cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
398
Views
0
Helpful
1
Replies

Update of VPN Licences caused Certficate errors

We have a pair of ASA5512's  with active failover.  recently our Anyconnect VPN licence expired, we have received the new licence and applied.  But we now have an error when connecting via client where it says incorrect certificate and seems to be trying to use a self signed cert when it should be using the correct anyconnect.Basildon certificate which was created specifically.  I have gone through all the cert management and checked trust point and cannot see why this is happening.  Both devices have been reset, are being seen correctly as active/passive. Reboot/flip from passive to active has not resolved.

 

Doing a search shows similar issues after update of adsm/asa software, but all we have done is apply new licences, surely this should not break the system.   Any assistance gratefully accepted.

1 Reply 1

Check that the correct trust point is mapped to the right interface

example:
#sh run ssl
#ssl trust-point STAR_CERT_COM OUT