Solved

My iPhone 5s (iOS 8.0.2), is NOT connecting to VPN, via Cisco Anyconnect.

Posted on 2014-10-19
16
253 Views
Last Modified: 2014-12-26
Hello,

My new iPhone 5s (iOS 8.0.2), is NOT connecting to VPN, via Cisco Anyconnect.

I have downloaded from App Store and installed successfully Cisco "VPN Anyconnect Version 3.0.12119" on my new iPhone 5s, which operates on iOS v. 8.0.2.

Before this, I bought a specific license for Mobile from Cisco Corporation.

So the Running Licenses on ASA are:
License:      Base
Max Physical Interfaces:      8
VLANs:      3, DMZ Rest
Dual ISPs:      Disabled
Trunk Ports:      0
Failover:      Disabled
Inside Hosts:      10
VPN DES Encryption:      Enabled
VPN 3DES and AES Encryption: Enabled
VPN Peers:      10
SSL VPN Peers:      2
Shared SSL VPN licensing:      Disabled
AnyConnect Mobile:      Enabled
Linksys VPN Phone:      Disabled
AnyConnect Essentials:      Enabled
Advanced Endpoint Assessment: Disabled
UC Proxy Sessions:      2
UC Phone Proxy Sessions:      2
Botnet Traffic Filter:      Disabled

The installation was successful and the connection was achieved, as you can see on a iPhone screenshot image, Fig. 1.

However, I notice that every time that I log in to AnyConnect, during the authentication process it asks me for Username & Password. So far so good. I then type in these data and subsequently responds "normally connected" (Fig. 1). Good again! Unfortunately, then the internet is completely cut-off in all programmes and it does NOT connect at all to internet, neither to my LAN nor to the WAN .....  (Please see Gig. 2). However, the AnyConnect interface, still indicates "Connected", WITHOUT in fact any connection......

Is there any idea from someone experienced on this topic how about I could work around this problem and be able to successfully connect, as it seems a puzzle to me?

Thank you,

Costas.
Cisco-Anyconnect-IMG-0006.PNG
Cisco-Anyconnect-IMG-0007.PNG
0
Comment
Question by:Dr.Costas Sachpazis
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 8
  • 6
16 Comments
 
LVL 26

Expert Comment

by:akahan
ID: 40390734
start by seeing if it is a DNS problem by trying to connect to the numeric IP of a website rather than the canonical name.

For example, if you connect to http://74.125.239.145  do you get Google?

If you do, then you are connected via the VPN, but you may have to work with the settings related to DNS.
0
 

Author Comment

by:Dr.Costas Sachpazis
ID: 40390768
Thank you akahan,

On my iPhone, while being on Anyconnect VPN connection, when I try to connect to www.google.com it does NOT connect.

However, when I try to use in the browser http://74.125.239.145 to connect, then I DO get connected to Google!

Any further assistance?

Thank you.
0
 

Author Comment

by:Dr.Costas Sachpazis
ID: 40390769
....but still I cannot connect to a LAN IP, for example to a camera set on 192.168.1.165.....
0
What, When and Where - Security Threats from Q1

Join Corey Nachreiner, CTO, and Marc Laliberte, Information Security Threat Analyst, on July 26th as they explore their key findings from the first quarter of 2017.

 
LVL 26

Expert Comment

by:akahan
ID: 40390772
Can you show screenshots of your settings pages on the iPhone for the iPhone Cisco anyconnect?  (Block out sensitive information, of course.)
0
 

Author Comment

by:Dr.Costas Sachpazis
ID: 40390779
Sure, just a minute...
0
 
LVL 26

Expert Comment

by:akahan
ID: 40390784
You cannot connect locally with the VPN turned on, because the VPN software on the iPhone is set to send EVERYTHING out to the VPN server.
0
 
LVL 26

Expert Comment

by:akahan
ID: 40390793
Waitaminnit.

Are you connecting to your OWN Cisco VPN server, on your own network?  Or are you at home, trying to connect to a server at an office network somewhere?
0
 

Author Comment

by:Dr.Costas Sachpazis
ID: 40390818
I am just uploading the Cisco Anyconnect images, as you asked me for. 13 images altogether in a chronological order... You can see that with IP I can connect but with domain name not...

I try to connect to my LAN at office from home, by using Cisco anyconnect VPN.

The strange thing is that, DOING EXACTLY THE SAME PROCEDURE using my Samsung Tablet (but with Android O.S) and using Anyconnect on my Samsung Tablet, the Tabletsconnects perfectrly to my LAN at office without any problem...

However, the iPhone 5s (iOS 8.0.2) using the same procedure and the same software it DOES NOT connect...

Any clue?
Cisco-Anyconnect-IMG-0008.PNG
Cisco-Anyconnect-IMG-0009.PNG
Cisco-Anyconnect-IMG-0011.PNG
Cisco-Anyconnect-IMG-0012.PNG
Cisco-Anyconnect-IMG-0013.PNG
Cisco-Anyconnect-IMG-0014.PNG
Cisco-Anyconnect-IMG-0015.PNG
Cisco-Anyconnect-IMG-0016.PNG
Cisco-Anyconnect-IMG-0017.PNG
Cisco-Anyconnect-IMG-0018.PNG
Cisco-Anyconnect-IMG-0019.PNG
Cisco-Anyconnect-IMG-0020.PNG
Cisco-Anyconnect-IMG-0021.PNG
0
 
LVL 26

Expert Comment

by:akahan
ID: 40390835
Are you sure that the Cisco server at your office supports iPhone?  Cisco IOS VPN servers and the Cisco 3000 series concentrators, for example, do not, while the Cisco ASA 5500 Security Appliances and PIX Firewalls do.
0
 

Author Comment

by:Dr.Costas Sachpazis
ID: 40390838
As I told you I bought a license from Cisco.

My firewall is Cisco ASA 5505.

Please have a look again:

Before this, I bought a specific license for Mobile from Cisco Corporation.

So the Running Licenses on ASA are:

•License:      Base
 Max Physical Interfaces:      8
 VLANs:      3, DMZ Rest
 Dual ISPs:      Disabled
 Trunk Ports:      0
 Failover:      Disabled
 Inside Hosts:      10
 VPN DES Encryption:      Enabled
 VPN 3DES and AES Encryption: Enabled
 VPN Peers:      10
 SSL VPN Peers:      2
 Shared SSL VPN licensing:      Disabled
 AnyConnect Mobile:      Enabled
 Linksys VPN Phone:      Disabled
 AnyConnect Essentials:      Enabled
 Advanced Endpoint Assessment: Disabled
 UC Proxy Sessions:      2
 UC Phone Proxy Sessions:      2
 Botnet Traffic Filter:      Disabled
0
 

Author Comment

by:Dr.Costas Sachpazis
ID: 40390841
....My Android (Samsung) Tablet, connects without any problem, thouhg.....
0
 
LVL 26

Expert Comment

by:akahan
ID: 40390927
I understand both that you bought a license from Cisco and that your Android tablet connects fine.
The issue is whether your Cisco server is able to work with the iPHone.  
The ASA 5505 should be fine, but the problem is with the configuration on the server, not the iPhone.

Do you have the 5505 running the latest software?  Here's a link to Cisco's configuration guide for this:

http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/100936-asa8x-split-tunnel-anyconnect-config.html
0
 

Accepted Solution

by:
Dr.Costas Sachpazis earned 0 total points
ID: 40400107
Hello again,

Unfortunately, there is no solution yet, because as I was told by a Cisco expert, the problem comes from the iOS 8 operating system, and as he advised me, I should wait until Apple gives out an update to fix this bug....

I am sorry, because I cannot connect to my LAN, using iPhone 5s running iOS 8.1 and Anyconnect ....

I am desperately looking for a God blessed solution...

Costas.
0
 

Author Comment

by:Dr.Costas Sachpazis
ID: 40511866
Unfortunately, nobody was able to solve this problem so far......
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The case of the missing phone talks about the way a small electronic gadget (the mobile phone) has penetrated into our lives and has made us addicted to it.
This article outlines the struggles that Macs encounter in Windows-dominated workplace environments – and what Mac users can do to improve their network connectivity and remain productive.
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…

630 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question