<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AnyConnect RA VPN in ASA Multiple Mode in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/anyconnect-ra-vpn-in-asa-multiple-mode/m-p/3881491#M31085</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326072"&gt;@johnlloyd_13&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The guide you linked is a valid one, even for 9.8.&lt;/P&gt;
&lt;P&gt;1. Any AnyConnect 4.x release is compatible. Cisco generally recommends using the latest release (currently 4.7.04056)&lt;/P&gt;
&lt;P&gt;2. As noted in the linked guide, we make some settings in system context, put the Anyconnect images into shared storage and then used the user context(s) to individually setup Anyconnect. That last bit is pretty much like it's done on a single context ASA.&lt;/P&gt;
&lt;P&gt;3. You get the 2 "AnyConnect Premium" (roughly equivalent to the current Apex type) licenses per ASA for free. If you need more you need to purchase Anyconnect Plus or Apex (or VPN only) licenses just like with any other ASA. You add those licenses via using the PAK plus serial number(s) to get an activation-key from the software.cisco.com licensing portal.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 28 Jun 2019 13:50:31 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2019-06-28T13:50:31Z</dc:date>
    <item>
      <title>AnyConnect RA VPN in ASA Multiple Mode</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-ra-vpn-in-asa-multiple-mode/m-p/3881317#M31084</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;i'll be configuring anyconnect for remote access VPN in an ASA5500-X 9.8 code. i tried to search but only see this doc which is on asa 9.6:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-firewalls/200353-ASA-Multi-Context-Mode-Remote-Access-A.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-firewalls/200353-ASA-Multi-Context-Mode-Remote-Access-A.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;my questions are:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) what anyconnect 4.x is compatible for asa 9.8 code? i don't see any compatibility matrix.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) which is the go-to config? private or shared storage? any config example i can follow?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) is there a specific license/feature needed? I have&lt;EM&gt; AnyConnect Premium Peers&lt;/EM&gt; applied (total of 4x from active-standby FWs).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Licensed features for this platform:&lt;BR /&gt;Maximum Physical Interfaces : Unlimited perpetual&lt;BR /&gt;Maximum VLANs : 500 perpetual&lt;BR /&gt;Inside Hosts : Unlimited perpetual&lt;BR /&gt;Failover : Active/Active perpetual&lt;BR /&gt;Encryption-DES : Enabled perpetual&lt;BR /&gt;Encryption-3DES-AES : Enabled perpetual&lt;BR /&gt;Security Contexts : 50 perpetual&lt;BR /&gt;Carrier : Disabled perpetual&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;AnyConnect Premium Peers : 2 perpetual&lt;/FONT&gt;&lt;BR /&gt;AnyConnect Essentials : Disabled perpetual&lt;BR /&gt;Other VPN Peers : 5000 perpetual&lt;BR /&gt;Total VPN Peers : 5000 perpetual&lt;BR /&gt;AnyConnect for Mobile : Disabled perpetual&lt;BR /&gt;AnyConnect for Cisco VPN Phone : Disabled perpetual&lt;BR /&gt;Advanced Endpoint Assessment : Disabled perpetual&lt;BR /&gt;Shared License : Disabled perpetual&lt;BR /&gt;Total TLS Proxy Sessions : 2 perpetual&lt;BR /&gt;Botnet Traffic Filter : Disabled perpetual&lt;BR /&gt;IPS Module : Disabled perpetual&lt;BR /&gt;Cluster : Enabled perpetual&lt;BR /&gt;Cluster Members : 2 perpetual&lt;/P&gt;&lt;P&gt;This platform has an ASA5555 VPN Premium license.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Failover cluster licensed features for this platform:&lt;BR /&gt;Maximum Physical Interfaces : Unlimited perpetual&lt;BR /&gt;Maximum VLANs : 500 perpetual&lt;BR /&gt;Inside Hosts : Unlimited perpetual&lt;BR /&gt;Failover : Active/Active perpetual&lt;BR /&gt;Encryption-DES : Enabled perpetual&lt;BR /&gt;Encryption-3DES-AES : Enabled perpetual&lt;BR /&gt;Security Contexts : 100 perpetual&lt;BR /&gt;Carrier : Disabled perpetual&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;AnyConnect Premium Peers : 4 perpetual&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;&amp;lt;&amp;lt; 2x from active + 2x from standby FW&lt;/FONT&gt;&lt;BR /&gt;AnyConnect Essentials : Disabled perpetual&lt;BR /&gt;Other VPN Peers : 5000 perpetual&lt;BR /&gt;Total VPN Peers : 5000 perpetual&lt;BR /&gt;AnyConnect for Mobile : Disabled perpetual&lt;BR /&gt;AnyConnect for Cisco VPN Phone : Disabled perpetual&lt;BR /&gt;Advanced Endpoint Assessment : Disabled perpetual&lt;BR /&gt;Shared License : Disabled perpetual&lt;BR /&gt;Total TLS Proxy Sessions : 4 perpetual&lt;BR /&gt;Botnet Traffic Filter : Disabled perpetual&lt;BR /&gt;IPS Module : Disabled perpetual&lt;BR /&gt;Cluster : Enabled perpetual&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2019 08:58:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-ra-vpn-in-asa-multiple-mode/m-p/3881317#M31084</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2019-06-28T08:58:23Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect RA VPN in ASA Multiple Mode</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-ra-vpn-in-asa-multiple-mode/m-p/3881491#M31085</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326072"&gt;@johnlloyd_13&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The guide you linked is a valid one, even for 9.8.&lt;/P&gt;
&lt;P&gt;1. Any AnyConnect 4.x release is compatible. Cisco generally recommends using the latest release (currently 4.7.04056)&lt;/P&gt;
&lt;P&gt;2. As noted in the linked guide, we make some settings in system context, put the Anyconnect images into shared storage and then used the user context(s) to individually setup Anyconnect. That last bit is pretty much like it's done on a single context ASA.&lt;/P&gt;
&lt;P&gt;3. You get the 2 "AnyConnect Premium" (roughly equivalent to the current Apex type) licenses per ASA for free. If you need more you need to purchase Anyconnect Plus or Apex (or VPN only) licenses just like with any other ASA. You add those licenses via using the PAK plus serial number(s) to get an activation-key from the software.cisco.com licensing portal.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2019 13:50:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-ra-vpn-in-asa-multiple-mode/m-p/3881491#M31085</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-06-28T13:50:31Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect RA VPN in ASA Multiple Mode</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-ra-vpn-in-asa-multiple-mode/m-p/3881905#M31086</link>
      <description>&lt;P&gt;hi marvin,&lt;/P&gt;&lt;P&gt;is this the ONLY file i need to transfer in the ASA flash? users are ONLY using windows.&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;EM&gt;&lt;SPAN class="pointer text-darkgreen"&gt;anyconnect-win-4.7.04056-webdeploy-k9.pkg&lt;/SPAN&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN class="pointer text-darkgreen"&gt;also, below is my template. appreciate if you let me know if there's any error in my config.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="pointer text-darkgreen"&gt;do i need to transfer the anyconnect image file twice? one to disk0 and another to the private 'virtual flash'?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;changeto system&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;class VPN&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT color="#FF0000"&gt;limit-resource VPN AnyConnect 4&amp;nbsp;&lt;/FONT&gt;&amp;nbsp;&amp;nbsp; &amp;lt;&amp;lt;&amp;lt; I CURRENTLY HAVE 4 ANYCONNECT DEFAULT/BUILT-IN LICENSE&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT color="#FF0000"&gt;limit-resource VPN Burst AnyConnect 4&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;EM&gt;mkdir PRIVATE_VPN&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;FONT color="#FF0000"&gt;copy ftp://ftpuser:ftpuser@172.x.x.x/anyconnect-win-4.7.04056-webdeploy-k9.pkg flash&amp;nbsp;&amp;nbsp; &amp;lt;&amp;lt;&amp;lt; DO I NEED TO TRANSFER ANYCONNECT IMAGE FILE TWICE?&lt;BR /&gt;&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;FONT color="#FF0000"&gt;copy flash:/anyconnect-win-4.7.04056-webdeploy-k9.pkg flash:/PRIVATE_VPN/CUST-X&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;context CUST-X&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT color="#FF0000"&gt;member VPN&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;allocate-interface GigabitEthernet0/0&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;allocate-interface GigabitEthernet0/1.9 &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;config-url disk0:/VPN.cfg&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT color="#FF0000"&gt;storage-url private disk0:/PRIVATE_VPN CUST-X&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 29 Jun 2019 14:07:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-ra-vpn-in-asa-multiple-mode/m-p/3881905#M31086</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2019-06-29T14:07:13Z</dc:date>
    </item>
  </channel>
</rss>

