## TL;DR
This message means the client itself tore the tunnel down, most often an idle timeout, a network interface change, or a conflicting adapter. Check the client logs for the trigger, stabilize the network path, and adjust timeout or reconnect settings.

## The query
```text
cisco anyconnect "secure vpn connection terminated locally by the client"
```

## Use this when
- AnyConnect logs show terminated locally by the client
- disconnects happen on Wi-Fi roams or sleep/wake
- the tunnel drops while the user is idle

## Not for
- login failed or authentication errors
- gateway not responding or unreachable errors
- certificate validation failures

## Steps
1. Open the AnyConnect DART or event logs around the disconnect timestamp and find the trigger event. Expected output: the log names the cause, such as idle timeout or interface change.
2. Ask whether the disconnect aligns with sleep, Wi-Fi roaming, or VPN idle periods. Expected output: a pattern emerges linking disconnects to an event.
3. Disable conflicting virtual adapters and confirm only one AnyConnect adapter is active. Expected output: a single clean adapter state.
4. Check the profile for idle timeout and dead-peer-detection settings with the VPN admin. Expected output: timeout values are known and sane for the use case.
5. Update the AnyConnect client to the current supported version and retest. Expected output: disconnects stop or the log shows a new actionable cause.

## Applies to
Cisco AnyConnect Secure Mobility Client 4.x/5.x, Cisco ASA and FTD headends, Windows and macOS.

## Variant phrasings
### Disconnects every few minutes on stable Wi-Fi
Likely dead-peer detection or a middlebox killing idle UDP; check DTLS vs TLS fallback.

### Disconnects only on hotel or guest Wi-Fi
Captive portal or aggressive NAT timeouts; the client gives up and reports local termination.

## Why it happens
The client tears down the tunnel itself when its keepalives fail, the OS signals a network change, or a policy timer fires. The message describes who ended it, not why, so the logs carry the real answer.

## Edge cases
- Always-on profiles can fight user-initiated disconnects; check the profile intent.
- Third-party endpoint security with its own VPN driver often conflicts; exclude or remove one.
- Collect DART before escalating; without logs the headend admin cannot help.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_-bX3-1k3Ogg6xOaYpZWgfg
