On 02/03/2014 09:35 PM, Kevin Cernekee wrote: > Interesting. In non-XML-POST mode (the default on 5.02 for gateways > with authgroups present), it returns the 204 error instead of the > usual "Login failed." In XML POST mode I get "Authentication failed." > which is a little different too. > > I will try it with AnyConnect + MITM to see what happens. > > Two things you can try: > > 1) Revert back to 5.01. This will use XML POST by default, and since > you're choosing the first authgroup, you shouldn't hit the old > authgroup selection problem. Still won't auth. http://fpaste.org/74172/48822413/ > 2) Use the head of tree from git.infradead.org. This will also use > XML POST, and the authgroup logic should work as expected. Won't auth. http://fpaste.org/74173/39148827/ I have to use a token at the end of my password, which is correctly entered. Not sure if this causes any problems for openconnect. Our VPN used to use vpnc and I was able to connect without a problem (including the token). Thanks, Michael