06-25-2013 07:48 PM - edited 02-21-2020 06:59 PM
I am currently using Cisco VPN client 5.x on Windows to conenct to Cisco VPN concentrator. First I connect to VPN client and then login to windows domain using the domain login features.
Now I am loking for the new replacement client "Anyconnect" and evaluating the software "Anyconnect Secure Mobility Client"
This software looks like a pure SSL VPN client, I could find the option to create a profile for specifying domain, group etc.
What software do I need to get in order to support my requirements?
Thanks
Solved! Go to Solution.
06-26-2013 06:55 AM
Are you talking about the old Cisco VPN concentrator? It doesn't support AnyConnect.
Michael
Please rate all helpful posts
06-30-2013 10:23 PM
You may predeploy anyconnect with any module (including SBL), using msi package (for Windows). Those packages include anyconnect VPN client itself, plus all the modules available. When you install it, you may enable it (SBL) from the client PC directly, or using anyconnect profile (.xml file) downloaded from ASA, where it was configured properly.
08-12-2013 12:46 AM
a) If you don't predeploy the image, you have to setup WebVPN portal page where users login via browser and install the image. AnyConnect supports "only" IKEv2 which depends on certificate, so this is a must
b) Sure!
Michael
Please rate all helpful posts
06-26-2013 06:55 AM
Are you talking about the old Cisco VPN concentrator? It doesn't support AnyConnect.
Michael
Please rate all helpful posts
06-26-2013 03:20 PM
I am not tryingto use it with Cisco VPN concentrator. I am just exploring the new anyconnect client features. On
"Anyconnect Secure Mobility Client" where can I configure the profiles, group name, Windows domain login options etc..
06-26-2013 11:23 PM
This is configured centrally on the ASA. Chosing groups can be done via dropdown list on the client, specifying group within the conncet link, or via certificate attributes.
Michael
Please rate all helpful posts
06-27-2013 02:52 AM
I am using the "Anyconnect Secure Mobility Client" I dont find the option to specify group name/password/domain authentication etc. At one place I only have the option to specify the VPN server.
When I press ALT+CTL+DEL on my Windows PC, the VPN client should pop up, connect to the VPN ASA and then login to the domain. How can I setup this with the "Anyconnect Secure Mobility Client"
06-27-2013 03:20 AM
I guess you should user start-before-login module/feature of anyconnect client for the PC to be able to vpnconnect first and then register with the AD. What modules will be downloaded to the client from server is controlled in hte Group-policy/Advanced/Anyconnect Client/Optional client modules to download. There you should choose Anyconnect SBL (Image with all the modules should be in the ASA's flash). Plus, in the anyconnect client profile, you should check the box "Use start before login".
For the part, regarding authentication, if you're looking where to specify group/password - it's not applicable to the sslvpn, cause there's no such thing as group authentication. That was only applicable for IKE. Group selection is done as ciscomax said, "via dropdown list on the client, specifying group within the conncet link, or via certificate attributes". So, if you configured group-url like https://serverIP/webvpngroup1 (Settings done in the connection-profile tab if using ASDM), you should specify exactly this url, when connecting from the client PC. Server will know, that if you're using this link, it should associate the client with the tunnel group, for wich this group-url was specified.
06-30-2013 07:30 PM
That means, the "Start Before Login" can only be enabled from the ASA side?
In such a case whoever wants to use the VPN client, for the first time require to login to the domain (may be using cached credentials), connect to VPN server and then use this "Start Before Login" feature for future logins.
In the above case, let's assume the PC is at the remote location and the user never logged into the PC (domain) even once. How can we address this issue?
06-30-2013 10:23 PM
You may predeploy anyconnect with any module (including SBL), using msi package (for Windows). Those packages include anyconnect VPN client itself, plus all the modules available. When you install it, you may enable it (SBL) from the client PC directly, or using anyconnect profile (.xml file) downloaded from ASA, where it was configured properly.
08-12-2013 12:30 AM
a) When we setup Anyconnect VPN, how do clients get's the anyconnect imaage? What needs to be enabled in order to get the image from the ASA to the client? Is it both IPSec & SSL? Why is that device certificate is must for IPSec?
b) Are the ACL's for the anyconnect group stateful?
08-12-2013 12:46 AM
a) If you don't predeploy the image, you have to setup WebVPN portal page where users login via browser and install the image. AnyConnect supports "only" IKEv2 which depends on certificate, so this is a must
b) Sure!
Michael
Please rate all helpful posts
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide