Client AnyConnect and Sprint 4G

I have a couple of ASA5520, used to access remote vpn. We use the customer client Anyconnect AnyConnect 3.0.2052. Many users use Sprint and is beginneng for cellular modems capable of 4G.  Users cannot connect through 4G.  They get an error message indicating that the AnyConnect client could not verify changes to the transfer table.  However, using the same material and the same Sprint cellular modem (Novatel) software, they can connect using 3 G. I've seen this with Windows using Windows XP clients.

If anyone else has experienced this?

Doug,

There was a recent bug filed against this problem and should be already set in 3.0.4xxx

http://Tools.Cisco.com/support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCtq95503

But then again, not sure if problem would or would not continue for your pair of dongle/operator.

M,

Tags: Cisco Security

Similar Questions

  • Client AnyConnect and connections without client hang for two users

    ASA 5525, v.19 9.1 (5)

    AnyConnect client 3.1.02026

    I have two users who are unable to connect through the AC client or no client via the web portal. The use of the client, it will get stuck in a loop of "check updates". On the portal, the connection will proceed to point "Cisco Secure Desktop validated successfully... Success... Reloading... Please wait. "Then it crashes here.

    This problem occurs for the user, no matter which company laptop it connects to. A help desk technician can use his laptop computer and connect properly, but she could not connect on his own laptop computer or on another laptop. (Same for the other user.) So the question does not appear to be linked to his laptop or the installation of the CA. (Helpdesk reimage her machine early in the process of solving problems before they realized that the question seems to follow the user.)

    I've updated the hostscan - no change in the results file.  Client and clientless connections seem to work for all users. We are puzzled.  Suggestions, anyone?  Thank you!

    The LDAP protocol must be people - Active Directory server.  Chances are the one who manages the SAA should have access at least to look at Active Directory to look that up.  If they are not they need.

    Of course, I don't know a lot about what you use the devices, but if you use ISE, there should be a type of device MNT (monitoring and troubleshooting) - collecting newspapers and, hopefully, they are sent to a certain type of overall collection of syslog (splunk?) tool.

    Otherwise, there should be a device called a CAM (Clean Access Manager) who collects newspapers - which can also be spread to a global tool for syslog - but with cam, you can pull reports from the output in a file delimited by commas (.csv) and pass through them that way.

    -The thing that annoys me, is he gets to two users any computer, they try to connect to any network to which they connect, and other users can authenticate and access network on these same devices.

    -That is why it is rather confused.  Pretty much saying, there must be something with:

    -the pool of intellectual property that they get an IP of

    -their powers AD

    -user name

    -something in this sense, if the information provided is accurate.

  • Clients vpn AnyConnect and cisco using the same certificate

    Can use the same certificate on the ASA client Anyconnect and cisco vpn ikev1-2?

    John.

    The certificate is to identify a user/machine rather than the Protocol, then Yes, generally 'yes' you can use the same certificate for SSL/IKEv1/IKEv2 connections.

    What you need to take care of, it's that said certificate is fulliling Elements of the Protocol, for example implmentations IKEv2 is 'necessary' particular KU are defined and client-server-auth/auth EKU are defined on the certificates.

    M.

  • using the group name and password group in client anyconnect

    Hello. Is it possible to use the group name/password of the legacy in customer cisco anyconnect vpn client? I checked the AnyConnect Administrator's Guide ' VPN XML Reference"and found nothing on this subject.

    It's true.

    AnyConnect Secure Mobility Client (VPN Module) can be used to connect to both types of VPN remote access:

    1. full SSL VPN tunnel

    2 IKEv2 VPN IPsec.

    The legacy VPN client is used only with the old IKEv1 IPsec VPN and you cannot use this type of VPN client AnyConnect.

  • AnyConnect and SSL - VPN without client

    Are there problems in running Cisco AnyConnect and SSL - VPN without client side by side?

    I am currently looking into adding features for an ASA AnyConnect who currently set up to operate without SSL - VPN client. The system without client is not removed. I don't know how to set it up, I wonder if someone has already set up this or if there is no problem with this Setup?

    Hi Daniel

    It's a little complicated if you want a granular authentication and authorization, but it works.

    I'm running an ASA with IPSec, SSL Client and clientless SSL.

    Each of these virtual private networks with user/one-time-password name and certificate based authentic.

    The main challenge is to put in place its own structure of profile cards, connection profiles, group policies and dynamic access policies.

    Feel free to ask questions...

    Stephan

  • Problem installing Client AnyConnect Secure Mobility Client 3.0.3054

    Hi all

    This is my first post and I hope that someone can help me with my problem.
    I'm trying to install the Client AnyConnect Secure Mobility Client 3.0.3054 on my PC (Windows 7 Professional 32 - bit operating system) and
    I get the following errors.

    Cannot install the Client AnyConnect Secure Mobility Client 3.0.3054 with the Installer error: fatal error during installation. Cannot establish a VPN connection.
    The acsock service failed to start due to the following error: a device attached to the system does not work.
    Please notify.
    Thank you.

    Anna,

    I had the same problem. Have you found the solution in some way?

  • VPN Client AnyConnect 5 migration

    Dear community

    We are migrating the old Cisco VPN Client 5-Cisco AnyConnect.

    I have a couple of ASA-5510 9.1 (1) running the code with a license Base and in the current configuration, all remote users is in the VPN using standard methods of IKE/IPSec with their laptops (no split tunneling, nothing fancy). The VPN Client currently has a profile that is imported into each user's computer and has a pre-shared key that is stored, the solution works very well.

    Management has decided to go for the more AnyConnect version, rather than Apex which I believe meets all our requirements (preview here: http://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect40/feature/guide/anyconnect40features.html).

    I have three questions about the migration of Client AnyConnect VPN:

    (1) currently my ASA shows that AnyConnect is disabled (see attached screenshot to see the version). Can I upgrade the license on my ASA? If what comes with AnyConnect or do I need to order it separately?

    (2) is it possible to use the AnyConnect VPN Client VPN profile or should I create a new one?

    (3) can someone direct me to a guide for remote access VPN configuration using the rather than the old VPN Client AnyConnect client? Are there any caveats / pitfalls, I should be aware of?

    Thank you very much!

    Best regards
    Martin

    1 order the AnyConnect license you will get a PAK that you can redeem on the auto-serivce portal to get an activation key for your ASA. (You will need the serial number ASA as well.) This will allow you to "Essentials" AnyConnect (former name for more have together (which now includes Mobile), more or less) and allow you to run the command "anyconnect essentials".

    2. the old style IPsec profiles channel not again SSL VPN ones.

    3. There are many many of them out there. If you are new to it, you can find Pete Long message on the blog useful How - to's:

    http://www.petenetlive.com/kb/article/0000069.htm

  • Profile of the client Anyconnect ASDM - cannot change preferences

    Hello

    I operation set up vpn, my problem is that I am putting in place beginning anyconnect before logon. I navigate to the section of the profile client anyconnect in the vpn for remote access and create a profile xml file by clicking on the Add button. I can add a new profile, but as soon as I save the file I can no longer change it. Change is dimmed and if I double click on the file the asdm will return the error: "entry is not a well-formed XML file, schema compliant."

    I am running the following versions of the software:

    ASDM: 7.1 (5) 100

    AnyConnect: 3.1.05152

    ASA: 8.2 (3)<----asa hardware="" doesn't="" support="" running="" a="" newer="">

    I was not able to find any info on this particular problem, but maybe someone here can help?

    Hello Ryan,

    You have the same problem if you download AnyConnect 2.5 and perform the same task?

    Also, have you tried this operation from another machine and the old version of JAVA as 1.6?

    HTH.

  • Scripts &amp; profile Client Anyconnect

    Hello

    I configured a client anyconnect profile that's train to be ousted to end users. In this context, I have enabled scripting and transferred two scripts to the ASA (scripts_OnConnect_logon.bat & scripts_OnDisconnect_disconnect.vbs).

    If I connect the VPN client and download the client Anyconnect (new installation), everything works fine IE I get the profile and two scripts.

    If I then remove the scripts and the profile of the end user and you reconnect using the anyconnect client, I receive the profile, but not scripts.

    Can someone help with this problem?

    Kind regards

    Terry

    Currently, this is how it works by design. In case you want to push the script once again,

    Delete the file VPNManifest.dat of the Anyconnect folder and connect

    with the customer. First time I think that scripts will not be pushed. The second time, you'll see the script in the folder.

  • AnyConnect Client AnyConnect communication

    Hello

    We have users that are connected via AnyConnect that cannot communicate with each other using their software phones during extension call. They can communicate with each other when using 7 digits well. They use Split tunnel and we have unchecked network list under the internal policy of the Group and added the AnyConnect subnets. They can call for any other network but network AnyConnect. Is there a defect that does not allow AnyConnect AnyConnect communication?

    Also, I got their firewalls, turn to users and they still couldn't call or ping or tracert.

    Is it possible for a client AnyConnect ping on another AnyConnect client that is on the same subnet?

    Any suggestions?

    Thank you, Pat.

    You can remove the following because it is not necessary ("clear xlate):

    NAT (outside, outside) static source AP-SSLDHCP destination interface static any_vpn any_vpn

    It's OK that the OSPF is advertising and redistribute, so not know internal OSPF routers to send the 10.3.8.0 subnet to the ASA.

    And when I say roads that overlap, I mean when you have for example 10.3.8.0/21 pointing inward, you need to configure more specific routes (10.3.8.0/22) pointing outward. Otherwise, it's going to be routing inwards and the loop since the supposed to exist outside vpn pool. Routing should be good, because you can access internal networks, so I wouldn't change anything regarding the roads.

  • Client AnyConnect on Macbook Air

    Hello

    For the client Anyconnect on the Macbook Air, IPSEC) 1 can be used?, 2) split tunneling is disabled?

    Hello

    For Mac:

    AnyConnect

    Activation of the IPsec IKEv2 connections

    OPERATING SYSTEM

    AnyConnect 3.1 Predeploy the Package name

    Mac OS X

    AnyConnect-macosx-i386 - k9.dmg

    Mac OS X

    Table 8 Mac OS X support modules and the new features in 3.1 AnyConnect

    AnyConnect Module 3.1

    Feature

    Mac OS X 10.6, 10.7, 10.8
    x 86 (32-bit) or x 64 (64-bit)

    Comments from customers

    Yes

    VPN

    Kernel

    Yes

    IPv6

    Yes

    Suite-B
    (IPsec only)

    Yes

    Network Access Manager

    Kernel

    NO.

    IPv6

    NO.

    Suite-B

    NO.

    Posture & Hostscan

    Kernel

    Yes

    IPv6

    Yes

    Keystroke logger

    Yes x 86 (32-bit) only

    Web Security

    Yes

    DART

    Yes

    Cisco IPsec client

    The Cisco IPsec client only is not currently supported with MAC OSX 10.6, but the built-in MAC VPN client can be used. The current configuration of head IPsec used for current users of Cisco's VPN IPsec Client should work with this client.

    Split tunneling can be turned off (just choose tunnelall)

    ASA 8.x: allow the tunneling split for AnyConnect VPN Client on the example of Configuration of ASA

    Please check the following information:

    Deployment Client AnyConnect secure mobility

    Release notes for Cisco AnyConnect Secure Mobility, version 3.1 Client

    Thanx.

    Portu

    Please note any workstation that you be useful.


  • SSL VPN client anyconnect - login page does not appear

    I have an ASA5510 I am setting up for remote access using SSL VPN with the anyconnect client. I followed the guides of configuration on the Cisco's Web site and elsewhere on the internet without success configuration guides.

    When you go to https://(outsdie interface ip address), I get nothing, the browser never loads a page. Here are the commands I entered:

    WebVPN

    allow outside

    SVC disk0:/anyconnect-win-2.5.3046-k9.pkg 1 image

    SVC disk0:/anyconnect-macosx-powerpc-2.5.3046-k9.pkg 2 image

    Picture disk0:/anyconnect-macosx-i386-2.5.3046-k9.pkg 3 SVC

    enable SVC

    tunnel-group-list activate

    in-house VRx-WebVPN group policy

    Group Policy attributes VRx-WebVPN

    Server DNS 192.168.100.11 value

    VPN-tunnel-Protocol svc

    Split-tunnel-policy tunnelspecified

    Split-tunnel-network-list value split

    VRX.NET value by default-field

    WebVPN

    SVC Dungeon-Installer installed

    time to generate a new key of SVC 30

    SVC generate a new method ssl key

    SVC request no svc default

    remote type tunnel-group VRx-WebVPN access

    attributes global-tunnel-group VRx-WebVPN

    address value vpn_pool pool

    authentication-server-group VRxAD

    Group Policy - by default-VRx-WebVPN

    tunnel-group VRx-WebVPN webvpn-attributes

    enable VRx-WebVPN group-alias

    We never seen this before - any ideas or what would be useful in troubleshooting this?

    Thank you in advance!

    Dave

    Hello David,.

    Hmm... I'll do a quick true lab setup for this.

    Edit: My own work without problem, it be something else on the configuration that is not allowing you to get the anyconnect portal.

    I used the same image anyconnect and the same ASA image.

    Julio

  • I visited a new client today and discovered that they are running a version of Microsoft Windows XP, I had never heard of, Black complete edition of Windows XP.

    I visited a new client today and discovered that they are running a version of Microsoft Windows XP, I had never heard of, Black complete edition of Windows XP.  What is black ultimate and what are its characteristics? Is this a legitimate copy of Windows?

    Everything I read is not a legitimate copy. It's a pirated copy. I don't know about the features.

    Jim

  • What is a DHCP client address and what is an ISP?

    Try to connect Tivo w / a wireless connector for my computer instead of using the phone line. TiVo's request for a DHCP client address and Pack International customer

    Hello

    The DHCP Dynamic Host Configuration Protocol () is a protocol for network configuration for hosts on networks IP (Internet Protocol). Computers that are connected to IP networks must be configured before it can communicate with other hosts. The essential information needed are an IP address and a default route and the routing prefix. DHCP eliminates the manual task by a network administrator. It offers a central database of devices that are connected to the network and eliminates duplicate resource assignments.
    An ISP (ISP) is an organization that provides access to the Internet.

    See the following link:
    Windows Vista cannot obtain an IP address from certain routers or some non-Microsoft DHCP servers
    http://support.Microsoft.com/kb/928233

    Note: this section, method, or task contains steps that tell you how to modify the registry. However, serious problems can occur if you modify the registry incorrectly. Therefore, make sure that you proceed with caution. For added protection, back up the registry before you edit it. Then you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click the following article: http://windows.microsoft.com/en-US/windows-vista/Back-up-the-registry

  • Cisco VPN client v5 and integration Active Directory 2008

    Hi all

    I need to know if I can integrate Single Sign On for my Cisco VPN Client v.5 with my Active Directory which run on windows 2008

    THX in advance

    No, unfortunately, Single Sign On is only supported on Clientless SSL VPN (WebVPN), not on the IPSec VPN Client AnyConnect VPN Client.

Maybe you are looking for

  • What size 9.3.4 for iPhone iOS?

    I have a very limited data plan. What is the size of the download for. 9.3.4 IOS for the iPhone? I just iOS 9.3.2 with an iPad Mini 2. Thank you V-

  • Satellite C660 - 1 DG-Toshiba Media Creator recovery fails creation DVD 2

    I spend a few hours in an attempt to create the floppies of recovery for my laptop (Satellite C660 - 1 DG) It fails on the second DVD at halfway. It just hangs. CTRL-ALT-DEL is no longer a cold start will have to start the thing. I tried several DVD

  • Important: Solution workaround to fall immediately SkypeOut call in Skype 4.0

    As I spent about 8 hours of my life on this question with the help of Skype you guys give a work around if you are not able to place SkypeOut calls from your Android device. This problem concerns new facilities of Skype 4.0 for Android. On my Samsung

  • QuickLook

    The Quicklook function no longer from time to time on my iMac since I've upgraded to El Capitan. No idea why?

  • Laptop will not turn on or charge

    My laptop only turns on when I press the power button. It will be not too to recharge the battery. I've had this phone for almost 2 years now, a this is the first time I have had this problem. I tried removing the battery and pressing the power for 3