This document describes different error messages generated when using
the Cisco AnyConnect VPN Client on Apple iPad devices. Corresponding
resolutions required in order to eliminate those error messages are also
There are no specific requirements for this document.
The information in this document is based on these software and
The information in this document was created from the devices in a
specific lab environment. All of the devices used in this document started with
a cleared (default) configuration. If your network is live, make sure that you
understand the potential impact of any command.
Technical Tips Conventions for more information on document
This section provides examples of error messages and their respective
This error message is received on the iPad client when trying to launch
the AnyConnect application:
The secure gateway has rejected the agent's VPN connect or reconnect request.
A new connection requires re-authentication and must be started manually.
Please contact your network administrator if this problem persists.
The following message was received from the secure gateway: No License
VPN session ended.
You need to have the required license in order to use the AnyConnect
VPN Client on iPad clients. Refer to this CLI snippet from the ASA
show version command:
AnyConnect for Mobile : Disabled perpetual
AnyConnect for Cisco VPN Phone : Disabled perpetual
Advanced Endpoint Assessment : Disabled perpetual
Provide details like "PAK number" and "Serial number of the device" at
(registered customers only)
in order to obtain the license. You could also contact
Technical Support or send an e-mail to
This error log message is received on the Cisco ASA:
%ASA-6-725007: SSL session with client
CERT-C: E ../cert-c/source/certobj.c(719) : Error
CRYPTO_PKI: can not set ca cert object
These error messages are received on the iPad client
The client certificate authentication is failing and the Cisco ASA can
parse some certificate extensions successfully, but cannot validate the client
certificate. In order to resolve this issue, configure the CA on the ASA and
enroll the iPad. Once complete, you should connect successfully using the
This error message is received when trying to connect to an ASA from an
iPad AnyConnect Client.
Secure gateway has reject the connection attempt. No
address available for SVC connection.
Verify that the tunnel-group has a valid address-pool/dhcp server and
that there are available addresses in that pool.
This error message is received while trying to connect:
The group URL requested has not been found.
Please specify a valid group URL, and try again.
Check that the group-url is properly configured on the iOS device and
on the head-end. They must match exactly, minus the https://, which should
exist on the head-end.