This document describes what to do when you enounter this Cisco AnyConnect Secure Mobility Client VPN User Message:
The VPN client was unable to setup IP filtering.
A VPN connection will not be established.
There are no specific requirements for this document.
The information in this document is based on Windows Vista and Windows 7 operating systems only.
The information in this document was created from the devices in a specific lab environment. All of the devices used in this document started with a cleared (default) configuration. If your network is live, make sure that you understand the potential impact of any command.
BFE is a service that manages firewall and Internet Protocol security (IPsec) policies and implements user-mode filtering. The security of the system is significantly reduced if you stop or disable the BFE service. It also results in unpredictable behavior in IPsec management and firewall applications.
These system components depend on the BFE service:
The AnyConnect Secure Mobility Client makes both routing and remote access changes to the host machine. The IKEv2 is also dependent on the IKE modules. This means that, if the BFE service is stopped, The AnyConnect Secure Mobility Client cannot be installed or used to establish a Secure Sockets Layer (SSL) connection.
There are threats in active circulation that disable and remove the BFE service as a first step in the infection process.
Win32/Sirefef (ZeroAccess) trojan is a multi-component family of malware that uses stealth to hide its presence on your computer. This threat gives attackers full access to your system. Due to its nature, the payload might vary greatly from one infection to another, although common behavior includes:
There are no common symptoms associated with this threat. Alert notifications from installed antivirus software might be the only symptoms.
Win32/Sirefef (ZeroAccess) trojan attempts to stop and delete these security-related services:
The scenarios are:
When these error messages are seen, it is important to confirm whether the BFE is actually disabled/missing or if the client is not able to recognize it. In order to troublehoot, complete these steps:
If the service works, the status displays as Started. If there is anything else in that column, there is a problem with the service. However, if the status displays as started, the client is clearly not able to communicate with the service, and it is possible there is a bug.
If the service is disabled or not started, some possible reasons are:
The first step is to scan and disinfect your system with an antivirus software. You should not restore the BFE service if it will be deleted again by Win32/Sirefef (ZeroAccess) trojan. Download the ESET SirefefCleaner tool from this web page, and save it to your desktop.
This video explains the procedure to remove the Win32/Sirefef (ZeroAccess) trojan:.
How do I remove Win32/Sirefef (ZeroAccess) trojan?
Once you have removed Win32/Sirefef (ZeroAccess) trojan, verify that the BFE service can be started and kept active by normal means. In order to do this:
If this procedure does not work, complete these steps:
Revision | Publish Date | Comments |
---|---|---|
1.0 |
26-Jun-2013 |
Initial Release |