Cisco AnyConnect Failed to Initialize Connection Subsystem

This issue was introduced with Microsoft KB# 3023607: Secure Channel cumulative update changes TLS protocol renegotiation and fallback behavior.

Included with Microsoft Security Bulletin MS15-009 – Critical Security Update for Internet Explorer (3034682)

This issue affects users running Windows 8 and may also affect Windows 7 users with IE 11.

The following steps should resolve the problem...
  1. Close the Cisco AnyConnect Window and the taskbar mini-icon (right-click on icon and select Quit)
  2. Right click vpnui.exe in the Cisco AnyConnect Secure Mobility Client folder located in C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\
  3. Click on the Run compatibility troubleshooter button
  4. Choose Try recommended settings
  5. If the wizard suggests Windows 8 compatibility...
    1. Click Test Program.  This will open the program. Click Connect and it should work.
    2. In the wizard, click Next
    3. Select Yes, save these settings for this program
    4. Close the wizard
  6. If the wizard suggests Windows 7 compatibility...
    1. Click Test Program.  This will open the program. Click Connect and it will fail.
    2. Again, close the Cisco AnyConnect Window and the taskbar mini-icon (right-click on icon and select Quit)
    3. In the wizard, click Next
    4. Select No, try again using different settings
    5. Check the box next to The program worked in earlier versions of Windows but won't install or run now and click Next.
    6. Choose Windows 8 and click Next
    7. Click Start the program....  Click Connect in the Anyconnect client and it should work now.
    8. Click Next in the wizard
    9. Select Yes, save these settings for this program
    10. Close the wizard
  7. Some people may need to repeat the above steps for vpnagent.exe. That is the local service that supports the client user interface.
  • 9 Users Found This Useful
Was this answer helpful?

Related Articles

Adding Users to ASA

1. Launch ASDM client 2. Sign In as administrator 3. Go to Configuration at the top of the screen...

Changing Password on ASA

1. Launch ASDM client 2. Sign in as administrator 3. Go to Configuration at the top of the screen...

Cisco Firewall Disabling TLS Initiation by Default

By default, the Cisco ASA will block STARTTLS initiation because of the SMTP packet inspection....

Multiple Subnets on Cisco ASA

Using a subnet directly on the DMZ segments to avoid any special needs regarding the NAT and DNS...

Quickkstart (including IPsec)

The first step is to install the VPN client on your desktop computer.  The Quick start guide does...