04-28-2020 01:19 PM
Have report from user and others that while on VPN(AnyConnect v4.6) the enduser loses as much as 5 minutes during connection. Checked the SYNC of the source devices with ASA and the NTP server. Complete numerous NTP commands on the routers and ASA no problems with SYNC. Yet users have been losing time. Can you give me a idea where would be the next lo ation to chack or change to resolve issue.
Have enclosed configuration of webvpn on ASA 5585-X. At most we have an average of 60 clients on at any given time.
Cleints use digital certificate (CAC) for login procedures.
Solved! Go to Solution.
04-29-2020 04:18 PM
HI
Do local users have the problem?
You say before VPN connection use Google, then once connected use your core router, how is this done? is it in the profile that is downloaded?
can the VPN users ping the core router ok?
also you can setup a capture on the ASA see if there is traffic
Capture ntp-traffic interface <interface that core router is connected to> match UDP host < core router IP> eq 123 < Anyconnect IP address pool>
then do a show capture ntp-traffic
04-29-2020 12:09 AM
But where is the user getting its time from the Router, ASA, or is the time source on the Internet?
do you have split tunnel, or is all traffic for the Internet go thru the VPN, that might be an area that needs checking
04-29-2020 06:48 AM
Before the user gets on the VPN they are getting the NTP from Google. Once the get on the VPN they are getting NTP from our core Router. Which the ASA gets it's timing from the Core router. We are not using split tunneling, due to security reasons. All of our traffic is required to go through the VPN. Here is the ntp information from our ASA
04-29-2020 04:18 PM
HI
Do local users have the problem?
You say before VPN connection use Google, then once connected use your core router, how is this done? is it in the profile that is downloaded?
can the VPN users ping the core router ok?
also you can setup a capture on the ASA see if there is traffic
Capture ntp-traffic interface <interface that core router is connected to> match UDP host < core router IP> eq 123 < Anyconnect IP address pool>
then do a show capture ntp-traffic
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide