cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
647
Views
0
Helpful
2
Replies

VPN fails in Anyconnect IKEV2 remote access with local authentication

Rajesh11735
Level 1
Level 1

Hey guys, 

I am trying to setup a Anyconnect IKEV2 VPN by following the below link. I am attaching the debug log and the router config (includes tested config changes). I am using the router's self signed cert and also changed the BypassDownloader option to "true". Used smart defaults as well as specific IKEV2 proposals but didnt work. I am getting the error: The VPN Client failed to establish a connection. Please check and suggest a solution.

Thanks in advance!


https://www.cisco.com/c/en/us/support/docs/security/flexvpn/200555-FlexVPN-AnyConnect-IKEv2-Remote-Access.html

2 Replies 2

@Rajesh11735 from the link you provided.....

Authenticating and Authorizating users using the Local Database

Note: In order to authenticate users against the local database on the router, EAP needs to be used. However, in order to use EAP, the local authentication method has to be rsa-sig, so the router needs a proper certificate installed on it, and it can't be a self-signed certificate.

Rajesh11735
Level 1
Level 1

Thanks for the quick response, Rob! I will check on this and get back here with the results.