cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1857
Views
0
Helpful
8
Replies

SecureMobility client & AnyConnect client on same machine?

abatson
Level 1
Level 1

Greetings;

 

I have a huge group of laptops that have the Cisco SecureMobility client (3.0) installed & configured by profile.  Some of these same machines need to connect to an ASA 5512-X I've just set up.  It has a standard "Cisco AnyConnect" image in its flash, so that's what it uses.   I've tested installing & using the AnyConnect Client on a plain-vanilla machine & it works fine.

 

Question:  Can I install the Cisco AnyConnect 2.5 client on a machine that already has a functioning installation of the SecureMobility (3.0) client?  Will one destroy the other, or will they co-exist?    Thanks!

8 Replies 8

Marvin Rhoads
Hall of Fame
Hall of Fame

I haven't tried it but would not expect them to coexist well, if at all. They would each try to load similar services at startup that are designed to do the same thing with respect to remote access SSL VPN.

A newer client can connect to an ASA that has any older AnyConnect image in flash just fine. During the connection process, the ASA wil cehck if the client has at least the version that's available in flash. As long as it does, newer clients can connect fine. I've used 3.x and 4.x clients just fine to establish SSL VPN connections to my customers' ASAs with AnyConnect 2.5, 3.x and 4.x on them.

Thanks for the info -- do you have any info on how to change/edit the Profile in the AnyConnect SecureMobility client, so that it could attach to my new ASA?  (right now, the client has a drop-down box that shows, let's say, East and West concentrators in my business; how would I add another option to that drop-down?   I know there's a Profile Editor; is there any wisdom on how to use it..?    Thanks!

 

If you create the profile in ASDM and associate it with the connection profile / tunnel-group it will save the profile (small XML file) to flash and automatically download to a client as part of the first connection. After that it wil have been saved locally (goes in a hidden directory location varying by OS as described in AnyConnect Admin Guide, each connection is represented by its own profile) and be an additional choice populating the drop down list. 

 

If you use the standalone desktop profile editor you will build the same xml file and have a local copy. You can upload that to the ASA or distribute it to clients either manually or via an enterprise tool like SCCM or Windows AD GPOs. Via the ASA is usually preferred as any updates will automatically deploy upon reconnect. 

Excellent --- I've got some work to do it would seem -- I'll post back with my results...

OP here:   OK, I did my testing; it did not turn out well.  Here's what I did below.  I need to figure out if its possible to get these to work together, or if I have to knuckle under and go for OpenVPN.

 

Started with:  Working copy of Cisco AnyConnect SecureMobility Client 3.0.3050

 

Installed "Cisco AnyConnect VPN Client"  2.5.2014

 

What happened:  The AnyConnect VPN Cleint 2.5 works just fine.  The SecureMobility client is dead & cold to the touch.   I get error messages on the screen, "VPN Service Not Available", then "The VPN Service is either not running or not available..."   I tried some prescribed fixes on the Internet with no beneficial effect.

 

Then: I un-installed the AnyConnect 2.5 client & rebooted.   SecureMobility still dead.

 

Now:  I've just downloaded the newest PKG file for AnyConnect, "3.1.08009", and I have that in flash.  I'll start with a fresh working copy of SecureMobility & then try installing this newer version of AnyConnect.

 

If I need to edit a consolidated XML config file, then I can't do that, because my business won't allow me to touch the config of the 'corporate' VPN client (because I then become responsible for it)   They can't run off their own configs & be seperate?
 

Each profile uses its own dedicated connection profile (xml file).

I have ASAs running multiple ones and it works just fine.

I also have 8 different profiles (pointing to VPNs across 7 ASAs) in my AnyConnect installation and it also works perfectly fine.

My AnyConnect is the latest release of 4.1, but this feature works pretty much the same with 3.1 as well.

Tonight's testing results:  Unexpected...  Everything works:

 

I found and edited the "Servers" section of the XML file to add my new VPN server along-side the two from my company.  All three appeared in the drop-down.  I connected to my ASA just fine...  then:

When I log into my corporate VPN device, it verifies I have the proper XML file, and deletes mine & puts a fresh copy in place.  --the entry for my ASA goes away, leaving just the two from corporate.    but...

 

If I log into my ASA using https://URL/, then it logs into my ASA just fine!... Even more interesting, it leaves the XML file intact.  When I disconnect from my ASA, the two entries from corporate are still there, and they work just fine.

 

The only bad thing is that it looks like a very Java-heavy process in order to log into the ASA via the web browser.  People with the newest version of Java will probably need a signed letter from God in order to connect.  the java on my test system is v6 update 31 and v7 update 55.  Given that corporate keeps pushing their 'proper' XML file to me, the only way to log into my ASA is via the web browser, since I cant make any permanent mods to the XML file...

Each connection can and should have a separate xml file. If the ASA admin has created them, they will automaticallly download to the client upon first connection (and be updated if any updates have been made on subsequent connections). 

In Windows 7 they are located (by default) in C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\Profile

You don't need to edit your corporate one to add entries on your dropdown list.

Assuming the new profiles don't have ASA-based profiles, you can simply create new ones by hand locally. Just copy the one you have, edit the server entry and save as a new xml file in the same local directory. The next time you start AnyConnect (or restart the vpnui.exe process), you should see it in the list to choose from. 

Review Cisco Networking products for a $25 gift card