cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1987
Views
0
Helpful
10
Replies

Help downloading anyconnect client

Andy White
Level 3
Level 3

Hello,

I want to test the Cisco Anyconenct VPN client out on a Windows PC and Mac, when I view the downlaod section there are so many clients, when 2 do I neect to pick?

Any what is the Cisco SSL VPN client?

My current license is:

Licensed features for this platform:

Maximum Physical Interfaces    : Unlimited

Maximum VLANs                  : 150

Inside Hosts                   : Unlimited

Failover                       : Active/Active

VPN-DES                        : Enabled

VPN-3DES-AES                   : Enabled

Security Contexts              : 2

GTP/GPRS                       : Disabled

SSL VPN Peers                  : 2

Total VPN Peers                : 750

Shared License                 : Disabled

AnyConnect for Mobile          : Disabled

AnyConnect for Cisco VPN Phone : Disabled

AnyConnect Essentials          : Disabled

Advanced Endpoint Assessment   : Disabled

UC Phone Proxy Sessions        : 2

Total UC Proxy Sessions        : 2

Botnet Traffic Filter          : Disabled

Does this mean I can have 750 Anyconnect VPN client connections?

Thanks

10 Replies 10

rahgovin
Level 4
Level 4

Hi Andy,

You can launch the Anyconnect client by using a browser and going to the clientless file portal page for anyconnect client. In that case you would need the .pkg files for all OS(win,mac,linux) and install it on the ASA.

An example for a win filename would be.

anyconnect-win-2.5.0217-k9.pkg

You can install and setup the anyconnect client using this guide

http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00808efbd2.shtml

Also the peers that you see are ipsec peers only. Right now, from your show version you have only 2 ssl vpn peers. You would need to purchase a license (  eg. Anyconnect essentials- for AC access only) to increase the number of peers.

A license guide is here:

http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/prod_brochure0900aecd80402e39.html

Thanks, I have a couple of questions:

  1. So the "Anyconnect" client is the Java based one like the Client VPN tool, mean we don'e have to install the VPN client on user laptops anymore?
  2. I noticed there is also a Portal page where you can public websites and use plugins like ica and rdp, if I upgrade the SSL VPN licence from 2 users to 25 this will also mean we can have 25 users shared across the portal page and using Anyconenct?
  3. What is the SSL client I thought that was the Anyconnect client (see image):

Thanks

Answers below:

1. Yes. You can go to the portal and download the client with an option of keeping it installed so that the next time on the users can directly start up the client.

2. Yes. 25 ssl vpn peers can be used for the clientless solution too. But note that if you purchase the anyconnect essentials license, it can be used only for anyconnect and not the clientless solutions(portal,plugins etc).

3. SSL vpn client is the older version of the Anyconnect client ( for ASA 7.x version). It has fewer features too.

Thanks,

  1. Does the SSL certificate get created on the ASA or do I have to buy one from say Versign?
  2. Can I create different profiles like on the Cisco VPN client for the Anyconnect or clientless options, so if a sales user logs in they get different access to IT?

Regards

1. Both are acceptable. Jut that in case of using a third prty certificate(well known CA), it will be trusted by the end user and you wont get that certificate not trusted error each time you connect.

2. Yes you can create different profiles and use for the AnyConnect clients. But they are a bit different from the IPSEC client. They can be pushed from the ASA when you connect to a particular group-policy. The guide is here.

http://www.cisco.com/en/US/docs/security/vpn_client/anyconnect/anyconnect25/administration/guide/ac03features.html#wp1228114

Thanks,

1.) I guess the self cert of official one are as good as each other, do I have to create the self cert or is this done automatically?

2.) I guess these VPN modes may allow someone with an iPad or Dell's Android streak to connect securely, as we have a few important internal websites we want to allow remote users to access?

Regards

1) You don need to create a cert at all. Automatically when webvpn is enabled a cert is generated but you wont be able to see that on the ASA. But you can create a self signed cert with the right dns name of the ASA and import the cert to the cleint machine( or install) so that you can avoid the cert not trusted errors.

2) Not sure what you mean by vpn modes.Ipad is ok to use but you need a special app to use that.

http://itunes.apple.com/us/app/cisco-anyconnect/id392790924?mt=8

I don think the there is an anyconnect android app yet that can be used.

Looks like I am spoilt for choice to allow users to securely access our confidential websites remotely, just choosing the right one, my head hurts. I guess I must try and get the group policy right for this to all work, hopefully I can do all this from the asdm gui?

We use windows Active Directory and have a windows IAS radius server too, hopefully I can still use these to control what type of access each user gets.

Yes its easier to use the asdm gui for all this. And once connected the anyconnect client is similar to ipsec client, you have to have the right nat rules and all.

And yes, you can use the IAS radius server to authentciate and authorize the anyconnect vpn users without any problem.

Please mark the post as answered if you have got your queries resolved.

Thanks

Hi,

  1. Few last thing what is the secure desktop option I've seen on the ASDM?
  2. And how can I create a new self cert on the ASA to use our DNS name?
  3. http://www.youtube.com/watch?v=pP1uteL7Z8c  - Is this tool covered in the SSL licence or do we need to enable the "AnyConnect for Mobile" option too?

Thanks