Solved

ASA 5540 WebVPN Issue

Posted on 2009-03-30
1
1,366 Views
Last Modified: 2012-05-06
Howdy, long time poster first time reader.......

Enough of the jokes. I have an open request with Cisco but how they didnt' see this is beyond me. For our WebVPN SSL, we are getting authentication failures. I've looked through the debugs and the only difference between a successful login and not is the statement "WebVPN: error creating WebVPN session!"

The LDAP authentication is successful.

Doing a show ver I get the following:

Maximum Physical Interfaces  : Unlimited
Maximum VLANs                : 200      
Inside Hosts                 : Unlimited
Failover                     : Active/Active
VPN-DES                      : Enabled  
VPN-3DES-AES                 : Enabled  
Security Contexts            : 2        
GTP/GPRS                     : Disabled  
VPN Peers                    : 5000      
WebVPN Peers                 : 2        
AnyConnect for Mobile        : Disabled  
AnyConnect for Linksys phone : Disabled  
Advanced Endpoint Assessment : Disabled  
UC Proxy Sessions            : 2        


To test my theory that the issue is WebVPN Peers: 2 I logged my successful session out and had another user who had just failed log in. He was able to connect. So I looked through ASDM and found the area where it limits the number of sessions to 2. I tried to change it and it states that I'm only allowed a max of 1 to 2 sessions. How do I change this? Is this a license issue?

Thanks for your time,

-JD-
0
Comment
Question by:trineit
1 Comment
 
LVL 43

Accepted Solution

by:
JFrederick29 earned 50 total points
ID: 24018662
Yes, this is a license issue.  You need to purchase additional WebVPN licenses.  By default, the ASA comes with 2.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Download Logs File from Cisco Switch 1 47
Stuck in INIT/DROTHER 2 26
Load Balancing 3 29
Interface traffic report in FortiAnalyzer 1000D 4 9
Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question