W
W
Wbozon2022-04-11 16:10:43
VPN
Wbozon, 2022-04-11 16:10:43

How to make Cisco AnyConnect and Outline friends?

Hello!
To connect to corporate resources, Cisco AnyConnect Secure Mobility Client is used, but while connecting with Outline , access to the corp. resources disappear. If you first connect via Outline, then Cisco does not want to connect at all. Admins claim that it is impossible to use both clients at the same time. I am by no means an expert in networking matters and I ask for your advice. Gathered all the statistics I could.

Cisco AnyConnect Secure Mobility Client

VPN Stats
Connection State: Connected
Bytes Received: 127724
Bytes Sent: 96269
Compressed Bytes Received: 0
Compressed Bytes Sent: 0
Compressed Packets Received: 0
Compressed Packets Sent: 0
Control Bytes Received: 7939
Control Bytes Sent: 8139
Control Packets Received: 34
Control Packets Sent: 59
Encrypted Bytes Received: 146720
Encrypted Bytes Sent: 153482
Encrypted Packets Received: 387
Encrypted Packets Sent: 683
Inbound Bypassed Packets: 0
Inbound Discarded Packets: 0
Outbound Bypassed Packets: 0
Outbound Discarded Packets: 0
Packets Received: 348
Packets Sent: 618
Session Disconnect: None
Time Connected: 00:12:34
Management Connection State: Disconnected (user tunnel active)

Protocol Info
Active Protocol
Protocol Cipher: DHE_RSA_AES_256_SHA256
Protocol Compression: None
Protocol State: Connected
Protocol: DTLSv1.2
Inactive Protocol
Protocol Cipher: DHE_RSA_AES_256_SHA256
Protocol Compression: None
Protocol State: Connected
Protocol: TLSv1.2

Tunnel Mode (IPv4): Split Include
Tunnel Mode (IPv6): Drop All Traffic
Dynamic Tunnel Exclusion: None
Dynamic Tunnel Inclusion: None

Routes
Secure Routes
172.*.*.* 22
172.*.*.* 24
172.*.*.* 24
172.*.*.* 24
172.*.*.* 22
172.*.*.* 22
172.*.*.* 24
172.*.*.* 22
172.*.*.* 24
172.*.*.* 24
172.*.*.* 24
172.*.*.* 24
172.*.*.* 23
172.*.*.* 16
172.*.*.* 32
172.*.*.* 32
192.*.*.* 24
192.*.*.* 24

Non-tunneled Routes
0.0.0.0 0

Firewall Rules

OS Version
Windows 10 : WinNT 10.0.19044

Windows IP Configuration

Host Name . . . . . . . . . . . . : hidden
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : hidden
IGD_Rostelecom

Ethernet adapter Ethernet 3:

Connection-specific DNS Suffix . : hidden
Description . . . . . . . . . . . : Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Physical Address. . . . . . . . . : hidden
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : hidden(Preferred)
Link-local IPv6 Address . . . . . : hidden(Preferred)
IPv4 Address. . . . . . . . . . . : 172.*.*.*(Preferred)
Subnet Mask . . . . . . . . . . . : 255.*.*.*
Default Gateway . . . . . . . . . : ::
DHCPv6 IAID . . . . . . . . . . . : hidden
DHCPv6 Client DUID. . . . . . . . : hidden
DNS Servers . . . . . . . . . . . : 172.*.*.*
172.*.*.*
NetBIOS over Tcpip. . . . . . . . : Enabled

Ethernet adapter Ethernet:

Connection-specific DNS Suffix . : IGD_Rostelecom
Description . . . . . . . . . . . : Realtek PCIe GbE Family Controller
Physical Address. . . . . . . . . : hidden
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IPv4 Address. . . . . . . . . . . : 192.*.*.*(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Lease Obtained. . . . . . . . . . : 10  ЇаҐ«п 2022 Ј. 19:46:52
Lease Expires . . . . . . . . . . : 12  ЇаҐ«п 2022 Ј. 11:25:56
Default Gateway . . . . . . . . . : 192.168.0.1
DHCP Server . . . . . . . . . . . : 192.168.0.1
DNS Servers . . . . . . . . . . . : 1.1.1.1
1.0.0.1
NetBIOS over Tcpip. . . . . . . . : Enabled

Ethernet adapter outline-tap0:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : TAP-Windows Adapter V9
Physical Address. . . . . . . . . : hidden
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

===========================================================================
Interface List
12...00 05 9a 3c 7a 00 ......Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
14...1c 6f 65 aa c4 e5 ......Realtek PCIe GbE Family Controller
20...00 ff 45 56 c7 c5 ......TAP-Windows Adapter V9
1...........................Software Loopback Interface 1
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.*.*.* 192.*.*.* 25
1.0.0.1 255.255.255.255 192.*.*.* 192.*.*.* 26
1.1.1.1 255.255.255.255 192.*.*.* 192.*.*.* 26
127.0.0.0 255.0.0.0 On-link 127.0.0.1 331
127.0.0.1 255.255.255.255 On-link 127.0.0.1 331
127.255.255.255 255.255.255.255 On-link 127.0.0.1 331
172.*.*.* 255.255.252.0 172.*.*.* 172.*.*.* 2
172.*.*.* 255.255.255.255 172.*.*.* 172.*.*.* 2
172.*.*.* 255.255.255.255 172.*.*.* 172.*.*.* 2
172.*.*.* 255.255.255.0 172.*.*.* 172.*.*.* 2
172.*.*.* 255.255.252.0 172.*.*.* 172.*.*.* 2
172.*.*.* 255.255.252.0 172.*.*.* 172.*.*.* 2
172.*.*.* 255.255.255.0 172.*.*.* 172.*.*.* 2
172.*.*.* 255.255.255.0 172.*.*.* 172.*.*.* 2
172.*.*.* 255.255.255.0 172.*.*.* 172.*.*.* 2
172.*.*.* 255.255.252.0 172.*.*.* 172.*.*.* 2
172.*.*.* 255.255.255.0 172.*.*.* 172.*.*.* 2
172.*.*.* 255.255.255.0 172.*.*.* 172.*.*.* 2
172.*.*.* 255.255.255.0 On-link 172.*.*.* 257
172.*.*.* 255.255.255.255 On-link 172.*.*.* 257
172.*.*.* 255.255.255.255 On-link 172.*.*.* 257
172.*.*.* 255.255.255.0 172.*.*.* 172.*.*.* 2
172.*.*.* 255.255.254.0 172.*.*.* 172.*.*.* 2
172.*.*.* 255.255.0.0 172.*.*.* 172.*.*.* 2
178.*.*.* 255.255.255.255 192.*.*.* 192.*.*.* 26
192.*.*.* 255.255.255.0 On-link 192.*.*.* 281
192.*.*.* 255.255.255.255 On-link 192.*.*.* 26
192.*.*.* 255.255.255.255 On-link 192.*.*.* 281
192.*.*.* 255.255.255.255 On-link 192.*.*.* 281
192.*.*.* 255.255.255.0 172.*.*.* 172.*.*.* 2
192.*.*.* 255.255.255.0 172.*.*.* 172.*.*.* 2
224.0.0.0 240.0.0.0 On-link 127.0.0.1 331
224.0.0.0 240.0.0.0 On-link 192.*.*.* 281
224.0.0.0 240.0.0.0 On-link 172.*.*.* 10000
255.255.255.255 255.255.255.255 On-link 127.0.0.1 331
255.255.255.255 255.255.255.255 On-link 192.*.*.* 281
255.255.255.255 255.255.255.255 On-link 172.*.*.* 10000
===========================================================================
Persistent Routes:
None

IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination Gateway
12 26 ::/0 On-link
1 331 ::1/128 On-link
12 281 fe80::/64 On-link
12 281 hidden
On-link
12 281 hidden
On-link
12 281 hidden
On-link
1 331 ff00::/8 On-link
===========================================================================
Persistent Routes:
None

Outline stats

Connection-specific DNS Suffix:
Description: TAP-Windows Adapter V9
Physical Address: ‎hidden
DHCP Enabled: No
IPv4 Address: 10.*.*.*
IPv4 Subnet Mask: 255.255.255.0
IPv4 Default Gateway:
IPv4 DNS Servers: 1.1.1.1, 9.9.9.9
IPv4 WINS Server:
NetBIOS over Tcpip Enabled: Yes
Link-local IPv6 Address: hidden
IPv6 Default Gateway:
IPv6 DNS Server:

Answer the question

In order to leave comments, you need to log in

1 answer(s)
K
ky0, 2022-04-11
@ky0

If both vpnas want you to set their route 0.0.0.0/0, then at the same time there is no way without squats. If aniconnect only pushes individual addresses/subnets, there shouldn't be any problems. Personally, openvpn, wireguard and anyconnect quietly coexist with me.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question