cisco anyconnect "login failed" common causes
Troubleshoots Cisco AnyConnect login failures. Covers credential, certificate, profile, and ASA-side causes in priority order. Use when the client reaches the gateway but login fails. Not for gateway-unreachable errors.
TL;DR
Confirm the username format the gateway expects (some need DOMAIN\user), retype the password to rule out paste issues, and check whether MFA is required but not prompting. Then check the client profile and the ASA logs for the real rejection reason.
The error
Login failed. Please try again.Steps
- Confirm the username format: try both plain username and DOMAIN\username. Expected: one format works. Gateways are picky and the error never says which format it wants.
- Retype the password manually; check caps lock. Expected: careful entry. Then verify the password works elsewhere (webmail, Okta) to isolate VPN vs account.
- Check if MFA is in play: some profiles require Duo/Okta push after password. Expected: push prompt appears. If the client never prompts, the profile may be misconfigured.
- Check the client profile XML for the correct host address and whether certificate auth is expected. Expected: matches the documented gateway. A stale profile pointing at a decommissioned gateway fails exactly this way.
- Ask the network team to check ASA logs for the connection attempt. Expected: the log names the rejection (bad credentials, no group policy, cert required). The client message is generic; the ASA log is specific.
When to use
- AnyConnect reaches the gateway but login fails
- After password changes (stale saved password in the client)
When not to use
- "Unable to reach gateway" (network issue)
- Connected but no internal access (tunnel issue)
Compatibility
- Cisco AnyConnect / Secure Client 4.x/5.x; ASA or FTD headends
Variants
"Certificate validation failure" instead
The client does not trust the gateway certificate. Install the CA or fix the gateway cert chain.
Login works on one gateway, fails on another
Group policies differ per gateway; the user may not be authorized on the second.
Why it happens
"Login failed" is the client's generic message for every post-connection rejection: wrong credentials, wrong format, missing MFA, missing cert, or no authorization. The ASA log is the only place the real reason appears.
Edge cases
- Saved passwords in the AnyConnect profile go stale after every password change; clear them.
- Account locked in AD shows as "login failed" here too; check lockout status.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_PxWpfBLtPPCZzJiw3tygRA
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.