cisco anyconnect "secure vpn connection terminated locally by the client"
Diagnoses Cisco AnyConnect disconnects reporting the connection was terminated locally by the client: separating user action, idle timeouts, network changes, and client bugs. Use when the log shows this message. Not for login failures or gateway unreachable errors.
TL;DR
This message means the client itself tore the tunnel down, most often an idle timeout, a network interface change, or a conflicting adapter. Check the client logs for the trigger, stabilize the network path, and adjust timeout or reconnect settings.
The query
cisco anyconnect "secure vpn connection terminated locally by the client"Use this when
- AnyConnect logs show terminated locally by the client
- disconnects happen on Wi-Fi roams or sleep/wake
- the tunnel drops while the user is idle
Not for
- login failed or authentication errors
- gateway not responding or unreachable errors
- certificate validation failures
Steps
- Open the AnyConnect DART or event logs around the disconnect timestamp and find the trigger event. Expected output: the log names the cause, such as idle timeout or interface change.
- Ask whether the disconnect aligns with sleep, Wi-Fi roaming, or VPN idle periods. Expected output: a pattern emerges linking disconnects to an event.
- Disable conflicting virtual adapters and confirm only one AnyConnect adapter is active. Expected output: a single clean adapter state.
- Check the profile for idle timeout and dead-peer-detection settings with the VPN admin. Expected output: timeout values are known and sane for the use case.
- Update the AnyConnect client to the current supported version and retest. Expected output: disconnects stop or the log shows a new actionable cause.
Applies to
Cisco AnyConnect Secure Mobility Client 4.x/5.x, Cisco ASA and FTD headends, Windows and macOS.
Variant phrasings
Disconnects every few minutes on stable Wi-Fi
Likely dead-peer detection or a middlebox killing idle UDP; check DTLS vs TLS fallback.
Disconnects only on hotel or guest Wi-Fi
Captive portal or aggressive NAT timeouts; the client gives up and reports local termination.
Why it happens
The client tears down the tunnel itself when its keepalives fail, the OS signals a network change, or a policy timer fires. The message describes who ended it, not why, so the logs carry the real answer.
Edge cases
- Always-on profiles can fight user-initiated disconnects; check the profile intent.
- Third-party endpoint security with its own VPN driver often conflicts; exclude or remove one.
- Collect DART before escalating; without logs the headend admin cannot help.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_-bX3-1k3Ogg6xOaYpZWgfg
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.