08-27-2013 10:42 AM - edited 02-21-2020 07:06 PM
Hi,
I f I need to modify a pool for vpn anyconnect.
IS all users that are currently connected when I push the modification on the ASA will continue to work or they will be disconnected.
Thanks,
08-27-2013 09:31 PM
Existing active sessions should not be affected by modifying a pool.
If you modify something like application of IPSec to an interface, that will cause problems.
09-03-2013 08:40 AM
I did the change but all existing session were disconnect.
So Marvin you was wrong.
Thanks,
09-03-2013 10:31 AM
My first reaction was similar to Marvin that if you modify a pool that it should not affect existing sessions. But then I realized that we should be a bit more cautious in answering and should determine the nature of the modification that you were planning to do. If the modification was to delete the existing addresses in the pool and to define the pool with a different address range, then I can see how any existing sessions would be dropped if their address was no longer defined as a client address on the VPN device.
HTH
Rick
09-03-2013 11:33 AM
True. We should always ask how the change was being made. I would have thought adding to a pool would not cause existing connections to have a problem, but replacing the addresses and possibly make NAT changes and route changes associated with it could cause issues.
09-03-2013 07:02 PM
Yes, Rick and Richard are right to clarify and qualify the answer. We should always explicitly state our assumptions.
My apologies for not doing so.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide