cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6050
Views
10
Helpful
6
Replies

Updating AnyConnect Client On Remote Users

errMsg
Level 1
Level 1

I have a situation where I need to update the anyconnect client on 1000 remote users.  I am not finding an easy way to do this because the only way to push the new client requires the the computers to be connected to the VPN and if we push the client upgrade while they are on the VPN it will disconnect the VPN.  This is the proverbial "Catch 22".  

Im looking for any suggestions to update the anyconnect client while the computer is connected to the anyconnect client.

6 Replies 6

balaji.bandi
Hall of Fame
Hall of Fame

below guide should help :

 

https://www.petenetlive.com/KB/Article/0000704

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hi,

If you upload the new AnyConnect package to the VPN headend (ASA or FTD) the client will auto-upgrade upon connection and then establish the VPN tunnel after upgrading. This is one of the most common methods to upgrade, the downside is it will upgrade all computers upon connecting to the VPN - you cannot control which users/computers receive the upgrade.

 

If you use Umbrella service and have the AnyConnect Umbrella Roaming Security Client in addtion to the VPN client, then this can auto-upgrade anyconnect (all modules) without having to be connected to a VPN, it just requires an internet connection.

 

Ultimately there will be some interruption during the upgrade, it's down to your organisation to determine what best fits in your environment.

 

HTH

What about admin rights for users?

Admin rights are not required when upgrading the client, admin rights are only required for the initial install.

Interesting,

 

In the past I remember we had some problems while upgrading Anyconnect through the firewall due to admin rights, we ended up upgrading them via SCCM.

 

When I have time I will try that again

Michael Braun
Level 1
Level 1

Hi Guys,

 

i would be careful with the ASA pushed install. We tried, had numerous problems with either the old client not to uninstall correctly or the new one not wanting to install.

We ended up with a broken uninstall and half of an install of the new one.

Effectively a manual clean up of registry and folders was needed to get rid of the broken remains following a clean install with admin rights. (it was not possible to just install after the broken upgrade, always came with an error during install - thus the cleanup)

This occurred from 4.6 as a base, upgrade to 4.7 and 4.8 same issue. I would not exclude potential install problems due to "security software" such as anti-virus or other vendor pre-installed software causing the install to fail. (HP e.g.)

In the end we stopped the push from the ASA and manually upgraded individual clients - painful but better than a failing client and them not being able to connect to HQ (especially now with all the home office workers)

 

Good Luck!

 

Markus