Any Connect VPN Client Configuration Guide

During the early development period of SSL VPNs, network administrators needed a VPN client that had similar benefits of an IPsec remote access VPN client, but required less administrative overhead than installing and maintaining the IPsec VPN client. To accommodate those requirements, the idea of a full tunnel SSL VPN client emerged. In the pre-version 8.0 releases, Cisco provided the SSL VPN Client (SVC). This is a self-downloading, self-installing, self-configuring, and self-uninstalling VPN that offers all benefits that are currently available in the Cisco IPsec client. However, in version 8.0 or later versions of Cisco ASA, Cisco introduced a newer SSL VPN client called Cisco AnyConnect VPN Client. The AnyConnect VPN clients leverage the SSL encryption engine that is already present on the client computer. If you currently use the pre-version 8.0 of code on the security appliances and have SVC clients deployed, test the AnyConnect in a lab environment first before upgrading the code to version 8.0 or higher of the software. Table 5-6 discusses the differences between the SVC and AnyConnect VPN clients. If you decide that the AnyConnect VPN Client will be beneficial in your environment, you can plan to upgrade your security appliance to version 8.x of the code by thoroughly testing it in the lab environment first.

Table 5-6 Contrasting SVC and AnyConnect

Feature

SVC

AnyConnect

Operating system support

Supported in Windows XP and Windows 2000

Supported in Windows Vista (both 32-and 64-bit), Windows XP, Windows 2000, Mac OS X (version 10.4 or 10.5), and Red Hat Linux (version 9 or higher)

DTLS with SSL

connections

Not supported

Fully supported

Package size

Approximately 400 KB

Approximately 1.2 MB

Administrative rights

Required to install and upgrade the package

Required to install the package initially; no administrative privileges are required subsequently

Platform support

Supported on VPN 3000, Cisco IOS routers, and Cisco ASA

Only supported on Cisco ASA and IOS routers

Start before login

Not supported

Supported on Windows 2000 and Windows XP systems

IPv6 support

Not supported

Supported on Windows XP SP2 and Windows Vista

Standalone connection

Requires SVC to be downloaded from Cisco ASA through a web browser

Can be installed as a standalone application or through a web browser

Because versions 8.x of code solely support the AnyConnect VPN Client, we only discuss AnyConnect in this chapter.

NOTE If you use 64-bit (x64) platforms, Cisco provides support only through the Cisco

AnyConnect VPN Client. Cisco AnyConnect VPN Client supports both Windows XP as well as Windows Vista x64 platforms. Cisco currently does not have plans to provide support for 64-bit platforms for the Cisco IPsec VPN Client or even the Cisco SSL VPN Client (SVC).

The AnyConnect VPN Client can be installed on a user's computer using one of these two methods:

• Web-enabled mode: In this method, the client is downloaded to a user computer through a browser. The user opens a browser and references the IP address or the FQDN of Cisco ASA to establish an SSL VPN tunnel. The user is presented with the standard SSL VPN logon page and is prompted for credentials. If credentials are valid, users are allowed to log in, and if they are using Internet Explorer, they are prompted to download the client using ActiveX. Otherwise, they are prompted to start it manually through the AnyConnect link. If ActiveX fails, the browser tries to download the client through Java. If either ActiveX or Java is successful, the client is downloaded and installed. After it is installed, it tries to connect to the security appliance and establishes an SSL VPN tunnel.

• Standalone mode: In this method, the client is downloaded as a standalone application from a file server or directly from the Cisco Systems website. The Microsoft Software Installer (MSI) installed is executed to install the client to the workstation. If the client is not preconfigured, the user needs to specify the IP address or FQDN of the security appliance, the tunnel group to connect to, the username, and the associated password.

NOTE If you receive the following message, you need to copy MSVCP60.dll and MSVCRT.dll into the system32 directory. Please consult the Microsoft's article KB259403 for more information.

The required system DLL filename is not present on the system.

The configuration of AnyConnect VPN Client is a two-step process:

Step 1 Loading the SVC package

Step 2 Defining AnyConnect VPN Client attributes

Continue reading here: Enabling Any Connect VPN Client Functionality

Was this article helpful?

0 0