Solved

ASA 5540 WebVPN Issue

Posted on 2009-03-30
1
1,336 Views
Last Modified: 2012-05-06
Howdy, long time poster first time reader.......

Enough of the jokes. I have an open request with Cisco but how they didnt' see this is beyond me. For our WebVPN SSL, we are getting authentication failures. I've looked through the debugs and the only difference between a successful login and not is the statement "WebVPN: error creating WebVPN session!"

The LDAP authentication is successful.

Doing a show ver I get the following:

Maximum Physical Interfaces  : Unlimited
Maximum VLANs                : 200      
Inside Hosts                 : Unlimited
Failover                     : Active/Active
VPN-DES                      : Enabled  
VPN-3DES-AES                 : Enabled  
Security Contexts            : 2        
GTP/GPRS                     : Disabled  
VPN Peers                    : 5000      
WebVPN Peers                 : 2        
AnyConnect for Mobile        : Disabled  
AnyConnect for Linksys phone : Disabled  
Advanced Endpoint Assessment : Disabled  
UC Proxy Sessions            : 2        


To test my theory that the issue is WebVPN Peers: 2 I logged my successful session out and had another user who had just failed log in. He was able to connect. So I looked through ASDM and found the area where it limits the number of sessions to 2. I tried to change it and it states that I'm only allowed a max of 1 to 2 sessions. How do I change this? Is this a license issue?

Thanks for your time,

-JD-
0
Comment
Question by:trineit
1 Comment
 
LVL 43

Accepted Solution

by:
JFrederick29 earned 50 total points
ID: 24018662
Yes, this is a license issue.  You need to purchase additional WebVPN licenses.  By default, the ASA comes with 2.
0

Featured Post

Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

Join & Write a Comment

This article will cover setting up redundant ISPs for outbound connectivity on an ASA 5510 (although the same should work on the 5520s and up as well).  It’s important to note that this covers outbound connectivity only.  The ASA does not have built…
Let’s list some of the technologies that enable smooth teleworking. 
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now