All,
I'm hoping somebody can help here. We have recently implemented MX devices devices across all our offices and use Umbrella with the cloud-based Secure Connect feature connecting all sites together.
As part of this solution, we have the Secure Connect environment setup to allow client VPN access for home/remote working, which as I understand it, is like a cloud-managed, stripped down version of direct MX/ASA-based VPN access. We have two datacentres configured (London and Frankfurt) and it works very well.
One thing that has been annoying me though is if we connect to the VPN while on an Ethernet connection, it initially connects, then immediately disconnects and reconnects, at least two times. The connection then remains perfect up to maximum session time limit.
If we connect via a WiFi connection, it connects first time and then works perfectly for the entirety of the session.
I found some posts on these very forums with a similar issue but it was specific to on-premise MX/ASA device client VPN termination and not Cisco's cloud variant. There was talk of it potentially being an MTU issue, which was resolved by amending the MX/ASA config slightly. It's not possible to make these amendments on the cloud version though.
I've been working with Meraki support for over a month and we've tried several things, mainly along the lines of disabling IPv6 on the various adapters and within the client config file itself, all to no avail.
I'm told the three mechanisms that would cause a reconnection/renegotiation event are:
- MTU value changes
- IPv4 or IPv6 addresses change
- Routing table changes
All of the above make sense to me logically but none of them are changing. Plus, why is it only happening when on an Ethernet connection and never on WiFi?
The testing has been completed and and off our corporate LAN, from home connections and while hot spotted, all with the same LAN-based issues.
The below is what we consistently see in the message history. To be clear, it never re-prompts for credentials other than at initial connection but it does make successfully connecting a mess of toaster notifications before access is consistent.
Any bright ideas? I've been submitting various DART bundles throughout.
21/07/2025
13:46:47 Ready to connect.
13:46:59 Contacting London, UK.
13:46:59 Posture Assessment: Required for access
13:46:59 Posture Assessment: Checking for updates...
13:46:59 Posture Assessment: Initiating...
13:47:05 Posture Assessment: Active
13:47:05 Posture Assessment: Initiating...
13:47:20 User credentials entered.
13:47:21 Establishing VPN session...
13:47:21 The Cisco Secure Client - Downloader is performing update checks...
13:47:21 Checking for profile updates...
13:47:21 Checking for customization updates...
13:47:21 Performing any required updates...
13:47:21 The Cisco Secure Client - Downloader update checks have been completed.
13:47:21 Establishing VPN - Initiating connection...
13:47:21 Establishing VPN session...
13:47:22 Establishing VPN - Examining system...
13:47:22 Establishing VPN - Activating VPN adapter...
13:47:23 Establishing VPN - Configuring system...
13:47:23 Establishing VPN...
13:47:23 Connected to London, UK.
13:47:27 Reconnecting to London, UK...
13:47:27 Establishing VPN - Examining system...
13:47:28 Establishing VPN - Activating VPN adapter...
13:47:28 Establishing VPN - Configuring system...
13:47:28 Establishing VPN...
13:47:28 Connected to London, UK.