12-20-2010 06:47 AM - edited 02-21-2020 05:02 PM
Hello,
I want to test the Cisco Anyconenct VPN client out on a Windows PC and Mac, when I view the downlaod section there are so many clients, when 2 do I neect to pick?
Any what is the Cisco SSL VPN client?
My current license is:
Licensed features for this platform:
Maximum Physical Interfaces : Unlimited
Maximum VLANs : 150
Inside Hosts : Unlimited
Failover : Active/Active
VPN-DES : Enabled
VPN-3DES-AES : Enabled
Security Contexts : 2
GTP/GPRS : Disabled
SSL VPN Peers : 2
Total VPN Peers : 750
Shared License : Disabled
AnyConnect for Mobile : Disabled
AnyConnect for Cisco VPN Phone : Disabled
AnyConnect Essentials : Disabled
Advanced Endpoint Assessment : Disabled
UC Phone Proxy Sessions : 2
Total UC Proxy Sessions : 2
Botnet Traffic Filter : Disabled
Thanks
12-20-2010 07:43 AM
Hi Andy,
You can launch the Anyconnect client by using a browser and going to the clientless file portal page for anyconnect client. In that case you would need the .pkg files for all OS(win,mac,linux) and install it on the ASA.
An example for a win filename would be.
anyconnect-win-2.5.0217-k9.pkg
You can install and setup the anyconnect client using this guide
http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00808efbd2.shtml
Also the peers that you see are ipsec peers only. Right now, from your show version you have only 2 ssl vpn peers. You would need to purchase a license ( eg. Anyconnect essentials- for AC access only) to increase the number of peers.
A license guide is here:
12-20-2010 08:21 AM
Thanks, I have a couple of questions:
Thanks
12-20-2010 08:27 AM
Answers below:
1. Yes. You can go to the portal and download the client with an option of keeping it installed so that the next time on the users can directly start up the client.
2. Yes. 25 ssl vpn peers can be used for the clientless solution too. But note that if you purchase the anyconnect essentials license, it can be used only for anyconnect and not the clientless solutions(portal,plugins etc).
3. SSL vpn client is the older version of the Anyconnect client ( for ASA 7.x version). It has fewer features too.
12-20-2010 08:30 AM
Thanks,
Regards
12-20-2010 08:39 AM
1. Both are acceptable. Jut that in case of using a third prty certificate(well known CA), it will be trusted by the end user and you wont get that certificate not trusted error each time you connect.
2. Yes you can create different profiles and use for the AnyConnect clients. But they are a bit different from the IPSEC client. They can be pushed from the ASA when you connect to a particular group-policy. The guide is here.
12-20-2010 09:32 AM
Thanks,
1.) I guess the self cert of official one are as good as each other, do I have to create the self cert or is this done automatically?
2.) I guess these VPN modes may allow someone with an iPad or Dell's Android streak to connect securely, as we have a few important internal websites we want to allow remote users to access?
Regards
12-20-2010 09:52 AM
1) You don need to create a cert at all. Automatically when webvpn is enabled a cert is generated but you wont be able to see that on the ASA. But you can create a self signed cert with the right dns name of the ASA and import the cert to the cleint machine( or install) so that you can avoid the cert not trusted errors.
2) Not sure what you mean by vpn modes.Ipad is ok to use but you need a special app to use that.
http://itunes.apple.com/us/app/cisco-anyconnect/id392790924?mt=8
I don think the there is an anyconnect android app yet that can be used.
12-20-2010 10:02 AM
Looks like I am spoilt for choice to allow users to securely access our confidential websites remotely, just choosing the right one, my head hurts. I guess I must try and get the group policy right for this to all work, hopefully I can do all this from the asdm gui?
We use windows Active Directory and have a windows IAS radius server too, hopefully I can still use these to control what type of access each user gets.
12-20-2010 11:11 AM
Yes its easier to use the asdm gui for all this. And once connected the anyconnect client is similar to ipsec client, you have to have the right nat rules and all.
And yes, you can use the IAS radius server to authentciate and authorize the anyconnect vpn users without any problem.
Please mark the post as answered if you have got your queries resolved.
Thanks
12-21-2010 12:55 AM
Hi,
Thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide