Solved

Problems with AnyConnect 2.5.2006 / ASA 8.3 and some pc's

Posted on 2010-11-26
5
2,641 Views
Last Modified: 2012-12-17
I have upgraded my firewalls to 8.3 and subsequently upgraded my AnyConnect to 2.5.2xxx
 
All seems good, except some PCs can't use the AnyConnect anymore.
 
The client will connect, and gets an ip address, but then drops the connection immediately, showing messages:
 
"The VPN client driver has encountered an error"
 
"AnyConnect was not able to establish a connection to the specified gateway, Please try connecting again"
 
and then at the bottom of the AC window:
 
"No trusted network detection rules defined. Contact your network admin"
 
 
But I have created a profile with trusted network rules set to Connect. I can see the profile is downloaded when the client attempts connection, and is stored in app support, and AC finds it during the connection but then the event manager logs indicate it's not being used, "No profile available for host xxxxxxxxx.com", that some default profile is being used, which has "TrustedNetworkPolicy:disconnect" set.
 
Any ideas?
 
I've also found out that the IPsec client won't work on this pc either, says the virtual adapter was not recognised by the operating system and fails to enable

Thanks for reading
0
Comment
Question by:cmrayer
  • 2
  • 2
5 Comments
 
LVL 33

Expert Comment

by:MikeKane
Comment Utility
The Trusted network detection (TND) is a policy that helps determine when a user is not on the corporate network.     Do you use this feature?

From the error, it sounds like you enabled the feature, but didn't define any rules for the TND.      Is that correct?    You may want to test just turning it off.

http://www.cisco.com/en/US/docs/security/vpn_client/anyconnect/anyconnect25/administration/guide/ac03features.html#wp1059922
0
 
LVL 4

Accepted Solution

by:
cmrayer earned 0 total points
Comment Utility
It looks like the problem was the age old "Windows XP Home doesn't like Cisco VPN" one as most other machines are fine without any profiles or alterations.  As 2.4 was the last Windows XP supported version then I guess we have to live with it as the ASA does not support one client for XP and another for Vista/7

Anyone any ideas on this?
0
 
LVL 33

Expert Comment

by:MikeKane
Comment Utility
If it does, I've never seen it setup.   I suppose that would be a TAC call to see if its supported.    I've only ever done the textbook setup for different OS (win, mac, linux)
0
 
LVL 4

Author Closing Comment

by:cmrayer
Comment Utility
Not a solution but simply a reality - problem still exists but as it is only for a few users with older machines we have told them that they just need to upgrade them...
0
 
LVL 1

Expert Comment

by:damelahn
Comment Utility
Here is the solution:  Open AD Users and Computers, Open user account in question, Select the Account tab, scroll down in the Account options window, check the box labeled "Do not require kerberos preauthentication", click OK.
0

Featured Post

Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

Join & Write a Comment

Suggested Solutions

Overview Often, we set up VPN appliances where the connected clients are on a separate subnet and the company will have alternate internet connections and do not use this particular device as the gateway for certain servers or clients. In this case…
This is an article about my experiences with remote access to my clients (so that I may serve them) and eventually to my home office system via Radmin Remote Control. I have been using remote access for over 10 years and have been improving my metho…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now