03-01-2013 01:08 AM - edited 02-21-2020 06:44 PM
hi,
I have configured anyconnect for users to connect using web interface.
It works fine ut sometimes it won't let you connect for sometime, about 15 minutes. after waiting that time you can connect.
The message is the same as if login credentials were wrong.
Is there any parameter I do have to configure?
thank you very much.
Kind regards.
03-07-2013 02:11 PM
Hi David
my best guess is that this is because sometimes the client does not disconnect cleanly, causing the ASA to consider it still connected. Consequently, it refuses the new connection because there are no more free licenses, or because the number of simultaneous connections for this user has reached the maximum (by default the value for vpn-simultaneous-connections is 3 but this can be changed in the group-policy or by the AAA server).
To confirm, check "show vpn-sessiondb" and "show vpn-sessiondb anyconnect" on the ASA (or "show vpn-sessiondb svc" in older ASA versions) immediately when unable to connect.
hth
Herbert
03-19-2013 10:11 AM
Hi Herbert,
Thank you very much for your answer.
I will be waiting for the problem to happend again, and then try to see how many sessions are opened at the moment.
I will keep you informed.
Thank you very much.
Kind Regards.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide