Monday, 12 November 2018

Anyconnect DNS issues on VPN

If you 're facing troubles with clients connecting to VPN and can't resolve DNS please check the following

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuz27826/?rfs=qvred

In short
Anyconnect creates a static route on the client for the DHCP server. if your DHCP server also servers as DNS etc. this breaks the DNS resolution for your client.
Apply the following as workaround

group-policy DfltGrpPolicy attributes
  webvpn
     anyconnect-custom-attr no-dhcp-server-route
     anyconnect-custom-data no-dhcp-server-route no-dhcp-server-route true

group-policy <XXX> attributes 
  anyconnect-custom no-dhcp-server-route value no-dhcp-server-route