AnyConnect problem after new domain controller

Solved
TimHagan
New here

AnyConnect problem after new domain controller

Our client uses the anyconnect VPN for remote work.  I recently created a 2019 Server Domain controller and moved all the roles to it so i can get rid of the 2012 server since it is now end of life.  

 

Now they cant connect through the VPN after pointing its authentication to the new 2019 DC.  If i point it back to the 2012 server it connects just fine.  

 

Currently getting this error.  msg: Peer IP=xxx.xx.xxx.xx Peer port[31641] AAA[1]: AAA authenticate failed retval=9 - Authentication service cannot retrieve authentication info

 

Meraki help ran packet captures and helped troubleshoot the issue and said that i am getting tls errors and need a certificate uploaded.  Then sent me this link. https://documentation.meraki.com/MX/Client_VPN/AnyConnect_on_the_MX_Appliance/Authentication#Active_...

 

Not sure how that link helps truthfully.  Anyone have any ideas?  Anyone else have these issues after domain controller upgrades since 2012 just went to end of life?  How did you fix it?

1 Accepted Solution

Actually the server needed a reboot and it resolved the issue.  Kind of mad I overlooked that because its IT 101 stuff.  Ended up connecting successfully after the reboot and the error in the logs was no longer present.

 

 

View solution in original post

2 Replies 2
alemabrahao
Kind of a big deal
Kind of a big deal

Have you validated that all AD certificates have been installed?

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

Actually the server needed a reboot and it resolved the issue.  Kind of mad I overlooked that because its IT 101 stuff.  Ended up connecting successfully after the reboot and the error in the logs was no longer present.

 

 

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels