Tuesday, August 30, 2016

AnyConnect 4.x on ASA 8.4.x: AnyConnect is not enabled on the VPN server

I recently had to do a failover on a pair of ASA5520s. On failing over to the secondary, AnyConnect stopped working. I did not see a license error, but users who connected received this error:

AnyConnect is not enabled on the VPN server

There weren't any smoking guns in the logs. I did notice that the newest version of the config was missing the client image definitions in webvpn. They were in the flash drive, but not copied to the secondary. So, when the secondary took over, this portion of the config was dropped.

The solution was to re-add the images:

config t
anyconnect image disk0:/anyconnect-macosx-i386-4.3.00748-k9.pkg 1
anyconnect image disk0:/anyconnect-win-4.3.00748-k9.pkg 2