AnyConnect and DAP does not not on ASA 8.3.2?

Hello

I encountered a problem using the AnyConnect client after upgrade ASA5510 to 8.3.2 (from 8.3.1). After entering the username and password in the browser, the error message "connection refused. Your environment does not meet the conditions of access defined by your administrator. "appears.

Some of the results:

1 connect to the ASA 8.3.1 and 8.2.3 works very well with dynamic access policies (RAP) defined
2 connection to ASA 8.3.2 fails when political DAP are defined
3. connect to ASA 8.3.2 works well when no DAP (except DfltAccessPolicy) policy is defined
4. error in the syslog file messages are "% ASA-3-734004: DAP: processing error: Code 2358" and "% ASA-3-734004: DAP: processing error: Code 3626".
5 cisco Secure Desktop is enabled, but not conduct audits host Scan.

Versions of the software in use:

-Secure desktop cisco 3.5.1077
-AnyConnect 2.5.0217
-Used for testing clients are running Windows XP and Vista

It doesn't seem to matter what the DAP policy contains, just that it exists. I tried to add a new policy to a single "Application = IPsec' (which he must jump and move to DfltAccessPolicy) and the other with a single"Application = AnyConnect"(that he must match and be allowed access). IPsec clients corresponding to the first and continue as usual, but the AnyConnect client stops as long as there is at least a defined strategy. The problem exists even if the DfltAccessPolicy is set to "continue".

I see this problem on two different ASA5510s. Is this a known issue?

More than likely you are running in the CSCth56065bug.  If you open a case with TAC, we can provide you the 8.3.2.1 Provisional which includes the fix.

Tags: Cisco Security

Similar Questions

Maybe you are looking for