : AnyConnect Premium
Encryption : AnyConnect-Parent: (1)none SSL-Tunnel: (1)AES128
Hashing : AnyConnect-Parent: (1)none SSL-Tunnel: (1)SHA1

 

While on working machine the below is present:

 

Protocol : AnyConnect-Parent SSL-Tunnel DTLS-Tunnel
License : AnyConnect Premium
Encryption : AnyConnect-Parent: (1)none SSL-Tunnel: (1)AES128 DTLS-Tunnel: (1)AES-GCM-256
Hashing : AnyConnect-Parent: (1)none SSL-Tunnel: (1)SHA1 DTLS-Tunnel: (1)SHA384

 

The difference for working is presence of DTLS-Tunnel.

I have checked the tunnel group and dtls port is 443.

Is there a way to verify why dtls is not present for the machine?

Thank you.

 

Regards,

Daniel

1 ACCEPTED SOLUTION

Accepted Solutions
ziqex
Beginner

To get internet working I had to use alternative proxy settings. Cisco Umbrella was getting blocked by the ISP at Egypt. No issues now, with alternative squid proxy.

View solution in original post

3 REPLIES 3
Rob Ingram
VIP Mentor

@ziqex 

The ISP the non-working machine is connected to might possibly be blocking UDP/443, which might explain why you have no DTLS tunnel. Regardless even if DTLS is blocked, a TLS tunnel is established so the machine should still be able to access resources.

 

What version of the AnyConnect client is used?

What Operating System?

Does it make a difference if a different user logins to the non-working machine?

Do you use different connection profiles and group-policies with a different IP address pool?

 

Thank you for your message.

What version of the AnyConnect client is used? All machines have anyconnect version 4.9.01095

What Operating System? Win 10 1809

Do you use different connection profiles and group-policies with a different IP address pool? Single connection profile across all devices.

ziqex
Beginner

To get internet working I had to use alternative proxy settings. Cisco Umbrella was getting blocked by the ISP at Egypt. No issues now, with alternative squid proxy.

View solution in original post

Content for Community-Ad