02-27-2024 06:29 PM
Hi all,
We are trying to move away from Cisco ASA to FTD and part of that is to migrate the Anyconnect VPN as well.
The current client versions being used are version 4.0 and 4.5 (on 2 different VPN concentrators).
What is the best method to upgrade the anyconnect client to let's say version 4.10.x or 5.x without being very disruptive to user experience.
the new FTD are version 7.2.5
Thanks in Advance,
V
Solved! Go to Solution.
02-28-2024 03:54 AM
@varrao I've not read any minimum version that is required. I would manually test an upgrade from AC 4.0 and 4.5 to confirm no issues in your environment prior to automating the upgrade.
The old AC clients may not support the strongest crypto that the FTD 7.2 would support. So you may need to ensure you run the older weaker crypto so those clients can connect and download SC 5.x, or pre-upgrade them before they connect.
Something to be aware of Secure Client is not supported on ASA versions older than 9.14, so depending on your old ASA version if the client was upgraded you may not be able to connect to the old ASA again.
02-28-2024 12:08 AM
@varrao upgrading AnyConnect to Secure Client is the same as before, either upload Secure Client 5.x to the FTD headend and once the users authenticate they will automatically upgrade or pre-deploy using your Network Management software solution such as SCCM or MDM.
I would not upgrade to AnyConnect 4.10, there will be no further patches or software maintainence updates for AnyConnect 4.x from March 31st 2024.
02-28-2024 03:11 AM
Hi Rob,
Thanks for taking out time to repsond.
Yeah that make sense, I am only conscious of upgrading the end-user client from 4.0 to straight 5.x, hope there is not strict intermediary steps like other Cisco upgrades?
Regards, V
02-28-2024 03:54 AM
@varrao I've not read any minimum version that is required. I would manually test an upgrade from AC 4.0 and 4.5 to confirm no issues in your environment prior to automating the upgrade.
The old AC clients may not support the strongest crypto that the FTD 7.2 would support. So you may need to ensure you run the older weaker crypto so those clients can connect and download SC 5.x, or pre-upgrade them before they connect.
Something to be aware of Secure Client is not supported on ASA versions older than 9.14, so depending on your old ASA version if the client was upgraded you may not be able to connect to the old ASA again.
03-02-2024 06:10 PM
Hi Rob,
Thanks for your response, I think that will be a very important consideration. We might not be able to rollback due to encryption mismatches and will have to move by fixing forward.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide