FYI, as the answer in this thread ultimately alludes to, we require a self-signed root as part of the uploaded chain in addition to any intermediates required to validate the end-device certificate.
... View more
Again, you're correct! Went back and looked at the support ticket and it was for the IPsec Client VPN Radius Timeout setting, NOT AnyConnect. We were testing both options, but opted to disable IPsec VPN and deploy AnyConnect only.
... View more