I've been working remote for a couple years now with no significant issues. Every morning, I connect to Cisco Anyconnect Secure Mobility Client via the use of an authentication card (I just punch in my date of birth and receive a custom password). When I go to type in the password given from the authentication card, the login simply fails now. The IT people at my work said that they don't deal with any Cisco issues, that it's beyond their control. I've restarted my laptop several times and even disabled my firewall (Windows Defender). I use Windows 10. I have absolutely no idea of what else to do. Please, are there any heroes here? I'm pretty upset that I can't get any work done and that there's zero hope of solving my issue.
From within the AnyConnect application you can click the "diagnostics" button to generate logs to aid troubleshoot, please do this and see if these indicate where the issue is. You should send these to whoever supports your VPN.
@Rob Ingram Thanks for the reply. Yes, I am just a peon and not an admin of the Remote Access VPN solution. I will consider posting a screenshot or 2. But I did likely identify the nature of the problem. I notice that when I go to connect, there is a message that flashes "No valid certificates available for authentication". Here is a copy/paste of the message log:
12:57:59 PM Ready to connect.
Basically, when I click that initial "Connect" button, it says "VPN: contacting [Redacted]" then "VPN: No valid certificates available for authentication" and then the username/password field window opens for me to login. Please note that the username field is always default populated by what my username is, so I only ever have to type in my password (smart card).
What exactly does this mean? Did my authentication smart card expire, etc.? What could have changed over the weekend that is now making my life so difficult?
May I have more clarification about what is meant by a 'certificate'? Is it a digital authorization of my user, or something like that? I'm still waiting for IT to look at the JIRA ticket that a coworker put in on my behalf, but hopefully someone at my work actually knows something about VPN problems like this.
As part of its journey to simplification, Cisco has been working to create a simpler network management platform experience to help customers easily access and navigate its platforms to manage all Cisco networking products from one place. Featuring cloud-driven automation, rich network insights, and innovation through its partner ecosystem, Cisco Networking Cloud will accelerate the delivery of unified experiences and drive measurable business outcomes.
Cisco (NASDAQ: CSCO) is the worldwide technology leader that securely connects everything to make anything possible. Our purpose is to power an inclusive future for all by helping our customers reimagine their applications, power hybrid work, secure their enterprise, transform their infrastructure, and meet their sustainability goals. Discover more on The Newsroom and follow us on Twitter at @Cisco.
Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. A listing of Cisco's trademarks can be found at www.cisco.com/go/trademarks. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company.
I can no longer connect to my Xfinity Router and use my Cisco AnyConnect for work. Sometimes it allows me to connect as soon as I reset the router but after that I can't connect again. I can connect fine with my verizon hotspot. Please Help
I just started experiencing the exact same issue this week. I think the xFi stuff was pushed out over the weekend, since that's when I first noticed it, and I wasn't having any issues with my VPN last week working from home.
However starting yesterday, my Cisco AnyConnect VPN would disconnect randomly every 1-2hrs. Once it did, I couldn't reconnect. Restarting the PC did nothing, and at that point I couldn't even ping the VPN server, not even from another PC on my network, so something (xFi) presumably was blocking it from the time it would get disconnected. Only thing that would fix it was restarting the modem, then immediately connecting until it happened again.
Nothing actually shows up in the logs for the modem/xFi, but so far disabling xFi seems to have resolved it. 4 hours straight today without issue. So yes, +1 to EG, for now it seems to have resolved it.
Thanks EG for the suggestion. Ever since I got XFi advanced security enabled, I was not able to connect to my work network. I wasn't able to find anything in the log. I have alternate network than xfinity and I was able to login to anyconnect with that network. Poor execution by xfinity on this part. Not sure how many other services are affected by xfi advanced security. Anyways, I have disabled it for now.
A VPN is a secured private network connection built on top of publicly accessible infrastructure. The Campus VPN service provides an alternative to using the proxy server for remote access to the UCLA Library and other campus resources. Campus VPN access is restricted to registered students and university employees with an active staff/faculty appointment.
You will be required to enroll in and authorize your login attempts using Multi-Factor Authentication (MFA) to connect to the Campus VPN. For additional information please see our help article here: Authenticating Using Multi-Factor Authentication on the Campus VPN.
What happens when you go to the vpn login screen, possition the currsor in the username field, switch to KeePass, manualy select an entry, right click, select Auto-Type?
Is the username and password beeing typed?
@fly-fast. I am a longtime user and ran into the strange issue with the Cisco AnyConnect VPN window. There is something about the AnyConnect login window that moves the cursor to the PW field if you are using Auto-Type key like:
Very handsome solution.
I wonder how (and especially why) this works when my pw database has to be accessed via VPN (this actually is my usecase). I tried it and KeePass is able to enter my VPN pw when using the key sequence above. While I am NOT connected to the databse.
Why? Or how?
If you are using File > Open to connect to the database, KeePass is able to supply connection credentials. These are saved unencrypted in the KeePass config file.
See the config file section in Help:
I have a work laptop with Cisco Anyconnect VPN software installed and it can connect to work just fine if I use my old N600 wifi router. However, my XR500 is blocking something and doesn't allow the laptop to connect. I grabbed wireshark captures and can't seem to figure out why the newer XR500 won't work.
This is especially a concern for me, since I purchased this specifically for the NetDuma OS. I was impressed by the LTT coverage of it, and specifically stepped up to this model because of it.
That being said, it's now a liablity since I can't throw an alternative firmware up onto the unit.
Sorry, this turned a bit ranty, but I'm having flashbacks here to the Portal Router, which I backed, and wasn't supported with decent firmware upgrades. When it worked, it was great, but I bought NetGear because I expected that issues like this wouldn't happen, and if they did, they would be resolved in a timely manner.
I agree that this is a problem but in my experience most of our customers use Hybrid-VPN instead of a VPN on their devices. The advantages to this are obvious, especially when it comes to gaming performance. Not to mention, Hybrid-VPN works with consoles.
As a gaming focused product, our primary concern is with Hybrid-VPN rather than the compability of desktop based business VPNs. That said, as you know, we are aware of this problem and we will be working to fix it.
And you do. There is no issue with the Macintosh version of the AnyConnect software. I've seen notes where it did have an issue, and it was patched/fixed. Someone just didn't test with the Windows version, I suspect.
Has anyone had any success to get Cisco AnyConnect VPN start before login on to allow us to deal with the scenario of needing to ship a Mac to a user who is working remotely and who has never logged into the laptop previously
I guess you could use something like DEPNotify and a script in a Enrollment Customization Configuration to prompt the user for name and password and then call the VPN binary with them to establish a VPN connection
Resurrecting this thread. Has anyone found a way to get this to work? Ideally, I would like the AnyConnect VPN gui window to popup at the login screen on a Mac. Allowing the user the ability to establish a VPN connection before logging into the Mac. @c.kay referenced that we might be able to use a launch daemon to do this workflow, however, I have no experience with creating launch daemons. Thoughts?
A custom login window plug-in will need to be created to interface with the above login process. No such dialog controls exist. Cisco should be up on point to create this interface for MacOS - they have the dev team and resources.
Jamf's purpose is to simplify work by helping organizations manage and secure an Apple experience that end users love and organizations trust. Jamf is the only company in the world that provides a complete management and security solution for an Apple-first environment that is enterprise secure, consumer simple and protects personal privacy. Learn about Jamf.
c80f0f1006