cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1049
Views
5
Helpful
6
Replies

VPN Type to use With Windows RDP Client

beatinger
Level 1
Level 1

I am using a Cisco ASA5540 firewall, and I would like to know which VPN solution would be the ideal choice for using RDP to remove into a Windows 2019 Server.  There are three different types under the VPN Wizard, in the ADSM, and I am not sure which one would be best or appropriate to use.  I am thinking that the configuration which uses the AnyConnect Client is the way to go, but need advice.  Thank you very much!

6 Replies 6

johnd2310
Level 8
Level 8

Hi,

What license do you have your ASA firewall? The license will tell you how many anyconnect peers you can have. If you don't have enough anyconnect, you can use the ipsec vpn.

 

Thanks

John

**Please rate posts you find helpful**

 

Hello John,

 

It appears that I have 10 AnyConnect Premium Peers, so this is plenty for us:

 

ciscoasa5540(config)# show version

Cisco Adaptive Security Appliance Software Version 9.1(7)32
Device Manager Version 7.8(2)151

Compiled on Tue 04-Sep-18 08:37 by builders
System image file is "disk0:/asa917-32-k8.bin"
Config file at boot was "startup-config"

ciscoasa5540 up 11 days 13 hours

Hardware: ASA5540-K8, 2560 MB RAM, CPU Pentium 4 2000 MHz,
Internal ATA Compact Flash, 256MB
BIOS Flash AT49LW080 @ 0xfff00000, 1024KB

Encryption hardware device : Cisco ASA-55xx on-board accelerator (revision 0x0)
Boot microcode : CN1000-MC-BOOT-2.00
SSL/IKE microcode : CNlite-MC-SSLm-PLUS-2.08
IPSec microcode : CNlite-MC-IPSECm-MAIN-2.09
Number of accelerators: 1

0: Ext: GigabitEthernet0/0 : address is 001a.2f94.4f56, irq 9
1: Ext: GigabitEthernet0/1 : address is 001a.2f94.4f57, irq 9
2: Ext: GigabitEthernet0/2 : address is 001a.2f94.4f58, irq 9
3: Ext: GigabitEthernet0/3 : address is 001a.2f94.4f59, irq 9
4: Ext: Management0/0 : address is 001a.2f94.4f55, irq 11
5: Int: Internal-Data0/0 : address is 0000.0001.0002, irq 11
6: Int: Internal-Control0/0 : address is 0000.0001.0001, irq 5

Licensed features for this platform:
Maximum Physical Interfaces : Unlimited perpetual
Maximum VLANs : 200 perpetual
Inside Hosts : Unlimited perpetual
Failover : Active/Active perpetual
Encryption-DES : Enabled perpetual
Encryption-3DES-AES : Enabled perpetual
Security Contexts : 2 perpetual
GTP/GPRS : Disabled perpetual
AnyConnect Premium Peers : 10 perpetual
AnyConnect Essentials : Disabled perpetual
Other VPN Peers : 5000 perpetual
Total VPN Peers : 5000 perpetual
Shared License : Disabled perpetual
AnyConnect for Mobile : Disabled perpetual
AnyConnect for Cisco VPN Phone : Disabled perpetual
Advanced Endpoint Assessment : Disabled perpetual
UC Phone Proxy Sessions : 2 perpetual
Total UC Proxy Sessions : 2 perpetual
Botnet Traffic Filter : Disabled perpetual
Intercompany Media Engine : Disabled perpetual
Cluster : Enabled perpetual

This platform has an ASA 5540 VPN Premium license.

Serial Number: JMX1112L1JH
Running Permanent Activation Key: 0x133c6c4f 0x3cca370e 0x9882a598 0x897810c8 0x0a2c0289
Configuration register is 0x1
Configuration last modified by enable_15 at 09:33:39.966 UTC Wed Aug 5 2020
ciscoasa5540(config)#

 

So, you would recommend using the AnyConnect client on the remote Windows 10 desktop where the RDP session is being initiated?

Hi,

 

Yes, go ahead and use the anyconnect.

 

Thanks

John

**Please rate posts you find helpful**

I have preferred ASDM GUI to configure. It can auto-generate AnyConnect VPN Profile in XML format, (such profile feature are auto re-connect, client controlled by remote desktop etc.)

Otherwise using profile editor Cisco AnyConnect Secure Mobility Client Administrator Guide, Release 4.0  

Wizard->VPN Wizard->AnyConnect Wizard...

image.png

 

Okay, so I am having some additional issues with the implementation of VPN on our Cisco 5540 firewall.  I tried to locate and download the AnyConnect client for the Windows 10 desktop computers, and I found that there is something offered by Microsoft Store, which I installed on my Windows 10 computer, but have no idea how it works.  It literally installed as part of the OS.  So I was wondering where I could obtain the actual Cisco AnyConnect client.  I cannot seem to be able to find it on the Internet, via Google searches.  Any ideas?

Hi, You download the vpn client from the Cisco software download website. https://software.cisco.com/download/home Thanks John
**Please rate posts you find helpful**