cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
162
Views
5
Helpful
4
Replies

Using same URL name for Anyconnect clients but redirecting Anyconnect connection to VPN ASA closer to client

Hello All;

 

We have different VPN URLs names depending on the region where the client is located and I like to know if you have a recommendation to use one VPN URL name (ex. myvpn.Company.com) but redirecting the VPN connection to a VPN ASA close to the Anyconnect client.

 

Thanks;

 

Juan

Everyone's tags (1)
4 REPLIES 4
Cisco Employee

Re: Using same URL name for Anyconnect clients but redirecting Anyconnect connection to VPN ASA closer to client

Hi Juan,

Maybe you could use something like optimal gateway selection(OGS).

OGS is a feature that can be used in order to determine which gateway has the lowest Round Trip Time (RTT) and connect to that gateway. One can use the OGS feature in order to minimize latency for Internet traffic without user intervention.

You can have one URL with some backup URL’s for the OGS process.

Links for reference:

https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/116721-technote-ogs-00.html

https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect40/administration/guide/b_AnyConnect_Administrator_Guide_4-0/anyconnect-profile-editor.html

 

Rate if it helps.

Regards,

Josue Brenes

TAC - VPN Engineer.

Highlighted
Hall of Fame Master

Re: Using same URL name for Anyconnect clients but redirecting Anyconnect connection to VPN ASA closer to client

I concur with @Josue Brenes - OGS is the way to go to solve this requirement.

Re: Using same URL name for Anyconnect clients but redirecting Anyconnect connection to VPN ASA closer to client

Hello Josue;

 

Thank you for providing the information about OGS, reading the URL link it sounds that OGS caches the information for 14 days, we have people at our company that travels across different countries and I don't know how this cache will work for them. Has you had any experience with this implementation at other sites? I want to be careful before I implement something that it will be more troublesome than the actual fix.

 

Thanks again;

 

Juan

Cisco Employee

Re: Using same URL name for Anyconnect clients but redirecting Anyconnect connection to VPN ASA closer to client

Hi Jaun,

 

We have many customers who have the same issue you are concerned with.  With OGS you will have all of your traveling employees opening IT cases stating that they are connecting to headends that are potentially across the globe.  I would reccomend using a true geographic based load balancer instead of OGS in AnyConnect. 

 

Thanks,

Steve S.