cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
15060
Views
20
Helpful
8
Replies

Does the AnyConnect Client reveal your IP address to wherever it connects?

Ishyster
Level 1
Level 1

I'm not familiar with the AnyConnect VPN software, but I'm familiar with other VPN software that can hide/spoof your IP and make it look like you are in another state or even another country. I assume this is because wherever you connect checks you IP and knows exactly your region/country/location and even your ISP provider.

I have been doing some work recently where we connect to a VPN with the AnyConnect Client in order to make the server or wherever we connect to believe we are in another location; now this gives us access to the intranet where before we could only access it in a building located in a whole other region. From there once we are connected to the intranet we can work as normal using another app to work from a Virtual Desktop. Previously we would have to access the intranet from inside the Virtual Desktop so this can slow things down with numerous people using the intranet.

Now I don't know if Cisco has some software server that they provide for AnyConnect Client users, but my question now is when I connect to the server in order to access the intranet does the server now know my IP address, ISP, and my exact location/Region? Does AnyConnect share this information with wherever it connects or if it connect to its own server software?

Will this organization now have all my information?

8 Replies 8

Marvin Rhoads
Hall of Fame
Hall of Fame

AnyConnect clients' public IP addresses are available to the remote system to which they connect when they establish the VPN. What (if anything) the administrator of that system does with that information is up to them, just as it is with the type of VPN systems that you describe.

Usually their goal is to provide business-related remote access, not to mine data about who you are and where you're coming from - unless that's required for compliance or other reasons on their end.

 

So is there anyway to mask my IP or Spoof my IP so the server does not have it or my location? I know this typically is done with other VPN software, but to my knowledge two VPN clients cannot work at the same time on the same computer. It's beginning to seem that if I don't want to reveal my info/location, I just won't be accessing the intranet unless its through the Virtual Desktop. Am I understanding this correctly or is there another option?

No you cannot spoof your IP address when connecting to a corporate VPN. If you could it would pretty much invalidate one of the main purposes of having a VPN in the first place - to protect the data end to end from an authenticated and authorized user to the corporate assets. Putting some box in the middle that terminates the connection and re-encapsulates it would expose the data in transit thus making the Virtual Private Network not so Private.

But what if the router iam connected to for Internet has a vpn installed on it?

The router VPN just masks the endpoint address while it is in transit to wherever that VPN ends. At some point your traffic leaves that VPN en route to to place your AnyConnect client is connecting. There your true IP address will become known.

Hi Marvin,

 

I have a couple of queries:

1. If I’m using a VPN router (ExpressVPN) can I still use Cisco Anyconnect on my corporate laptop? Will this work?

 

2. Is there a way that Cisco VPN can identify that I’m using a VPN router ?

 

3. if I’ve set / location the location on my VPN router to “X” but physically present in “Y” is there anyway for Cisco Anyconnect to identify my actual location I.e. “Y” ?

Using a third party VPN client such as Express VPN on top of AnyConnect may work with some configuration sand not with others.

If it works, the AnyConnect head end (firewall or router) would see the source IP address reported by Express VPN and not your actual IP address and associated location.

Doing so might violate the acceptable use policy of the corporate system so be careful to check that is not the case for you before doing this. There may be legal or HR implications is it is a violation.

Thanks for your swift reply!

 

but not clear on your response to Question #1.

if the setup is to work what changes / configuration settings must I amend ?

 

many thanks once again !