Lifecyle Solutions
formerly Canvas Systems

Refurbished & Used Servers, Storage & Networking Solutions

RemarkIT Blog

If you’re having trouble connecting to your company’s network through the Cisco VPN client, check the error code. If you see “Secure VPN connection terminated locally by the client. Reason 412″ it means that the software VPN client detected that the VPN server isn’t responding and has deleted the connection.Cisco VPN error 412 ScreenShot

Cisco VPN error 412 – What Causes it?

The following are the main causes of a VPN 412 error:

  • You’re behind a firewall that’s blocking ports UDP 4500/500 and/or ESP.
  • The VPN client is using connecting on TCP and the default TCP port 10000 for NAT-T is blocked.
  • Your internet connection isn’t stable and some packets aren’t reaching the concentrator/server or the replies from the server/concentrator aren’t getting to the client.
  • The VPN client is behind a NAT device and the VPN server doesn’t have NAT-T enabled. If this is the case, you won’t be able to send or receive traffic. It will connect, but then nothing.  After some time the software client deletes the VPN tunnel.

VPN error 412 Possible solutions

To fix the problem, try the following:

  • If you are using wireless, try to connect with cable. 
  • Turn your firewall off, then test the connection to see whether the problem still occurs. If it doesn’t then you can turn your firewall back on, add exception rules for port 500, port 4500 and the ESP protocol in your firewall.
  • Turn on NAT-T/TCP in your profile, and unblock port 10000 in your firewall.
  • Edit your profile with your editor and change ForceKeepAlive=0 to 1
  • Configure your firewall to permit UDP ports 500 and 62515. These are required for Cisco VPN client.
  • Verify that your client is actually transmitting packets: Start a command window and run the command “netstat -s -p ip 60″ to see IP send and receive packet counts.

Does this solve your Cisco VPN error 412 problem? Let us know in the comments.


# Dilip
Monday, September 17, 2012 1:32 AM
Thanks man

Seems this resolved my problem

thanks again
Ramsh Meena
# Ramsh Meena
Monday, September 17, 2012 9:36 PM
Yes, ForceKeepAlive=1 resolved my issue.
Thanks for posting solution.
# drew
Sunday, October 07, 2012 10:21 PM
Hi guys,

I've been experiencing that kind of error also. May I know the step by step process [of each solution] speciall on how to edit the profile and make ForceKeepAlice set to '1' ? Your response is highly appreciated. Thanks
# ryan
Wednesday, December 19, 2012 7:45 AM
@drew - Open the pcf file in a text editor and add "ForceKeepAlive=1" into the file (I put mine at the end). Also, make sure there is no "ForceKeepAlive=0" already in the file.
# hana
Thursday, January 10, 2013 2:55 AM
May I know the step by step process specially on how to edit the profile and make ForceKeepAlice set to '1' ? Thanks
# Saint
Monday, February 25, 2013 9:45 AM
You have to go to the VPN install folder (ex: c:/program files/cisco system/vpn client/profiles) and edit the desire profile with a text editor, like notepad or wordpad.
Then save it and then try to connect again.
# Rathesh
Sunday, March 03, 2013 6:25 PM

I tried all the above solutions but its not working for me. I spend almost 5 hours searching online and resolving this issue but i still have this issue. Please help!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
# uday
Monday, March 18, 2013 1:30 AM
I cannot find ForceKeepAlice in my pcf file.can i add this ForceKeepAlice in my pcf file.
# xoanxo
Tuesday, April 30, 2013 10:01 AM
Hi guys!
I've the same problem. My vpn drops in a few minutes (sometimes 1.45 or 3.07)
Sometimes the error is 412 or 433. But if i try to connect from other computer, the vpn connects successfully.

Please, I need help!
Friday, May 10, 2013 5:27 AM
Its "ForceKeepAlive" NOT "ForceKeepAlice".

Thnx for the information. Might come handy.
# Anusha
Sunday, May 12, 2013 9:07 AM
Hi Experts !

I am also facing the same problem. I tried with disabling the Firewall , editing the pcf file. ... but nothing worked out.... Could u pls let me know how is the setting of UDP Ports and NAT-T/TCP is done in Windows 7 Home basic. The same file and software works for my pal's system.. but is not working on mine. I am using the 'vpnclient-winx64-msi-' vpn client . Is there any necessary settings required. Please let me know the solution its very important for me..... Thanks a ton. :-)

Post A Comment

Name (required)

Email (required)


Enter the code shown above in the box below

var google_conversion_id = 1039057855; var google_conversion_label = "kO3YCOeggQYQv4e77wM"; var google_custom_params = window.google_tag_params; var google_remarketing_only = true;