Any Connect VPN Client Configuration Guide
During the early development period of SSL VPNs, network administrators needed a VPN client that had similar benefits of an IPsec remote access VPN client, but required less administrative overhead than installing and maintaining the IPsec VPN client. To accommodate those requirements, the idea of a full tunnel SSL VPN client emerged. In the pre-version 8.0 releases, Cisco provided the SSL VPN Client (SVC). This is a self-downloading, self-installing, self-configuring, and self-uninstalling VPN that offers all benefits that are currently available in the Cisco IPsec client. However, in version 8.0 or later versions of Cisco ASA, Cisco introduced a newer SSL VPN client called Cisco AnyConnect VPN Client. The AnyConnect VPN clients leverage the SSL encryption engine that is already present on the client computer. If you currently use the pre-version 8.0 of code on the security appliances and have SVC clients deployed, test the AnyConnect in a lab environment first before upgrading the code to version 8.0 or higher of the software. Table 5-6 discusses the differences between the SVC and AnyConnect VPN clients. If you decide that the AnyConnect VPN Client will be beneficial in your environment, you can plan to upgrade your security appliance to version 8.x of the code by thoroughly testing it in the lab environment first.
Table 5-6 Contrasting SVC and AnyConnect
|
Feature |
SVC |
AnyConnect |
|
Operating system support |
Supported in Windows XP and Windows 2000 |
Supported in Windows Vista (both 32-and 64-bit), Windows XP, Windows 2000, Mac OS X (version 10.4 or 10.5), and Red Hat Linux (version 9 or higher) |
|
DTLS with SSL connections |
Not supported |
Fully supported |
|
Package size |
Approximately 400 KB |
Approximately 1.2 MB |
|
Administrative rights |
Required to install and upgrade the package |
Required to install the package initially; no administrative privileges are required subsequently |
|
Platform support |
Supported on VPN 3000, Cisco IOS routers, and Cisco ASA |
Only supported on Cisco ASA and IOS routers |
|
Start before login |
Not supported |
Supported on Windows 2000 and Windows XP systems |
|
IPv6 support |
Not supported |
Supported on Windows XP SP2 and Windows Vista |
|
Standalone connection |
Requires SVC to be downloaded from Cisco ASA through a web browser |
Can be installed as a standalone application or through a web browser |
Because versions 8.x of code solely support the AnyConnect VPN Client, we only discuss AnyConnect in this chapter.
NOTE If you use 64-bit (x64) platforms, Cisco provides support only through the Cisco
AnyConnect VPN Client. Cisco AnyConnect VPN Client supports both Windows XP as well as Windows Vista x64 platforms. Cisco currently does not have plans to provide support for 64-bit platforms for the Cisco IPsec VPN Client or even the Cisco SSL VPN Client (SVC).
The AnyConnect VPN Client can be installed on a user's computer using one of these two methods:
• Web-enabled mode: In this method, the client is downloaded to a user computer through a browser. The user opens a browser and references the IP address or the FQDN of Cisco ASA to establish an SSL VPN tunnel. The user is presented with the standard SSL VPN logon page and is prompted for credentials. If credentials are valid, users are allowed to log in, and if they are using Internet Explorer, they are prompted to download the client using ActiveX. Otherwise, they are prompted to start it manually through the AnyConnect link. If ActiveX fails, the browser tries to download the client through Java. If either ActiveX or Java is successful, the client is downloaded and installed. After it is installed, it tries to connect to the security appliance and establishes an SSL VPN tunnel.
• Standalone mode: In this method, the client is downloaded as a standalone application from a file server or directly from the Cisco Systems website. The Microsoft Software Installer (MSI) installed is executed to install the client to the workstation. If the client is not preconfigured, the user needs to specify the IP address or FQDN of the security appliance, the tunnel group to connect to, the username, and the associated password.
NOTE If you receive the following message, you need to copy MSVCP60.dll and MSVCRT.dll into the system32 directory. Please consult the Microsoft's article KB259403 for more information.
The required system DLL filename is not present on the system.
The configuration of AnyConnect VPN Client is a two-step process:
Step 1 Loading the SVC package
Step 2 Defining AnyConnect VPN Client attributes
Continue reading here: Enabling Any Connect VPN Client Functionality
Was this article helpful?