cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
10297
Views
4
Helpful
20
Replies

Jabber Secure Connect

Martin2m2
Level 1
Level 1

Hi All,

I have been through loads of presentations and documents, but can't seem to find a definitive answer to my Jabber Secure Connect questions.

Customer of mine has plans to roll out Cisco Jabber for iPhone, Jabber for Android and Jabber for Windows (currently uses IPC since they do not have Presence).

He has CUCM 8.6 (with UCL) on two UCS-C servers and a ASA5510. No Presence server at the moment.

If the user does not require FULL application access on his iPhone or Android phone, but Jabber access only:

Q1: Is it correct that NO Cisco AnyConnect Secure Mobility client is necessary on the phone?

Q2: Is there a minimum version of Jabber for iPhone and Android to have the Secure Connect functionality included?

Q3: On the ASA you need the AnyConnect Mobile ASA5510 license. But do you need AnyConnect Essential or Premium licenses with the Secure Connect?

Q4: When you are not using the AnyConnect Secure Mobility client is it therefore a clientless SSL connection and is Premium required?

For the Jabber for Windows:

Q5: Does the Secure Connect functionality exist in the Jabber for Windows, if so in what version?

I could imagine that a full application access with the AnyConnect Secure Mobility client for a laptop is more logical.

Q6: If so, do you still require the AnyConnect Mobile ASA5510 license? Since it enables mobile OS platform compatibility and a Windows laptop is hardly a Mobile OS.

Q7: Is the AnyConnect Essential sufficient in combination with the AnyConnect Secure Mobility client or when are the Premium licenses needed in this case?

Thanks for any help,

Martin

Message was edited on April 19, 2013:  Lisa Marcyes from the Cisco Collaboration Community Team added community category and tags for greater ease in filtering (no change to content).

- I say what I mean and I do what I say -
20 Replies 20

All apps are moving away from Secure connect. The slide was done before the updates happened. All apps will use Any connect standalone to launch

Thanks

Srini

Martin2m2
Level 1
Level 1

Hi All,

I will try to summarize the discussion here for future reference to other users. And I have one additional question.

Comments are welcome.

Jabber for iPhone/Android

Q1: Is it correct that NO Cisco AnyConnect Secure Mobility client is necessary on the smartphone?

A1: You do need the AnyConnect Secure Mobility client. The developments are that Cisco has moved away from the Secure Connect feature in the Jabber for iPhone/Android. The AnyConnect client delivers a better connectivity experience and also the option to have VPN access for other applications.

Q2: Is there a minimum version of Jabber for iPhone and Android to have the Secure Connect functionality included?

A2: Not relevant anymore. It is going the other way, the newer versions of Jabber do not have Secure connect.

Q3: On the ASA you need the AnyConnect Mobile ASA5510 license. But do you need AnyConnect Essential or Premium licenses with the Secure Connect?

A3: For VPN connection with a laptop or smartphone with Jabber AnyConnect Essentials on the ASA is enough. Be carefull that you can't combine Essentials and Premium on one platform. If you wan to use the VPN Phone (with a deskphone) connectivity option then Premium is needed.

Q4: When you are not using the AnyConnect Secure Mobility client is it therefore a clientless SSL connection and is Premium required?

A4: No you can't do without, see A1 and A2.

For the Jabber for Windows:

Q5: Does the Secure Connect functionality exist in the Jabber for Windows, if so in what version?

I could imagine that a full application access with the AnyConnect Secure Mobility client for a laptop is more logical.

A5: No Secure Connect doesn't exist in Jabber for Windows.

Q6: If so, do you still require the AnyConnect Mobile ASA5510 license? Since it enables mobile OS platform compatibility and a Windows laptop is hardly a Mobile OS.

A6: NO, AnyConnect Mobile ASA5510 license is not needed for Jabber for Windows.

Q7: Is the AnyConnect Essential sufficient in combination with the AnyConnect Secure Mobility client or when are the Premium licenses needed in this case?

A7: NO, also in this case (JAbber for Windows with AnyConnect client) AnyConnect Essentials on the ASA is enough.

New Question:

Q8: Is it possible to setup the AnyConnect Secure Mobile client in such a way that ONLY the Jabber client has access over the VPN and no other applications? Customer wants the VPN connection to come up when Jabber is started and go down again when it is closed.

Many thanks to the contributors to this discussion.

Martin

- I say what I mean and I do what I say -

I don’t believe that solution is baked. Once the tunnel is set up all applications has access to the tunnel. Now can restrict what address are allowed on the tunnel/ports to restrict to a certain degree other applications. You can also do split tunneling to avoid You tube or other consumer applications from flowing through that tunnel

There is discussion on using any connect URI handlers(enhancements with 3.0) to programmatically connect/disconnect the tunnel when Jabber is launched/killed.

Thanks

Srini

As said "No Secure Connect doesn't exist in Jabber for Windows".

Does this mean that I cant use jabber in windows with cisco anyconnect?. The problem is that cisco jabber when using cisco anyconnect version 3.1 only connects to the Presence server but it does not connect to the Call Manager both deskphone and softphone mode and also voicemail are not working but when inside the network both deskphone, softphone and voicemail features work.

Are there any ports that I can open other than the following:

8443 HTTP

2748 TCP

143 TCP/TLS

16384 to 3276 UDP

69 UDP

443 SSL



No secure connect is a completely different thing. Secure connect was a plan to embed any connect inside the client itself so that when the client would launch the tunnel would be generated from within the client.

Jabber does support launching the any connect separately and that’s the strategy going forward.

For troubleshooting issues best to post here

https://supportforums.cisco.com/community/netpro/collaboration-voice-video/jabber

Thanks

Srini

Hi,

I'm having the same problem as you. Please let me know if you were able to get this resolved and how you did it.

Thanks