AnyConnect VPN Windows Store Client constantly disconnecting

Solved
from_afar
Building a reputation

AnyConnect VPN Windows Store Client constantly disconnecting

I'm trying to get my users set up with Anyconnect so they can VPN from home. I started by using the exe that can be downloaded from the dashboard, but discovered the Windows Store Version allows install from Company Portal via Intune which is much easier. However, I've run in to an issue with each of the several Win 10 (fully patched) machines I've tried/installed it on. The connection opens and seems to work for a few minutes but consistently drops after no more than 5 minutes. The even logs all look the same:

 

Jan 29 14:24:38 loc1-exmpl1-lt-vpn AnyConnect VPN AnyConnect VPN client connected local_ip: 192.168.112.168, user_id: homer.simpson@example.com, remote_ip: 12.34.56.78
Jan 29 14:24:33 loc1-exmpl1-lt-vpn AnyConnect VPN AnyConnect VPN client disconnected local_ip: 192.168.112.168, user_id: homer.simpson@example.com, remote_ip: 12.34.56.78
Jan 29 14:18:23 loc1-exmpl1-lt-vpn AnyConnect VPN AnyConnect VPN client connected local_ip: 192.168.112.50, user_id: homer.simpson@example.com, remote_ip: 12.34.56.78
Jan 29 14:18:18 loc1-exmpl1-lt-vpn AnyConnect VPN AnyConnect VPN client disconnected local_ip: 192.168.112.50, user_id: homer.simpson@example.com, remote_ip: 12.34.56.78
Jan 29 13:16:05 loc1-exmpl1-lt-vpn AnyConnect VPN AnyConnect VPN client connected local_ip: 192.168.112.13, user_id: homer.simpson@example.com, remote_ip: 12.34.56.78
Jan 29 13:16:03 loc1-exmpl1-lt-vpn AnyConnect VPN AnyConnect VPN client disconnected local_ip: 192.168.112.13, user_id: homer.simpson@example.com, remote_ip: 12.34.56.78
Jan 29 12:57:21 loc1-exmpl1-lt-vpn AnyConnect VPN AnyConnect VPN client connected local_ip: 192.168.112.168, user_id: homer.simpson@example.com, remote_ip: 12.34.56.78
Jan 29 12:57:19 loc1-exmpl1-lt-vpn AnyConnect VPN AnyConnect VPN client disconnected local_ip: 192.168.112.168, user_id: homer.simpson@example.com, remote_ip: 12.34.56.78
Jan 29 12:57:00 loc1-exmpl1-lt-vpn AnyConnect VPN AnyConnect VPN client connected local_ip: 192.168.112.50, user_id: homer.simpson@example.com, remote_ip: 12.34.56.78
Jan 29 12:56:59 loc1-exmpl1-lt-vpn AnyConnect VPN AnyConnect VPN client disconnected local_ip: 192.168.112.50, user_id: homer.simpson@example.com, remote_ip: 12.34.56.78
Jan 29 12:56:40 loc1-exmpl1-lt-vpn AnyConnect VPN AnyConnect VPN client connected local_ip: 192.168.112.13, user_id: homer.simpson@example.com, remote_ip: 12.34.56.78
Jan 29 12:56:38 loc1-exmpl1-lt-vpn AnyConnect VPN AnyConnect VPN client disconnected local_ip: 192.168.112.13, user_id: homer.simpson@example.com, remote_ip: 12.34.56.78
Jan 29 12:35:37 loc1-exmpl1-lt-vpn AnyConnect VPN AnyConnect VPN client connected local_ip: 192.168.112.168, user_id: homer.simpson@example.com, remote_ip: 12.34.56.78
Jan 29 12:35:33 loc1-exmpl1-lt-vpn AnyConnect VPN AnyConnect VPN client disconnected local_ip: 192.168.112.168, user_id: homer.simpson@example.com, remote_ip: 12.34.56.78
Jan 29 12:02:41 loc1-exmpl1-lt-vpn AnyConnect VPN AnyConnect VPN client connected local_ip: 192.168.112.50, user_id: homer.simpson@example.com, remote_ip: 12.34.56.78
Jan 29 12:02:40 loc1-exmpl1-lt-vpn AnyConnect VPN AnyConnect VPN client disconnected local_ip: 192.168.112.50, user_id: homer.simpson@example.com, remote_ip: 12.34.56.78
Jan 29 12:02:12 loc1-exmpl1-lt-vpn AnyConnect VPN AnyConnect VPN client connected local_ip: 192.168.112.13, user_id: homer.simpson@example.com, remote_ip: 12.34.56.78
Jan 29 12:02:10 loc1-exmpl1-lt-vpn AnyConnect VPN AnyConnect VPN client disconnected local_ip: 192.168.112.13, user_id: homer.simpson@example.com, remote_ip: 12.34.56.78
Jan 29 12:01:26 loc1-exmpl1-lt-vpn AnyConnect VPN AnyConnect VPN client connected local_ip: 192.168.112.168, user_id: homer.simpson@example.com, remote_ip: 12.34.56.78
Jan 29 11:55:14 loc1-exmpl1-lt-vpn AnyConnect VPN AnyConnect VPN client connected local_ip: 192.168.112.50, user_id: homer.simpson@example.com, remote_ip: 12.34.56.78
Jan 29 11:49:34 loc1-exmpl1-lt-vpn AnyConnect VPN AnyConnect VPN client connected local_ip: 192.168.112.13, user_id: homer.simpson@example.com, remote_ip: 12.34.56.78
Jan 27 15:06:28 loc1-exmpl1-lt-vpn AnyConnect VPN AnyConnect VPN client disconnected local_ip: 192.168.112.13, user_id: homer.simpson@example.com, remote_ip: 12.34.56.78

 

which isn't super helpful. I've tried running a packet capture on that machine on Anyconnect, but that doesn't seem to work either (as soon as I hit "start capture", it downloads a 0byte file, then stops doing anything). If I try to download after stopping capture, I get a "failed to connect to server" error message:

 

Screenshot 2024-01-29 at 4.16.40 PM.png

 

Not quire sure what is going on. 

 

Is there a setting I'm missing that would reconnect the Windows VPN automatically or something? Or should it be more stable than this?

1 Accepted Solution
Gary_Geihsler1
Meraki Employee
Meraki Employee

The version of Secure Client (AnyConnect) that is available via the Universal Windows Platform has limitations when compared to the standard client software. Looking at the release notes here - there are multiple conflicts with Secure Connect. Most notably the lack of SAML 2.0 authentication which is the only supported authentication method in Secure Connect today. 

There are instructions for deploying the Umbrella Roaming Security Module alongside the Core VPN module here - additionally you want to deploy the Firewall Posture Module and DART (Diagnostics) module for full Secure Connect capability. I do not recommend deploying the NAM or ISE modules as they are not used and can cause issues if not configured properly. 

View solution in original post

9 Replies 9
CptnCrnch
Kind of a big deal
Kind of a big deal

I've never actively used the Windows Store version, but heard one of my customers telling me about that this is a more or less "crippled down" version of Secure Client. 

 

Have you tried using the regular version from the Cisco Download site? Just to make sure that it's not related to the source.

from_afar
Building a reputation

Thanks for the reply.

 

Yes I've tried the downloadable from dashboard version and it seems to work OK if I don't install the Network Access Manager (if that is installed, some laptops, seemingly at random, will have their network access completely broken--it will consistently fail at "getting IP address" when they try to join their WiFi networks. Found a bug for this on Cisco site but was marked as "unable to reproduce"). The issue with this version is that I have to remote in to install it on all of the clients whereas the Store version can be installed by the user via Company Portal which makes things much easier. 

CptnCrnch
Kind of a big deal
Kind of a big deal

Any chance to use e.g. Intune for rolling out the Secure Client agent? As we don't know anything about your environment, there would be various ways to roll it out.

from_afar
Building a reputation

Probably. I've done it with other softwares. Just not sure how it would work with all of the extra packages (Umbrella, ZTA, ISE Posture, etc.) with IntuneWinAppUtil.exe. I suppose I could just run core and not worry about the other stuff. 

I'm also a tiny bit hesitant as I'm supposed to be getting Umbrella API keys to enable Umbrella which may offer a better user experience for users to VPN in. 

If there is a guide to deploying the Secure Client via intune that you know of, I'd love to check it out. 

PhilipDAth
Kind of a big deal
Kind of a big deal

Couldn't you just deploy the MSIs?

from_afar
Building a reputation

I could but as I said I'm unfamiliar with deploying where there are multiple msi's involved. I could deploy just core, but then I'd still have to install Umbrella, ZTA, etc. manually. 

Gary_Geihsler1
Meraki Employee
Meraki Employee

The version of Secure Client (AnyConnect) that is available via the Universal Windows Platform has limitations when compared to the standard client software. Looking at the release notes here - there are multiple conflicts with Secure Connect. Most notably the lack of SAML 2.0 authentication which is the only supported authentication method in Secure Connect today. 

There are instructions for deploying the Umbrella Roaming Security Module alongside the Core VPN module here - additionally you want to deploy the Firewall Posture Module and DART (Diagnostics) module for full Secure Connect capability. I do not recommend deploying the NAM or ISE modules as they are not used and can cause issues if not configured properly. 

from_afar
Building a reputation

Thanks very much, Gary. I got the core deploying correclty which is I guess a good start. At least I can get people working. I will review the link on combining the packages--I really would prefer to take advantage of all of the security offerings available. 

I learned the hard way about NAM 🙂 Completely broke networking on most of the machines I deployed it on. Once uninstalled/installed without, things seem to be working fine. Interesting to hear ISE might cause trouble as well--I will leave it out going forward--thank you!

Gary_Geihsler1
Meraki Employee
Meraki Employee

ISE module by itself does not cause a conflict. If you have traffic set to split exclude and ISE is set to [Block untrusted server]; the split excluded traffic is blocked. Could you use the ISE module for purposes outside of Secure Connect, yes. Same with NAM- just have to be careful to deploy properly or there may be issues as you saw. If you are not using ISE or NAM, best to not include the modules. 

Get notified when there are additional replies to this discussion.