Cisco announced the general release of the Cisco AnyConnect client for the iPhone. While I think it is cool that Cisco has released this finally I am a bit flabbergasted at the licensing they are doing on the ASA - yet again. Not only do you need AnyConnect Essentials or Premium license but it will require the AnyConnect for Mobile license also. I still don't understand why Cisco feels the need to do this and it is frustrating when trying to sell the ASA platform to have to address each one of the licensing requirements for features that many expect from the base AnyConnect Essentials license. It makes you want to stick with the inbuilt IPSec client solutions regardless of the feature enhancements.
If you do a show version on your ASA you can see what your current license status is, the output should look like:
ASA#show version
(...)
Licensed features for this platform:
Maximum Physical Interfaces : Unlimited
Maximum VLANs : 50
Inside Hosts : Unlimited
Failover : Disabled
VPN-DES : Enabled
VPN-3DES-AES : Enabled
Security Contexts : 0
GTP/GPRS : Disabled
SSL VPN Peers : 2
Total VPN Peers : 250
Shared License : Disabled
AnyConnect for Mobile : Disabled
AnyConnect for Cisco VPN Phone : Disabled
AnyConnect Essentials : Disabled
Advanced Endpoint Assessment : Disabled
UC Phone Proxy Sessions : 2
Total UC Proxy Sessions : 2
Botnet Traffic Filter : Disabled
So note that you will need the AnyConnect Essentials or AnyConnect Premium (SSL VPN Peers) license plus the AnyConnect for Mobile to have a working solution. Some product overview information is available here, the link might require CCO logon access.
- Ed
Showing posts with label Cisco AnyConnect. Show all posts
Showing posts with label Cisco AnyConnect. Show all posts
Wednesday, September 22, 2010
Cisco ASA - AnyConnect for iPhone released
Tuesday, September 21, 2010
Cisco ASA - AnyConnect 3.0 features
Cisco has announced new features for AnyConnect 3.0 and will finally be supporting both IPSec VPN and SSL VPN in a single client. They have outlined some interesting things like using RDP to launch AnyConnect, IPv6 VPN access, captive portal detection and auto reconnect. All things that make AnyConnect much more useful and easier for end users to use VPN all the time.
It seems that Cisco is taking seriously Microsoft's DirectAccess solution given the features they are putting into AnyConnect. In addition, they are making the client available for platforms that Microsoft can't support such as the Apple iPad and iPhone. They are also making AnyConnect able to leverage a split VPN connectivity option to take advantage of their ScanSafe cloud security solution so that might give folks more options in terms of offloading posture assessment of VPN clients.
I still think that Microsoft's DirectAccess is an impressive solution for Win7/Server 2008R2 shops that want to provide their end users a remarkable VPN experience. You can tell the difference of something that is made from the ground up in a product and integrated so tightly in the operating system that the experience becomes seamless. The downside is that there are often shortcoming in flexibility in the number of scenarios you can deploy the solution.
I think Cisco's AnyConnect is a great solution in terms of the flexibility it offers while still providing a strong set of capabilities. I just wish a lot of these features had come out in the 1.x release instead of having to wait this long. I special note is the IPSec support in a single client - that has been an issue since AnyConnect was first launched.
- Ed
It seems that Cisco is taking seriously Microsoft's DirectAccess solution given the features they are putting into AnyConnect. In addition, they are making the client available for platforms that Microsoft can't support such as the Apple iPad and iPhone. They are also making AnyConnect able to leverage a split VPN connectivity option to take advantage of their ScanSafe cloud security solution so that might give folks more options in terms of offloading posture assessment of VPN clients.
I still think that Microsoft's DirectAccess is an impressive solution for Win7/Server 2008R2 shops that want to provide their end users a remarkable VPN experience. You can tell the difference of something that is made from the ground up in a product and integrated so tightly in the operating system that the experience becomes seamless. The downside is that there are often shortcoming in flexibility in the number of scenarios you can deploy the solution.
I think Cisco's AnyConnect is a great solution in terms of the flexibility it offers while still providing a strong set of capabilities. I just wish a lot of these features had come out in the 1.x release instead of having to wait this long. I special note is the IPSec support in a single client - that has been an issue since AnyConnect was first launched.
- Ed
Friday, March 19, 2010
Cisco IPSec VPN Client - 5.0.7 BETA - Win7 64-bit support
Cisco has a beta version of the IPSec VPN Client out, version 5.0.7 BETA (vpnclient-winx64-msi-5.0.07.0240-k9-BETA.exe) available for download. It appears they got the message about the need for a 64-bit version of the IPSec client for Windows 7! It is available for download on CCO but requires a valid CCO login and current contract to get the code.
This is great news for Microsoft customers that have Cisco ASA's, PIX's or VPN 3000 concentrators deployed and their IT team is migrating their client OS's to Windows 7. Many OEM's are shipping the default OS as Windows 7 64-bit to take advantage of the all the RAM systems can support today.
Cisco is still pushing their AnyConnect client + ASA platform to compete with Microsoft's DirectAccess solution on Forefront UAG. Cisco is positioning the AnyConnect client as an always ready vpn client that auto-reconnects and is seamless in that process. I don't know if I am buying that position given the flexibility of what DirectAccess can do and how you can manage the policies with GPO's in AD in the Microsoft solution. Plus the fact that once DirectAccess is deployed there is no VPN "client" per-say, it is more of a policy function which is a very unique position in terms of product positioning.
At least if you have a Cisco IPSec solution deployed today you can now leverage it with Windows 7 without requiring any third party software to get around the problem of being on a 64-bit OS.
- Ed
This is great news for Microsoft customers that have Cisco ASA's, PIX's or VPN 3000 concentrators deployed and their IT team is migrating their client OS's to Windows 7. Many OEM's are shipping the default OS as Windows 7 64-bit to take advantage of the all the RAM systems can support today.
Cisco is still pushing their AnyConnect client + ASA platform to compete with Microsoft's DirectAccess solution on Forefront UAG. Cisco is positioning the AnyConnect client as an always ready vpn client that auto-reconnects and is seamless in that process. I don't know if I am buying that position given the flexibility of what DirectAccess can do and how you can manage the policies with GPO's in AD in the Microsoft solution. Plus the fact that once DirectAccess is deployed there is no VPN "client" per-say, it is more of a policy function which is a very unique position in terms of product positioning.
At least if you have a Cisco IPSec solution deployed today you can now leverage it with Windows 7 without requiring any third party software to get around the problem of being on a 64-bit OS.
- Ed
Saturday, November 28, 2009
Cisco AnyConnect Client
For those that are still using the older AnyConnect Client there are several reasons to upgrade to the newer 2.4.0202 release or at a minimum the 2.3.2016 release. The 2.3.2016 fixed some issues with passcode vs password prompts within the Client windows when logging in. If you are using RSA SecurID I would recommend moving to 2.3.2016 or 2.4.0202 to avoid the sort of confusion the older client presents for end users.
The release notes for AnyConnect 2.4.0202 are here. Note that this version officially supports Microsoft Windows 7 32 and 64 bit and Apple OS X 10.6 and 10.6.1 both 32 and 64 bit.
One of the more interesting features they added was the Trusted Network Detection (TND) which in essence allows the AnyConnect client to determine when it is already on a trusted network and disconnect from the VPN or if it is NOT on a trusted network to initiate the VPN connection. I think this feature might need a bit of time before it works out all the kinks but it looks promising. I see it as an attempt by Cisco to address the unique abilities of Microsoft's DirectAccess feature without having to engineer anything new.
- Ed
The release notes for AnyConnect 2.4.0202 are here. Note that this version officially supports Microsoft Windows 7 32 and 64 bit and Apple OS X 10.6 and 10.6.1 both 32 and 64 bit.
One of the more interesting features they added was the Trusted Network Detection (TND) which in essence allows the AnyConnect client to determine when it is already on a trusted network and disconnect from the VPN or if it is NOT on a trusted network to initiate the VPN connection. I think this feature might need a bit of time before it works out all the kinks but it looks promising. I see it as an attempt by Cisco to address the unique abilities of Microsoft's DirectAccess feature without having to engineer anything new.
- Ed
Subscribe to:
Posts (Atom)