The issue is in the way AnyConnect processes the profile XML files. In our testing with ASDM 6.1 / ASA 8.0 and AnyConnect 2.4.0202 we have found that the profiles are processed in alphabetical order. So if a user is initially in a group with profile name default.xml and is moved into a group with a profile called sbl.xml, they will not see the changes in their client that are defined in SBL.xml. In our example the SBL profile contains directives to use start before login. These features never materialize, as the default.xml file is the only one being processed.
Further, when a profile name is cahnged in an existing group - say we cahnge the profile in group a from default.xml to new-default.xml new-default.xml would not get processed. The anyconnect client does not delete old profiles that are no longer required - as soon as they are downloaded to the client pc they are there forever.
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...