V
V
Vladimir Pilipchuk2013-07-03 12:29:36
VPN
Vladimir Pilipchuk, 2013-07-03 12:29:36

Cisco IOS 12.4.24 asking for license when connecting with AnyConnect?

It was necessary to configure Cisco SSL VPN in branches here. Installed, configured - everything works.
But a problem surfaced in one of the branches - Tsiska sends off - he asks for a license.

The required license for this type ov VPN client is not avaliable on the secure gateway

Stand at all points 2811
Cisco IOS Software, 2800 Software (C2800NM-ADVIPSERVICESK9-M), Version 12.4(24)T8, RELEASE SOFTWARE (fc1)
webvpn gateway GATEWAY
 hostname tf.domain.ru
 ip address X.X.X.X port 443
 http-redirect port 80
 ssl trustpoint tf.domain.ru
 logging enable
 inservice
 !
webvpn install svc flash:/webvpn/anyconnect-win-2.5.3046-k9.pkg sequence 1
 !
webvpn context sslvpn
 title "WELCOME TO COOL SSLVPN Server"
 secondary-color white
 title-color #CCCC66
 text-color black
 ssl authenticate verify all
 !
 login-message "Enter your credentials"
 !
 policy group vpn1
   functions svc-enabled
   banner "Authentication on SSLVPN server success"
   timeout idle 3600
   timeout session 10800
   svc address-pool "EVPN_POOL"
   svc default-domain "tep.local"
   svc keep-client-installed
   svc split dns "tep.local"
   svc split include 10.0.0.0 255.0.0.0
   svc split include X.X.X.X 255.255.255.255
   svc dns-server primary 10.70.11.251
   svc dns-server secondary 10.70.12.80
 default-group-policy vpn1
 aaa authentication list evpn_auth_1
 aaa accounting list vpn-users
 gateway GATEWAY
 max-users 100
 logging enable
 inservice
!
end

I ask for help, colleagues, because I did not expect such a trick from IOS 12.4 (the pieces of iron were purchased the same, in one batch. Why it works for everyone, but I have no idea on this one).

Answer the question

In order to leave comments, you need to log in

5 answer(s)
V
Vladimir Pilipchuk, 2013-07-04
@SLIDERWEB

The issue was resolved by selecting ROM-MON and IOS without changing the configuration of services
Everything worked in the following configuration:

ROM: System Bootstrap, Version 12.4(13r)T, RELEASE SOFTWARE (fc1)
System image file is "usbflash0:c2800nm-advipservicesk9-mz.151-2.T2.bin"

What is the sacred meaning I still do not understand ...

J
JDima, 2013-07-03
@JDima

How many users are already connected? Or the first one sends off? What does "show license" say? Did the piece of iron (you never know)?

V
Vladimir Pilipchuk, 2013-07-03
@SLIDERWEB

The most interesting thing is that on all four branches the aniconnect started up with a half-kick, but on one it doesn’t want to ... and I can’t figure out what I’m doing wrong ... in the intricacies of cisco licensing, with leathering, I’m almost a noob. There are also subtleties of IOS-ROMMON compatibility

P
pavelsh, 2013-07-03
@pavelsh

Have you already looked at debugs?

V
Vladimir Pilipchuk, 2013-07-03
@SLIDERWEB

After your advice

Try disabling the "no crypto engine onboard 0" crypto accelerator
Now it won't connect at all...

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question