Hi,
We're having some trouble with a Meraki AnyConnect deployment and wanted to check with the community to see if anyone else has encountered this random issue. The deployment is MX 250 running firmware 18.107.2 with authentication to DUO via SAML. On the client side, Meraki AnyConnect v4.10.05085.
This issue is fairly new, has impacted various users, we're unable to reproduce it, and it appears to have showed up after a recent MX firmware upgrade. We have an open Meraki Support case on this that's not progressing.
As for the issue, when a user attempts to establish the Meraki AnyConnect VPN connection, the AnyConnect client displays this error: "Authentication failed due to problem navigating to the single sign-on URL."
When the issue occurs, we have confirmed that Internet access is good and that the user is 100% able to navigate to the SSO URL via web browser which indicates that this isn't a DNS, connectivity, or services availability issue. While this is occurring for a specific user, others are able to establish VPN's without issue. Rebooting the client PC does not help and waiting a while and trying again does not help.
To work around the issue, the only thing that seems to help "resolve" is to:
- Uninstall the AnyConnect Client (appwiz.cpl)
- Delete the "c:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client"
- Reinstall v4.10.05085
In a few instances we've attempted to upgrade a client to Cisco Secure Client AnyConnect 5.0.02075 with same error. I have also been informed that the error condition remains if you uninstall/reinstall without deleting "c:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client".
If anyone has run into this or has any thoughts on what may be happening or a better work-around, I'd greatly appreciate any feedback.
Thanks!