10-31-2014 09:29 AM
have a small company with ASA5505 8.3.2/ASDM 6.4 - they would like to access their server files remotely, etc - so VPN... (right?)
(I went to school for networking but we just kinda flew through VPN configurations and specifics "because there are too many to try to teach, so you'll just learn it on the job." Now on the job, time to learn.)
Anyway, what's the best way to configure the VPN - SSL? IPSec? They want to connect windows 7 and 8 machines as well as iphones/ipads/android devices. Do you have to pay for the AnyConnect client software? There isn't a Cisco service contract for this account. What are my options? Can someone please help a guy setting up his first VPN? Thanks in advance...
10-31-2014 12:23 PM
No service contract hurts yo in a case like this - Smartnet on a 5505 is very inexpensive and entitles you to 24x7 Cisco TAC support.
That said, there is a VPN wizard in ASDM that does the heavy lifting for you. The type you want is SSL VPN. That will use the AnyConnect client. There isn't any cost for that software but to get the latest versions you need service contract. They update it quite regularly. A new major release (4.0) will be out later in November.
For mobile devices (iOS and Android) you will have to have the AnyConnect for Mobile license added. That runs about $100 list. Check the output of "show activation-key" to see if you have it already.
Maybe you can have them purchase both the mobile license and Smartnet support if it's needed. The license is permanent and Smartnet on a 5505 is only about US$100-200 per year depending on the current license type (i.e 10 user or unlimited). One troubleshooting session with the TAC is worth that cost.
11-03-2014 07:01 AM
So, I can still get the AnyConnect client software without a service contract, but it just won't be current version? I can't find it. When I go here to download the AnyConnect there is v5.x and v4.x and v4.x is for Linux/Mac and for v5.x it says I need service contract with login. Where do I find the older windows client download?
11-03-2014 07:34 AM
You are looking at the legacy and deprecated Cisco VPN client when you look at the version 4 and 5 software. It is used only for IKEv1 IPsec VPNs. The Windows client is still available for download (even though the End-of-Life announcement says it shouldn't be):
AnyConnect Secure Mobility Client is currently at version 3.1 (4.0 about to come out) and is a completely different software client. It is used for SSL VPN (and IKEv2 IPsec).
11-03-2014 07:38 AM
11-03-2014 01:15 PM
I contacted Cisco and turns out there aren't any versions of AnyConnect that I can get without a service contract.
11-03-2014 06:57 PM
Correct - your Smartnet on an ASA will entitle you to get the current AnyConnect client software in addition to TAC support for both the hardware and software.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide