Release Notes for Cisco AnyConnect Secure Mobility Client, Release 2.5
|
|
|
- Laurence Henderson
- 10 years ago
- Views:
Transcription
1 Release Notes for Cisco AnyConnect Secure Mobility Client, Release 2.5 Updated: August 10, 2012 This document includes the following sections: Introduction Downloading the Latest Version Important AnyConnect, CSD, and Host Scan Interoperability Information Changes in AnyConnect Changes in AnyConnect Changes in AnyConnect Changes in AnyConnect Changes in AnyConnect Changes in AnyConnect Changes in AnyConnect Changes in AnyConnect Changes in AnyConnect Changes in AnyConnect Changes in AnyConnect Changes in AnyConnect Changes in AnyConnect Changes Introduced in AnyConnect Changes Introduced in AnyConnect AnyConnect 2.5 Guidelines Guidelines from Previous Releases Still in Effect System Requirements AnyConnect Support Policy Americas Headquarters: Cisco Systems, Inc., 170 West Tasman Drive, San Jose, CA USA Cisco Systems, Inc. All rights reserved.
2 Introduction Caveats Notices/Licensing Related Documentation Introduction These release notes are for all Cisco AnyConnect Secure Mobility Client, Release 2.5 versions. Note We removed Releases and from the AnyConnect Software Download page because they have a regression issue with VPN load balancing (CSCtk01166). If you are running one of these releases in a VPN load balancing environment, we strongly recommend upgrading. We changed the name of the Cisco AnyConnect VPN Client to the Cisco AnyConnect Secure Mobility Client; the product name change is in transition, and may not be complete in all places. The Cisco AnyConnect Secure Mobility client provides remote users with secure VPN connections to the Cisco ASA 5500 Series Adaptive Security Appliance using the Secure Socket Layer (SSL) protocol and the Datagram TLS (DTLS) protocol. AnyConnect provides remote end users with the benefits of a Cisco SSL VPN client, and supports applications and functions unavailable to a clientless, browser-based SSL VPN connection. It runs on Microsoft Windows, Windows Mobile, Linux, and Mac OS X, and supports connections to IPv6 resources over an IPv4 network tunnel. You can upload the client to the ASA to automatically download to remote users when they log in, or you can download and install it on the endpoint. You can configure the ASA to uninstall AnyConnect from the endpoint after the connection terminates, or it can remain on the remote PC for future SSL VPN connections. In addition to the Cisco Adaptive Security Appliance 5500 Series, Cisco IOS Release 15.1(2)T supports the AnyConnect Secure Mobility client. For more information, see the Cisco IOS SSL VPN Data Sheet. Downloading the Latest Version To download the latest version of AnyConnect, you must be a registered user of Cisco.com. Step 1 Step 2 Step 3 Follow this link to the Cisco AnyConnect Secure Mobility Client Introduction page: Login to Cisco.com. Click Download Software. Step 4 Expand the Latest Releases folder and click Step 5 Step 6 Download AnyConnect Packages using one of these methods: To download a single package, find the package you want to download and click Download. To download multiple packages, click Add to cart in the package row and then click Download Cart at the top of the Download Software page. Read and accept the Cisco license agreement when prompted. 2
3 Important AnyConnect, CSD, and Host Scan Interoperability Information Step 7 Select a local directory in which to save the downloads and click Save. What to do Next See, Chapter 2, Configuring the Security Appliance to Deploy AnyConnect in Cisco AnyConnect Secure Mobility Client Administrator Guide, Release 2.5 to install the packages onto an ASA or to deploy AnyConnect using your enterprise software management system. Important AnyConnect, CSD, and Host Scan Interoperability Information AnyConnect is compatible with Host Scan or later versions and CSD or later versions. AnyConnect is not compatible with earlier versions of Host Scan or CSD. Caution AnyConnect will not establish a VPN connection when used with an incompatible version of Host Scan or CSD. Caution If you cannot upgrade AnyConnect and Host Scan or AnyConnect and CSD at the same time, upgrade your version of Host Scan or CSD fist, then upgrade your version of AnyConnect. Table 1 AnyConnect and Cisco Secure Desktop Compatibility AnyConnect Client Version Cisco Secure Desktop Version Are these versions compatible? or later or later yes or later or earlier no or later or later yes or later or earlier no or earlier Any version of CSD no Table 2 AnyConnect and Host Scan Compatibility AnyConnect Client Version Host Scan Version Are these versions compatible? or later or later yes or earlier or later yes or later or later yes or later or earlier no and earlier Any version of Host Scan no 3
4 Changes in AnyConnect Changes in AnyConnect AnyConnect specifies new compatibility requirements between AnyConnect, Host Scan, and CSD as described in Important AnyConnect, CSD, and Host Scan Interoperability Information on page page 3 and resolves the caveats in Table 1. Changes in AnyConnect AnyConnect Release is a maintenance release that resolves the caveats in Table 2. No new features have been introduced with this release. Changes in AnyConnect AnyConnect Release is a maintenance release that resolves the caveat in Table 4. No new features have been introduced with this release. Changes in AnyConnect Compatibility with Global Site Selector Devices The AnyConnect VPN client is now compatible with Global Site Selector (GSS) devices. No client-side configuration is required to take advantage of this capability. When you point the client at the fully qualified domain name (FQDN) answered to the GSS, the devices provide DNS performance improvements through load balancing mechanisms. For GSS support, server certificate verifications must occur at the outset of authentication, including SSL handshakes performed in API, downloader, and agent. LZS Compression Cisco now supports compression for DTLS and TLS on AnyConnect or later. Each tunneling method configures compression separately, and the preferred configuration is to have both SSL and DTLS compression as LZS. You enable compression in the webvpn submode of the group policy and username configuration modes. This feature enhances migration from the legacy VPN clients. You must have ASA release x or later for support of the LZS compression feature. Using data compression on high speed remote access connections passing highly compressible data requires significant processing power on the ASA. With other activity and traffic on the ASA, the number of sessions that can be supported on the platform is reduced. 4
5 Changes in AnyConnect Lion Support AnyConnect provides support for Lion OS X 10.7.Without the appropriate JAVA and Web applet, OS X users may experience CSCtq62860 or CSCto You must install JAVA and enable the appropriate Applet plug-in and web start applications using these steps: Step 1 Open the JAVA Preferences when doing Hostscan or Weblaunch with Safari on OS X Step 2 Step 3 If JAVA is not already installed, you are prompted to do so. Check the Enable applet plug-in and Web Start applications option. Changes in AnyConnect AnyConnect Release is a maintenance release that resolves the caveat in Table 8. The fix resolves a certificate-based installation issue on Mac OS X and Linux only. No new features have been introduced with this release. Changes in AnyConnect Network Location Awareness for Windows With Network Location Awareness enabled on the AnyConnect virtual adapter (VA), Windows 7 now applies the proper firewall profile containing a collection of network and security settings to the network connection associated with the VA. The Cisco AnyConnect Secure Mobility Client connection now appears in the Windows Control Panel, Network and Sharing Center. Changes in AnyConnect AnyConnect Release is a maintenance release that resolves the caveat in Table 11. No new features have been introduced with this release. Changes in AnyConnect AnyConnect Release is a maintenance release for Cisco I.T. use only. Changes in AnyConnect AnyConnect Release is a maintenance release that resolves the caveat in Table 13. No new features have been introduced with this release. 5
6 Changes in AnyConnect Changes in AnyConnect AnyConnect Release is a maintenance release that resolves the caveat in Table 14. No new features have been introduced with this release. Changes in AnyConnect AnyConnect Release is a maintenance release that resolves the caveat in Table 15. No new features have been introduced with this release. Changes in AnyConnect AnyConnect Release is a maintenance release that resolves the caveats in Table 17. No new features have been introduced with this release. Changes in AnyConnect AnyConnect Release is a maintenance release that resolves the caveats in Table 18. No new features have been introduced with this release. Changes in AnyConnect AnyConnect Release is a maintenance release that resolves the caveats in Table 19. No new features have been introduced with this release. Changes Introduced in AnyConnect AnyConnect Release supports the following new features. Local Proxy Connection Support By default, AnyConnect now lets users establish a VPN session through a transparent or non-transparent proxy on the local PC. Some examples of elements that provide a transparent proxy service include: Acceleration software provided by some wireless data cards Network component on some antivirus software, such as Kaspersky. 6
7 Changes Introduced in AnyConnect AnyConnect supports this feature on the following Microsoft OSs: Windows 7 (32-bit and 64-bit) Windows Vista (32-bit and 64-bit) SP2 or Vista Service Pack 1 with KB Windows XP SP2 and SP3. Support for this feature requires either an AnyConnect Essentials or an AnyConnect Premium SSL VPN Edition license. To use the ASDM AnyConnect Profile Editor to disable this feature, open the Preferences (cont) window and uncheck Allow Local Proxy Connections near the top of the panel. Alternatively, you can use a text editor to insert the XML tag <AllowLocalProxyConnections> into the AnyConnect profile. The options are true and false. For example: <ClientInitialization> <AllowLocalProxyConnections>false</AllowLocalProxyConnections> </ClientInitialization> Pause and Resume Support for the Trusted Network Policy If you set the trusted network policy to pause, and a user then establishes a VPN session outside the network, then enters a network configured as trusted, AnyConnect suspends the VPN session instead of disconnecting it. When the user goes outside the trusted network again, AnyConnect resumes the session. This feature is for the user s convenience because it eliminates the need to establish a new VPN session after leaving a trusted network. The ASA idle timer starts when the user s session becomes inactive as a result of leaving the untrusted network and stops when the session resumes in the untrusted network. Before configuring this feature, adjust both the Maximum Connect Time and Idle Timeout values on the ASDM Group Policy General panel. AnyConnect supports this feature on the following OSs: Windows 7 (32-bit and 64-bit) Windows Vista (32-bit and 64-bit) SP2 or Vista Service Pack 1 with KB Windows XP SP2 and SP3. Mac OS 10.5 and 10.6.x Support for this feature requires either an AnyConnect Essentials or an AnyConnect Premium SSL VPN Edition license. To use the Profile Editor to set the trusted network policy to pause, open the Preferences (cont) window and choose Pause next to the Trusted Network Policy parameter. Alternatively, you can use a text editor to change value of the XML tag <TrustedNetworkPolicy> in the AnyConnect profile. The following example shows a complete trusted network policy configuration: <ClientInitialization> <AutomaticVPNPolicy>true <TrustedDNSDomains>*.cisco.com</TrustedDNSDomains> <TrustedDNSServers> *, </TrustedDNSServers> <TrustedNetworkPolicy>Pause</TrustedNetworkPolicy> <UntrustedNetworkPolicy>Connect</UntrustedNetworkPolicy> </AutomaticVPNPolicy> </ClientInitialization> 7
8 Changes Introduced in AnyConnect Authentication Timeout Control By default, AnyConnect waits up to 12 seconds for an authentication from the secure gateway before terminating the connection attempt. AnyConnect then displays a message indicating the authentication timed out. The AnyConnect profile now lets you specify the authentication timeout value. Specify the number of seconds in the range AnyConnect supports this feature on all OSs supported by AnyConnect. Support for this feature requires either an AnyConnect Essentials or an AnyConnect Premium SSL VPN Edition license. To use the Profile Editor to change the authentication timer, open the Preferences (cont) window and enter the number of seconds into the Authentication Timeout Values field. Alternatively, you can use a text editor to add the XML tag <AuthenticationTimeout> to the AnyConnect profile. The following example sets the authentication timeout to 20 seconds: <ClientInitialization> <AuthenticationTimeout>20</AuthenticationTimeout> </ClientInitialization> Microsoft Internet Explorer Proxy Lockdown Control By default, AnyConnect hides the Connections tab in Microsoft Internet Explorer for the duration of the AnyConnect VPN session. AnyConnect supports the ASA group policy configuration of the Microsoft Internet Explorer Proxy Lockdown Control feature introduced in ASA Releases 8.2.3, 8.3.2, and later. This feature lets you disable the default behavior. Using the default behavior prevents users from specifying a proxy service and changing LAN settings. Preventing user access to these settings enhances endpoint security during the AnyConnect session. Disabling the default behavior lets users specify the proxy service to use and change LAN settings during the AnyConnect session. AnyConnect supports this feature on the following Microsoft OSs: Windows 7 (32-bit and 64-bit) Windows Vista (32-bit and 64-bit) SP2 or Vista Service Pack 1 with KB Windows XP SP2 and SP3. Support for this feature requires either an AnyConnect Essentials or an AnyConnect Premium SSL VPN Edition license. To prevent AnyConnect from hiding the Connections tab, use the ASA msie-proxy lockdown disable command in group-policy configuration mode. The following example does not hide the Connections tab: hostname(config)# group-policy FirstGroup attributes hostname(config-group-policy)# msie-proxy lockdown disable The following example hides the Connections tab for the duration of the AnyConnect session: hostname(config-group-policy)# msie-proxy lockdown enable 8
9 Changes Introduced in AnyConnect Changes Introduced in AnyConnect AnyConnect Release supports the following new features on Windows 7, Vista, and XP; and Mac OS X 10.5 and 10.6.x: Post Log-in Always-on VPN Connect Failure Policy Captive Portal Hotspot Detection Captive Portal Remediation Client Firewall with Local Printer and Tethered Device Support Optimal Gateway Selection Quarantine AnyConnect Profile Editor Post Log-in Always-on VPN As an administrator, you can configure AnyConnect to establish a VPN session automatically after the user logs in to a computer. The VPN session remains open until the user logs out of the computer. If the physical connection is lost, the session remains open, and AnyConnect continually attempts to reestablish the physical connection with the ASA to resume the VPN session. (Post log-in) always-on VPN enforces corporate policies to protect the computer from security threats by preventing access to Internet resources when it is not in a trusted network. Always-on VPN requires a valid server certificate configured on the ASA; otherwise, it fails and logs an event indicating the certificate is invalid. Caution Ensure your server certificates can pass strict mode if you configure always-on VPN. With always-on enabled, the client does not support connecting through a proxy. The ASA lets you configure dynamic access policies, group policies, or both to exempt certain individuals from an always-on VPN setting. If an AnyConnect policy enables always-on VPN and a dynamic access policy or group policy disables it, the client retains the disable setting for the current and future VPN sessions as long as its criteria match the dynamic access policy or group policy on the establishment of each new session. AnyConnect supports a Disconnect button for always-on VPN sessions. If you enable it, AnyConnect displays a Disconnect button upon the establishment of a VPN session. Users of always-on VPN sessions may want to click Disconnect so they can choose an alternative secure gateway for reasons such as the following: Performance issues with the current VPN session. Reconnection issues following the interruption of a VPN session. Caution For the reasons noted above, disabling the Disconnect button can at times hinder or prevent VPN access. 9
10 Changes Introduced in AnyConnect Do not attempt to configure always-on VPN until you have read all of the instructions and understand its requirements and implications, as detailed in the following sections in the Cisco AnyConnect Secure Mobility Client Administrator Guide, Release 2.5. When using always on, the integrity of your network must be well defined. As such, CRL Distribution Points for the secure gateway s server certificate must be available for verification by a client on a public network. Post Log-in Always-on VPN Disconnect Button for Always-on VPN Connect Failure Policy The connect failure policy determines whether the computer can access the Internet if always-on VPN is enabled and AnyConnect cannot establish a VPN session (for example, when a secure gateway is unreachable). The fail-close policy disables network connectivity except for VPN access. The fail-open policy permits network connectivity. Regardless of the connect failure policy, AnyConnect continues to try to establish the VPN connection. The following table explains the fail open and fail close policies: Always-on VPN Connect Policy Scenario Advantage Trade-off Fail open Fail close AnyConnect fails to establish or reestablish a VPN session. This failure could occur if the secure gateway is unavailable, or if AnyConnect does not detect the presence of a captive portal (often found in airports, coffee shops and hotels). Same as above except that this option is primarily for exceptionally secure organizations where security persistence is a greater concern than always-available network access. Grants full network access, letting users continue to perform tasks where access to the Internet or other local network resources is needed. The endpoint is protected from web-based malware and sensitive data leakage at all times because all network access is prevented except for local resources such as printers and tethered devices permitted by split tunneling. Security and protection are not available until the VPN session is established. Therefore, the endpoint device may get infected with web-based malware or sensitive data may leak. Until the VPN session is established, this option prevents all network access except for local resources such as printers and tethered devices. It can halt productivity if users require Internet access outside the VPN and a secure gateway is inaccessible. Caution A connect failure closed policy prevents network access if AnyConnect fails to establish a VPN session. AnyConnect detects most captive portals, described in Captive Portal Hotspot Detection and Remediation; however, if it cannot detect a captive portal, a connect failure closed policy prevents all network connectivity. If you deploy a closed connection policy, we highly recommend that you follow a phased approach. For example, first deploy always-on VPN with a connect failure open policy and survey users for the frequency with which AnyConnect does not connect seamlessly. Then deploy a small pilot deployment of a connect failure closed policy among early-adopter users and solicit their feedback. Expand the pilot 10
11 Changes Introduced in AnyConnect program gradually while continuing to solicit feedback before considering a full deployment. As you deploy a connect failure closed policy, be sure to educate the VPN users about the network access limitation as well as the advantages of a connect failure closed policy. Do not attempt to configure a connect failure policy until you have read all of the instructions and understand the requirements and implications, as detailed in Connect Failure Policy for Always-on VPN in the Cisco AnyConnect Secure Mobility Client Administrator Guide, Release 2.5. Captive Portal Hotspot Detection Many facilities that offer Wi-Fi and wired access, such as airports, coffee shops, and hotels, require the user to pay before obtaining access, agree to abide by an acceptable use policy, or both. These facilities use a technique called captive portal to prevent applications from connecting until the user opens a browser and accepts the conditions for access. AnyConnect displays the Unable to contact VPN server message on the GUI if it cannot connect, regardless of the cause. If a captive portal is not present, AnyConnect continues to attempt to connect to the VPN and updates the status message accordingly. If always-on VPN is enabled, the connect failure policy is closed, captive portal remediation is disabled, and AnyConnect detects the presence of a captive portal, the AnyConnect GUI displays the following message once per connection and once per reconnect: The service provider in your current location is restricting access to the Internet. The AnyConnect protection settings must be lowered for you to log on with the service provider. Your current enterprise security policy does not allow this. If AnyConnect detects the presence of a captive portal and the AnyConnect configuration differs from that described above, the AnyConnect GUI displays the following message once per connection and once per reconnect: The service provider in your current location is restricting access to the Internet. You need to log on with the service provider before you can establish a VPN session. You can try this by visiting any website with your browser. Captive Portal Remediation Captive portal remediation is the process of satisfying the requirements of a captive portal hotspot to obtain network access. By default, the connect failure policy prevents captive portal remediation because it restricts network access. You can configure AnyConnect to lift restricted access to let the user satisfy the captive portal requirements. You can also specify the duration for which AnyConnect lifts restricted access. For instructions, see Captive Portal Remediation in the Cisco AnyConnect Secure Mobility Client Administrator Guide, Release 2.5. Client Firewall with Local Printer and Tethered Device Support When users connect to the ASA, all traffic is tunneled through the connection and users cannot access resources on their local network. This includes printers, cameras, and Windows Mobile devices (tethered devices) that sync with the local computer. Enabling Local LAN Access in the client profile resolves this problem, however it can introduce a security or policy concern for some enterprises as a result of unrestricted access to the local network. You can use the ASA to deploy endpoint OS firewall capabilities to restrict access to particular types of local resources, such as printers and tethered devices. 11
12 Changes Introduced in AnyConnect To do so, enable client firewall rules for specific ports for printing. The client distinguishes between inbound and outbound rules. For printing capabilities, the client opens ports required for outbound connections, but blocks all incoming traffic. The client firewall is independent of the always-on feature. Note Be aware that users logged in as administrators have the ability to modify the firewall rules deployed to the client by the ASA. Users with limited privileges cannot modify the rules. For either user, the client reapplies the rules when the connection terminates. If you configure the client firewall, and the user authenticates to an Active Directory (AD) server, the client still applies the firewall policies from the ASA. However, the rules defined in the AD group policy take precedence over the rules of the client firewall. Note Host Scan and some third-party firewalls can interfere with the firewall function configured on the ASA group policy. With third-party firewalls, traffic is passed only if both the AnyConnect client firewall and the third-party firewall permit the traffic type. If the third-party firewall blocks a specific traffic type that the AnyConnect client permits, the client blocks the traffic. Differences in Firewall Behavior between Mac and Windows For Windows computers, deny rules take precedence over allow rules in Windows Firewall. If the ASA pushes down an allow rule to the AnyConnect client, but the user has created a custom deny rule, the AnyConnect rule is not enforced. On Mac computers, the AnyConnect client applies rules sequentially in the same order the ASA applies them. Global rules should always be last. Windows users whose firewall service must be started by the AnyConnect client (not started automatically by the system) may experience a noticeable increase in the time it takes to establish a VPN connection. Due to limitations of the OS, the client firewall policy on computers running Windows XP is enforced for inbound traffic only. Outbound rules and bidirectional rules are ignored. This would include firewall rules such as permit ip any any. For instructions on how to use the firewall to support local printers and tethered devices, see Client Firewall with Local Printer and Tethered Device Support in the Cisco AnyConnect Secure Mobility Client Administrator Guide, Release 2.5 Optimal Gateway Selection Using the Optimal Gateway Selection (OGS) feature, you can minimize latency for Internet traffic without user intervention. With OGS, the AnyConnect client identifies and selects which secure gateway is best for connection or reconnection. OGS begins upon first connection or upon a reconnection at least four hours after the previous disconnection. Users who travel to distant locations connect to a secure gateway nearer to the new location for better performance. Your home and office will get similar results from the same gateway, so no switch of secure gateways will typically occur in this instance. Connection to another secure gateway occurs rarely and only occurs if the performance improvement is at least 20%. 12
13 Changes Introduced in AnyConnect Note You can configure these threshold values using the Profile Editor. By optimizing these values for your particular network, you can find the correct balance between selecting the optimal gateway and reducing the number of times to force the re-entering of credentials. OGS is not a security feature, and it performs no load balancing between secure gateway clusters or within clusters. You can optionally give the end user the ability to enable or disable the feature. The minimum round trip time (RTT) solution selects the secure gateway with the fastest RTT between the client and all other gateways. The client always reconnects to the last secure gateway if the time elapsed has been less than four hours. Factors such as load and temporary fluctuations of the network connection may affect the selection process, as well as the latency for Internet traffic. OGS supports computers running: Windows 7, Vista, and XP Mac OS X 10.5 and 10.6.x You use the second Preferences menu option of the Profile Editor to control the activation and deactivation of the OGS and to specify whether end users may control the feature themselves. If OGS is enabled when the AnyConnect client GUI is started, Automatic Selection displays in the Connect To drop-down menu on the Cisco AnyConnect Connection tab. You cannot change this selection. OGS automatically chooses the optimal secure gateway and displays the selected gateway on the status bar. You may need to click Select to start the connection process. It contacts only the primary servers to determine the optimal one. Once determined, the connection algorithm is as follows: 1. Attempt connection to the optimal server. 2. If that fails, try the optimal server s backup server list. 3. If that fails, try each remaining server in the OGS selection list, as ordered by its selection results. If you made the feature user controllable, the user can manually override the selected secure gateway with the following steps: Step 1 Step 2 Step 3 If currently connected, click Disconnect. Open the Preferences tab and uncheck Enable Optimal Gateway Selection. Choose the desired secure gateway. Note If AAA is being used, end users may have to re-enter their credentials when transitioning to a different secure gateway. The use of certificates eliminates this. For more information about OGS, see Optimal Gateway Selection in the Cisco AnyConnect Secure Mobility Client Administrator Guide, Release
14 Changes Introduced in AnyConnect Quarantine Through the use of quarantine, you can restrict a particular client who already has an established tunnel through a VPN. The ASA applies restricted ACLs to a session to form a restricted group, based on the selected dynamic access policy. When an endpoint is not compliant with an administratively defined policy, the user can still access services for remediation (such as updating the antivirus and so on), but restrictions are placed upon the session. After the remediation occurs, the user can reconnect, which invokes a new posture assessment. If this assessment passes, the user connects. Note Using the Reconnect button, the user can initiate a disconnect and start a new tunnel after remediation if always-on VPN is enabled. Quarantine requires an Advanced Endpoint Assessment license specified in the adaptive security license configuration. The advanced endpoint assessment remediates endpoints that do not comply with dynamic policy requirements for antivirus, antispyware, and firewall applications; and any associated application definition file requirements. Advanced endpoint assessment is a Cisco Secure Desktop Host Scan feature, so AnyConnect supports quarantine on the OSs that the version of Cisco Secure Desktop supports. Go to Supported VPN Platforms and refer to the Cisco Secure Desktop section that identifies the release you are using. The table identifies the OSs that Host Scan supports. ASA Release 8.3(1) or later features dynamic access policies and group policies that support a user message to display on the AnyConnect UI for the duration of the quarantine state. Quarantine does not require the ASA upgrade; only the user message requires it. If you upgrade the ASA to 8.3(1), we recommend that you also upgrade ASDM to Release 6.3(1) or later so that you can use it to configure the new features. For instructions, see Using Quarantine to Restrict Non-Compliant Clients in the Cisco AnyConnect Secure Mobility Client Administrator Guide, Release 2.5. AnyConnect Profile Editor The AnyConnect profile editor is a convenient GUI-based configuration tool you can use to configure the AnyConnect client profile an XML file containing settings that control client features. Previously, you could only change profile settings manually by editing the XML tags in the profile. The AnyConnect client software package for each operating system, version 2.5 and later, contains the profile editor. You can launch the profile editor from ASDM (version 6.3(1) or later) if the client software package is loaded on the ASA as an SSL VPN client image. Note If you do not upgrade ASDM to version 6.3(1) or later, use the XML examples in the following sections as a guide to modifying the AnyConnect profile to enable each feature. If you load multiple client packages, ASDM loads the profile editor from the newest client package. This approach ensures the editor displays the features for the newest client loaded, as well as the older clients. The Profile Editor supports only Java SE 1.6 on the client computer. To activate the profile editor in ASDM, load the AnyConnect client software package as an SSL VPN image and go to Configuration > Remote Access VPN > Network (Client) Access > AnyConnect Client Profile. 14
15 AnyConnect 2.5 Guidelines For more information about using the profile editor, see the sections beginning with Introduction to the AnyConnect Profile Configuration in the Cisco AnyConnect Secure Mobility Client Administrator Guide, Release 2.5. AnyConnect 2.5 Guidelines The following sections provide guidelines that are new in AnyConnect 2.5 and guidelines noted in earlier releases that are still in effect. New Guidelines The following guidelines are new in AnyConnect 2.5: Preventing Other Devices in a LAN from Displaying Hostnames on page 15 Messages in the Localization File Can Span More than One Line on page 16 IOS Support on page 16 Change to AnyConnect Pop-Up Messages on page 16 Revocation Message on page 17 MTU Adjustment on Group Policy May Be Required on page 17 AnyConnect for Mac OS Performance when Behind Certain Routers on page 17 Preventing Windows Users from Circumventing Always-on on page 17 Preventing Other Devices in a LAN from Displaying Hostnames After one uses AnyConnect to establish a VPN session with Windows 7 on a remote LAN, the network browsers on the other devices in the user s LAN can display the names of hosts on the protected remote network. However, the other devices cannot access these hosts. To ensure the AnyConnect host prevents the hostname leak between subnets, including the name of the AnyConnect endpoint host, configure that endpoint to never become the master or backup browser. To do so, Step 1 Step 2 Step 3 Step 4 Step 5 Step 6 Enter regedit in the Search Programs and Files text box. Navigate to HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Browser\Parameters\ Double-click MaintainServerList. The Edit String window opens. Enter No. Click OK. Close the Registry Editor window. 15
16 AnyConnect 2.5 Guidelines Messages in the Localization File Can Span More than One Line If you try to search for messages in the localization file, please note that they can span more than one line, as shown in the example below: msgid "" "The service provider in your current location is restricting access to the " "Secure Gateway. " IOS Support Cisco supports Anyconnect 2.5 VPN access to IOS Release 15.1(2)T functioning as the secure gateway; however, you cannot use the features introduced in AnyConnect 2.5 with IOS. The new AnyConnect 2.5 features that do not support are IOS are: Post Log-in Always-on VPN Connect Failure Policy Captive Portal Hotspot Detection and Remediation Client Firewall with Local Printer and Tethered Device Support Optimal Gateway Selection Quarantine AnyConnect Profile Editor Refer to for additional IOS feature support information. Change to AnyConnect Pop-Up Messages For release 2.5, we created this new message displayed to AnyConnect users: AnyConnect cannot confirm it is connected to your secure gateway. The local network may not be trustworthy. Please try another network. Users receive the new message when the client cannot validate the certificate from the ASA for either of these reasons: An entity between the AnyConnect client and the ASA is giving the client an invalid certificate in order to sniff traffic (which could be a man-in-the-middle attack). Switching networks could alleviate the problem. The server certificate configuration on the ASA is incorrect. If so and if strict-mode is enabled, all users will experience this issue. You can resolve this by putting the proper server certificate on the ASA that can be validated by the AnyConnect client from the certificate authority. The new message replaces and consolidates the following messages displayed by releases 2.4 and earlier: Connection attempt has failed due to server certificate problem. Local policy prohibits the acceptance of untrusted server certificates. A VPN connection will not be established. 16
17 AnyConnect 2.5 Guidelines Revocation Message An AnyConnect GUI revocation warning popup window opens after authentication if AnyConnect attempts to verify a server certificate that specifies the distribution point of an LDAP certificate revocation list (CRL) and the distribution point is only internally accessible. If you want to avoid the display of this popup window, do one of the following: Obtain a certificate without any private CRL requirements. Disable server certificate revocation checking in Internet Explorer. Caution Disabling server certificate revocation checking in Internet Explorer can have severe security ramifications for other uses of the OS. MTU Adjustment on Group Policy May Be Required AnyConnect sometimes receives and drops packet fragments with some routers. This can result in a failure of some web traffic to pass. To avoid this, lower the value of the MTU. To access the MTU with ASDM, choose Configuration > Network (Client) Access > Group Policies > Add or Edit > Advanced > SSL VPN Client. AnyConnect for Mac OS Performance when Behind Certain Routers When the AnyConnect client for Mac OS connects to the ASA from behind certain types of routers, such as the Cisco Virtual Office (CVO) router, some web traffic may pass through the connection while other traffic drops. This could happen because AnyConnect may calculate the MTU incorrectly. To work around this problem, set the MTU for the AnyConnect adaptor to a lower value using the following command from the OS X command line: sudo ipconfig cscotun0 mtu 1200 (For Mac OS10.5 or earlier) sudo ipconfig utun0 mtu 1200 (For Mac OS10.6 and later) Preventing Windows Users from Circumventing Always-on On Windows computers, users with limited or standard privileges may sometimes have write access to their program data folders. This could allow them to delete the AnyConnect profile file and thereby circumvent the always-on feature. To prevent this, configure the computer to restrict access to the following folders (or at least the Cisco sub-folder): For Windows XP users: C:\Document and Settings\All Users For Windows Vista and Windows 7 users: C:\ProgramData 17
18 AnyConnect 2.5 Guidelines Guidelines from Previous Releases Still in Effect The Cisco AnyConnect Secure Mobility Client Administrator Guide, Release 2.5, incorporates most of the guidelines reported in previous releases that remain in effect. The following sections address the remaining guidelines. AnyConnect Smart Card Support AnyConnect supports smart cards in the following environments: Microsoft CAPI 1.0 and CAPI 2.0 on Windows XP, 7 & Vista Keychain via Tokend on Mac OS X, 10.4 and higher AnyConnect does not support: Smart cards on Linux PKCS #11 devices Responding to a TUN/TAP Error Message with Mac OS X 10.5 During the installation of AnyConnect on Mac OS X 10.5 and earlier versions, the following error message sometimes appears: A version of the TUN virtual network driver is already installed on this system that is incompatible with the AnyConnect client. This is a known issue with OS X version 10.5 and prior, and has been resolved in Please uninstall any VPN client, speak with your System Administrator, or reference the AnyConnect Release Notes for assistance in resolving this issue. Mac OS X 10.6 resolves this issue because it provides the version of the TUN/TAP virtual network driver AnyConnect requires. Versions of Mac OS X earlier than 10.6 do not include a TUN/TAP virtual network driver, so AnyConnect installs its own on these operating systems. However, some software such as Parallels, software that manages data cards, and some VPN applications install their own TUN/TAP driver. The AnyConnect installation software displays the error message above because the driver is already present, but its version is incompatible with AnyConnect. To install AnyConnect, you must remove the TUN/TAP virtual network driver. Note Removing the TUN/TAP virtual network driver can cause issues with the software on your system that installed the driver in the first place. To remove the TUN/TAP virtual network driver, open the console application and enter the following commands: sudo rm -rf /Library/Extensions/tap.kext sudo rm -rf /Library/Extensions/tun.kext sudo rm -rf /Library/StartupItems/tap sudo rm -rf /Library/StartupItems/tun sudo rm -rf /System/Library/Extensions/tun.kext sudo rm -rf /System/Library/Extensions/tap.kext 18
19 AnyConnect 2.5 Guidelines sudo rm -rf /System/Library/StartupItems/tap sudo rm -rf /System/Library/StartupItems/tun After entering these commands, restart Mac OS, then re-install AnyConnect. 64-bit Internet Explorer Not Supported AnyConnect installation via WebLaunch does not support 64-bit versions of Internet Explorer. Please instruct users of x64 (64-bit) Windows versions supported by AnyConnect to use the 32-bit version of Internet Explorer or Firefox to install WebLaunch. (At this time, Firefox is available only in a 32-bit version.) Avoid Wireless-Hosted-Network Using the Windows 7 Wireless Hosted Network feature can make AnyConnect unstable. When using AnyConnect, we do not recommend enabling this feature or running front-end applications that enable it (e.g., Connectify or Virtual Router). AnyConnect Requires That the ASA Be Configured to Accept TLSv1 Traffic The AnyConnect client cannot establish a connection with the following ASA settings for ssl server-version : ssl server-version sslv3. ssl server-version sslv3-only. Flexibility in the Sequence and Method Used to Install Start Before Logon and DART Components Previously, in order to use the Start Before Logon components for Windows, the same installation method was required for both AnyConnect and the Start Before Logon components. Both needed to be pre-deployed or both needed to be web-deployed. AnyConnect Release 2.4 eliminates this requirement. This allows the client to be deployed by one method and, perhaps at a later time, the Start Before Logon components to be installed by the same or another method. The Start Before Logon component still has the requirement that AnyConnect be installed first. Another new behavior for AnyConnect Release 2.4 is that if SBL or DART is manually uninstalled from an endpoint that then connects, these components will be re-installed. This behavior will only occur if the head-end configuration specifies that these components be installed and the preferences (set on the endpoint) permit upgrades. Previously these components would not be re-installed in this scenario without uninstalling and re-installing AnyConnect. 19
20 System Requirements System Requirements This section identifies the general management and endpoint requirements for this release. For endpoint OS support and license requirements for each feature, see AnyConnect Secure Mobility Client Features, Licenses, and OSs, Release 2.5. AnyConnect 2.5 installations can coexist with other VPN clients, including IPsec clients, on all supported endpoints; however, we do not support running AnyConnect while other VPN clients are running. The following sections identify the minimum management and endpoint requirements: Security Appliance Software Requirements Microsoft Windows Linux Mac OS X Windows Mobile Security Appliance Software Requirements For the latest fixes, the ASAs must be running the following: ASA Release 8.3(1) ASDM 6.3(1) Cisco Secure Desktop AnyConnect 2.5 requires the following: ASA 8.0(2) or later. ASDM 6.1(3) or later. The minimum supported version of Cisco Secure Desktop is or later. We also recommend upgrading to ASDM 6.3(1) or later so that you can use the AnyConnect profile editor to configure many of the AnyConnect features. You can use ASDM 6.3(1) in combination with ASA 8.0(2) or later. If you choose not to upgrade ASDM, you must use an editor to add the XML tags to the AnyConnect profile if you want to deploy the new AnyConnect features. You must upgrade to ASA 8.3(1) if you want to do the following: Use the services supported by a Cisco IronPort Web Security Appliance license. These services let you enforce acceptable use policies and protect endpoints from websites found to be unsafe by granting or denying all HTTP and HTTPS requests. Deploy firewall rules. If you deploy always-on VPN, you might want to enable split tunneling and configure firewall rules to restrict network access to local printing and tethered mobile devices. Configure dynamic access policies or group policies to exempt qualified VPN users from an always-on VPN deployment. Configure dynamic access policies to display a message on the AnyConnect GUI when an AnyConnect session is in quarantine. 20
21 System Requirements Microsoft Windows For WebLaunch, use Internet Explorer 6.0 or later or Firefox 3.0+, and enable ActiveX or install Sun JRE Windows Versions Windows 7 (32-bit and 64-bit) AnyConnect requires a clean install if you upgrade from Windows XP to Windows 7. If you upgrade from Windows Vista to Windows 7, manually uninstall AnyConnect first, then after the upgrade, reinstall it manually or by establishing a web-based connection to a security appliance configured to install it. Uninstalling before the upgrade and reinstalling AnyConnect afterwards is necessary because the upgrade does not preserve the Cisco AnyConnect Virtual Adapter. AnyConnect is compatible with 3G data cards which interface with Windows 7 via a WWAN adapter. Windows Vista (32-bit and 64-bit) SP2 or Vista Service Pack 1 with KB AnyConnect requires a clean install if you upgrade from Windows XP to Windows Vista. Windows XP SP2 and SP3. Windows Requirements Pentium class processor or greater. x86 (32-bit) or x64 (64-bit) processors. 5 MB hard disk space. RAM: 256 MB for Windows XP. 512 MB for Windows Vista. 512 MB for Windows 7. Microsoft Installer, version 3.1. Linux The following sections show the supported Linux distributions and requirements. Linux Distributions Red Hat Enterprise Linux 5 Desktop Ubuntu 9.x and 10.x We do not validate other Linux distributions. We will consider requests to validate other Linux distributions for which you experience issues, and provide fixes at our discretion. Linux Requirements x86 instruction set. 32-bit or biarch 64-bit processor 32 MB RAM. 20 MB hard disk space. 21
22 System Requirements Superuser privileges. libstdc++ users must have libstdc++ version (libstdc++.so.5) or higher, but below version 4. Firefox 2.0 or later with libnss3.so installed in /usr/local/lib, /usr/local/firefox/lib, or /usr/lib. Firefox must be installed in /usr/lib or /usr/local, or there must be a symbolic link in /usr/lib or /usr/local called firefox that points to the Firefox installation directory. libcurl 7.10 or later. openssl 0.9.7a or later. Java 5 (1.5) or later. Iced Tea is the default Java package on Fedora 8. The only version that works for web installation is Sun Java. You must install Sun Java and configure your browser to use that instead of the default package. zlib. gtk 2.0.0, gdk 2.0.0, libpango 1.0. iptables 1.2.7a or later. tun module supplied with kernel or 2.6. Note AnyConnect SMC 2.5 reportedly runs on 64-bit Linux, although we do not support it. Mac OS X AnyConnect 2.5 supports the following versions of Mac OS: Mac OS X 10.5 Mac OS X 10.6.x (32-bit and 64-bit) MAC OS X 10.7 (for release or later) AnyConnect requires 50MB of hard disk space. If you upgrade from one major Mac OS X release to another (for example 10.5 to 10.6), manually uninstall AnyConnect first, then after the upgrade, reinstall it manually or by establishing a web-based connection to a security appliance configured to install it. 22
23 AnyConnect Support Policy Windows Mobile Note End of Life has been announced for all versions of AnyConnect for Windows Mobile. Refer to the End-of-Life Announcement for the Cisco AnyConnect Secure Mobility Client on Windows Mobile for support and availability details. Although the devices listed below were originally qualified with AnyConnect for Windows Mobile , these releases were removed from customer availability due to a security vulnerability. Please contact your authorized support representative for further details. AnyConnect 2.5 is compatible with Windows Mobile 6.5, 6.1, 6.0 and 5.0 Professional and Classic for touch-screen devices only. Users have reported success with most touch-screen devices running these versions of Windows Mobile. However, to ensure interoperability, we guarantee compatibility only with the devices we test, as follows: HTC Imagio running Windows Mobile 6.5 HTC Tilt 2 running Windows Mobile 6.5 HTC Touch running Windows Mobile 6.0 HTC TyTN running Windows Mobile 5.0 Samsung Epix running Windows Mobile 6.1 Samsung Omnia Pro 4 running Windows Mobile 6.5 Samsung Omnia running Windows Mobile 6.1 Samsung Saga running Windows Mobile 6.1 AnyConnect Support Policy We support all AnyConnect software versions available on the Cisco AnyConnect VPN Software Download site; however, we provide fixes and enhancements only in maintenance or feature releases based on the most recently released version. Caveats Caveats describe unexpected behavior or defects in Cisco software releases. Note If you have an account with CCO, you can use Bug Navigator II to find caveats of any severity for any release. To reach Bug Navigator II on CCO, select Software & Support: Online Technical Support: Software Bug Toolkit or navigate to The following sections lists the Severities 2 and 3 caveats: Caveats Resolved by AnyConnect Caveats Resolved by AnyConnect Open Caveats in Release
24 Caveats Resolved by AnyConnect Caveats Resolved by AnyConnect Open Caveats in Release Caveats Resolved by AnyConnect Open Caveats in Release Caveats Resolved by AnyConnect Open Caveats in AnyConnect and Caveats Resolved by AnyConnect Caveat Resolved by AnyConnect Open Caveats in AnyConnect Caveat Resolved by AnyConnect Caveat Resolved by AnyConnect Caveat Resolved by AnyConnect Open Caveats in AnyConnect Caveats Resolved by AnyConnect Caveats Resolved by AnyConnect Caveats Resolved by AnyConnect Caveats Resolved by AnyConnect Open Caveats in AnyConnect Caveats Resolved by AnyConnect Caveats Resolved by AnyConnect Caveats Resolved by AnyConnect Table 1 Caveats Resolved by Cisco AnyConnect Secure Mobility Client Release Component Identifier download_install CSCtw47523 Downloader remote code vulnerability: Not Validating Manifest Origin download_install CSCtw48681 Downloader remote code vulnerability: ActiveX Not Checking Timestamp download_install CSCty45925 One version of the Java applet download does not check signatures posture-asa CSCtx74235 CSD: Downloaders/ActiveX to fix validation of downloaded code vpn CSCti97331 API not checking file signature on CSD library vpn CSCtz94705 Need to disable install on 10.4 OS X 24
25 Caveats Resolved by AnyConnect Caveats Resolved by AnyConnect Table 2 shows the caveats that AnyConnect Secure Mobility Client Release resolves. Table 2 Caveat Resolved by Cisco AnyConnect Secure Mobility Client Release CSCtk18952 AnyConnect fails to connect if PtP interface does not have destination address CSCts44278 AnyConnect fails with SBL and certificates on Windows 7 Open Caveats in Release Table 3 lists the caveats that are unresolved in Cisco AnyConnect Secure Mobility Client Releases Table 3 Open Caveats in Cisco AnyConnect Secure Mobility Client Releases CSCsm69213 CSCsv49773 CSCsx62325 CSCta94621 CSCtb73259 CSCtc03052 CSCtc17266 CSCte42921 CSCtf20226 CSCtf56830 CSCtf81852 CSCtf90996 CSCtg01525 CSCtg04881 CSCtg31720 CSCtg31729 CSCtg45505 CSCth85648 CSCtj62029 CSCtn84747 CSCto53984 CSCtq02141 CSCtq75832 AnyConnect does not perform auto route correction on Mac/Linux Ability to accommodate multiple head-end profiles Windows Mobile driver error with SVC rekey new-tunnel Enable local LAN access not consistent with other split tunnel options Message Connection to the proxy server failed appears during reconnect SCEP fails in upgrade scenario Private-side proxy on OS X does not support per-protocol proxy Get Unresolved Gateway Address when trying to connect Make AnyConnect DNS with split tunnel behavior for Mac same as Windows AC cert popup appears even when not requested by ASA Revocation popup when LDAP CRL on outside is blocked OGS selects inaccessible host AnyConnect should have clear description for each error message VPN downloaders always aborts first SSL handshake JPN: Status message appeared at bottom is corrupted when disconnected JPN: JPN message garbled when uninstallation runs without disconnection VPN connection fails from network with unusual captive portal GUI: Auth challenge window - Mac is missing text - Windows ignoring CR/LF Cannot establish tunnel with machine cert auth and untrusted server CA Proxy auth problems when proxy offers multiple auth schemes pki-crl: crl download fails when always-on enabled AnyConnect DNS issue when ISP DNS is on the same subnet as Public IP AnyConnect does not perform auto route correction on Mac/Linux 25
26 Caveats Resolved by AnyConnect Table 3 Open Caveats in Cisco AnyConnect Secure Mobility Client Releases CSCtr27865 CSCtr75228 CSCtr75253 CSCtr75276 CSCts46682 Observing slow throughput when using AnyConnect Mac client VPN client driver has encountered an error csdlib.dll is corrupted and size of 0K Experiencing frequent disconnects from VPN connection AnyConnect Linux init script issues Caveats Resolved by AnyConnect Table 4 shows the caveats that AnyConnect Secure Mobility Client Release resolves. Table 4 Caveat Resolved by Cisco AnyConnect Secure Mobility Client Release CSCtr20634 CSCtr51718 CSCtr64798 AC: Split-exclude route not working when overlapping a link-level route UI exits without an informative message when Captive Portal is detected in SBL mode [Lion] Critical error while connecting to certain head-ends Open Caveats in Release Table 5 lists the caveats that are unresolved in Cisco AnyConnect Secure Mobility Client Releases Table 5 Open Caveats in Cisco AnyConnect Secure Mobility Client Releases CSCsm69213 CSCsv49773 CSCsx62325 CSCta94621 CSCtb73259 CSCtc03052 CSCtc17266 CSCte42921 CSCtf20226 CSCtf56830 CSCtf81852 CSCtf90996 CSCtg01525 AnyConnect does not perform auto route correction on Mac/Linux Ability to accommodate multiple head-end profiles Windows Mobile driver error with SVC rekey new-tunnel Enable local LAN access not consistent with other split tunnel options Message Connection to the proxy server failed appears during reconnect SCEP fails in upgrade scenario Private-side proxy on OS X does not support per-protocol proxy Get Unresolved Gateway Address when trying to connect Make AnyConnect DNS with split tunnel behavior for Mac same as Windows AC cert popup appears even when not requested by ASA Revocation popup when LDAP CRL on outside is blocked OGS selects inaccessible host AnyConnect should have clear description for each error message 26
27 Open Caveats in Release Table 5 Open Caveats in Cisco AnyConnect Secure Mobility Client Releases CSCtg04881 CSCtg31720 CSCtg31729 CSCtg45505 CSCth85648 CSCtj62029 CSCtk75358 CSCtl12833 CSCtl23155 CSCtn84747 CSCto53984 CSCtq02141 CSCtq75832 CSCtr27865 VPN downloaders always aborts first SSL handshake JPN: Status message appeared at bottom is corrupted when disconnected JPN: JPN message garbled when uninstallation runs without disconnection VPN connection fails from network with unusual captive portal GUI: Auth challenge window - Mac is missing text - Windows ignoring CR/LF Cannot establish tunnel with machine cert auth and untrusted server CA AnyConnect compatibility issues with Microsoft Forefront AC certificate prompt after network down with automatic cert selection AnyConnect SBL fails with Novell netware Proxy auth problems when proxy offers multiple auth schemes pki-crl: crl download fails when always-on enabled AnyConnect DNS issue when ISP DNS is on the same subnet as Public IP AnyConnect does not perform auto route correction on Mac/Linux Observing slow throughput when using AnyConnect Mac client Caveats Resolved by AnyConnect Table 6 shows the caveats that AnyConnect Secure Mobility Client Release resolves. Table 6 Caveats Resolved by Cisco AnyConnect Secure Mobility Client Release CSCth83069 CSCtq74504 CSCtq84525 CSCtr19783 API fails to launch cached Downloader VPN connection fails with link-local split-exclude network AnyConnect CertPathValidatorException timestamp check failed AnyConnect Weblaunch ignores proxy server setting Open Caveats in Release Table 7 lists the caveats that are unresolved in Cisco AnyConnect Secure Mobility Client Releases Table 7 Open Caveats in Cisco AnyConnect Secure Mobility Client Releases CSCsm69213 CSCsv49773 CSCsx62325 CSCta94621 AnyConnect does not perform auto route correction on Mac/Linux Ability to accommodate multiple head-end profiles Windows Mobile driver error with SVC rekey new-tunnel Enable local LAN access not consistent with other split tunnel options 27
28 Open Caveats in Release Table 7 Open Caveats in Cisco AnyConnect Secure Mobility Client Releases CSCtb73259 CSCtc03052 CSCtc17266 CSCte42921 CSCtf20226 CSCtf56830 CSCtf81852 CSCtf90996 CSCtg01525 CSCtg04881 CSCtg31720 CSCtg31729 CSCtg45505 CSCth85648 CSCtj62029 CSCtk75358 CSCtl12833 CSCtl23155 CSCtn84747 CSCto53984 CSCtq02141 CSCtq75832 CSCtr27865 Message Connection to the proxy server failed appears during reconnect SCEP fails in upgrade scenario Private-side proxy on OS X does not support per-protocol proxy Get Unresolved Gateway Address when trying to connect Make AnyConnect DNS with split tunnel behavior for Mac same as Windows AC cert popup appears even when not requested by ASA Revocation popup when LDAP CRL on outside is blocked OGS selects inaccessible host AnyConnect should have clear description for each error message VPN downloaders always aborts first SSL handshake JPN: Status message appeared at bottom is corrupted when disconnected JPN: JPN message garbled when uninstallation runs without disconnection VPN connection fails from network with unusual captive portal GUI: Auth challenge window - Mac is missing text - Windows ignoring CR/LF Cannot establish tunnel with machine cert auth and untrusted server CA AnyConnect compatibility issues with Microsoft Forefront AC certificate prompt after network down with automatic cert selection AnyConnect SBL fails with Novell netware Proxy auth problems when proxy offers multiple auth schemes pki-crl: crl download fails when always-on enabled AnyConnect DNS issue when ISP DNS is on the same subnet as Public IP AnyConnect does not perform auto route correction on Mac/Linux Observing slow throughput when using AnyConnect Mac client Caveats Resolved by AnyConnect Table 8 shows the caveat that AnyConnect Secure Mobility Client Release resolves. Table 8 Caveat Resolved by Cisco AnyConnect Secure Mobility Client Release CSCtq84525 Anyconnect CertPathValidatorException: timestamp check failed 28
29 Open Caveats in Release Open Caveats in AnyConnect and Table 9 lists the caveats that are unresolved in Cisco AnyConnect Secure Mobility Client Releases and Table 9 CSCsm69213 CSCsu52949 CSCsv49773 CSCsw37980 CSCsx48918 CSCsx62325 CSCsy34111 CSCsy48762 CSCsz56742 CSCta94621 CSCtb73073 CSCtb73259 CSCtc03052 CSCtc17266 CSCte42921 CSCte73983 CSCtf20226 CSCtf56830 CSCtf81852 CSCtf90996 CSCtg01525 CSCtg04881 CSCtg31720 CSCtg31729 CSCtg45505 CSCth32206 CSCth35315 CSCth85648 CSCtj62029 CSCtk14009 CSCtk36448 Open Caveats in Cisco AnyConnect Secure Mobility Client Releases and Anyconnect does not perform auto route correction on Mac/Linux GUI pops up certificate warning prompts on every connection attempt Ability to accommodate multiple head-end profiles Needs more certificate matching events RDP+SBL: Unable to retrieve logon information to verify compliance Windows Mobile driver error with SVC rekey new-tunnel SVC MSIE proxy option auto does not work WM: Split tunnel does not work with Anyconnect Mobile Will not use certificates under certain ASA configuration Enable local LAN access not consistent with other split tunnel options VPN establishment allowed while multiple local users logged in on MAC Message Connection to the proxy server failed appears during reconnect SCEP fails in upgrade scenario Private-side proxy on OS X doesn't support per-protocol proxy Get Unresolved Gateway Address When Trying to Connect bad apple config may cause vpnagentd to fail Make Anyconnect DNS w/ split tunnel behavior for Mac same as windows AC cert popup appears even when not requested by ASA Revocation popup when LDAP CRL on outside is blocked OGS selects inaccessible host Anyconnect should have clear description for each error msg VPN Downloader always aborts first SSL handshake JPN: Status message appeared at bottom is corrupted when disconnected JPN: JPN message garbled when uninstallation runs w/o disconnection VPN connection fails from network with unusual captive portal Logging is insufficient for troubleshooting captive portal reconnect after resume blocks cisco nac agent discovery GUI: Auth challenge window - Mac is missing text - Win ignoring CR/LF Can't establish tunnel with machine cert auth and untrusted server CA AnyConnect 2.x/3.x: Public proxy PAC URL fails to connect DOC: Anyconnect for Mac does not check System Keychain for Certificates 29
30 Open Caveats in Release Table 9 CSCtk75358 CSCtl12833 CSCtl21430 CSCtl23155 CSCtn46629 CSCtn84747 CSCto53984 CSCtq02141 Open Caveats in Cisco AnyConnect Secure Mobility Client Releases and AnyConnect compatibility issues with Microsoft Forefront AC certificate prompt after network down with automatic cert selection DOC: Anyconnect 2.5 admin guide should include firewall config examples Anyconnect SBL fails with Novell netware DART does not collect files from localized paths proxy auth problems when proxy offers multiple auth schemes pki-crl: crl download fails when always-on enabled AnyConnect DNS Issue when ISP DNS is on same subnet as Public IP Caveats Resolved by AnyConnect Table 10 shows the caveats that AnyConnect Secure Mobility Client Release resolves. Table 10 Caveats Resolved by Cisco AnyConnect Secure Mobility Client Release CSCto76864 Anyconnect fails after few seconds connected on certain 3G cards. CSCto53112 DNS Cache failure CSCtj89377 CSD causes client crash on Mac CSCto05439 Time out setting in the profile editor for websec does not work CSCtl90819 Random Cert Validation Failures CSCtf81226 AC Profile Editor: Disable Cert Selection option is not clear CSCtj51376 IE Proxy setting is not restored after Anyconnect disconnect on Win 7 CSCtn96122 Opening Advanced Window Link While GUI Shutting Down Crashes GUI CSCtk66387 WPAD doesn't work on Win7 + IE 8 CSCto00117 Tunnel resumption exhibits broken split tunnel (which is not configured) CSCto08814 Routing Issue Gets Client Stuck Reconnecting CSCto05492 VPN Connection Stuck Reconnecting and then Disconnecting CSCtk78458 Anyconnect API crash in attach and detach CSCtf94284 Anyconnect may show password in clear text in RAM CSCtn75204 AnyConnect 3.0 VPN Server could not parse request with & or < in passwd CSCtn89892 signal handling bug causes hostscan to scan twice per minute CSCtn68171 Add ability for AC to detect wrong client cert CSP and generate event CSCtn42751 Anyconnect + 'Retain VPN on logoff', case sensitivity not compatible wit CSCtl79784 Crash from WER Data CSCtn78403 cscan signature not checked before launch CSCtk06308 AC failing to perform SCEP proxy enrollment - Profile () not found 30
31 Open Caveats in Release Table 10 Caveats Resolved by Cisco AnyConnect Secure Mobility Client Release CSCto73233 CSCto73186 CSCtl45627 CSCtn87093 CSCth76124 DOC: Anyconnect FIPS package has system-wide consequences. DOC Anyconnect FIPS module - details not documented Connection to IPv6 enabled head end fails (Vista/Win7) VPN: WinXP with TND strips DefaultGW and breaks trusted DNS settings Retain ASA DNS resolution throughout connection establishment Caveat Resolved by AnyConnect Table 11 shows the caveat that AnyConnect Secure Mobility Client Release resolves. Table 11 Caveat Resolved by Cisco AnyConnect Secure Mobility Client Release CSCtn21228 AnyConnect Profile Editor enabling all Extended Key Usages causes error Open Caveats in AnyConnect Table 12 lists the caveats that are unresolved in Cisco AnyConnect Secure Mobility client Releases , , , and Table 12 CSCsh69786 CSCsm69213 CSCsu52949 CSCsu70199 CSCsv49773 CSCsw37980 CSCsx48918 CSCsx62325 CSCsy34111 CSCsy48762 CSCsz56742 CSCta94621 CSCtb73073 CSCtb73259 CSCtc03052 Open Caveats in Cisco AnyConnect Secure Mobility Client Releases IPv6 link local addresses are not tunneled through AnyConnect Client Anyconnect does not perform auto route correction on Mac/Linux GUI pops up certificate warning prompts on every connection attempt IPv6: Network error: windows has detected and IP address conflict Multiple local profiles for SG may result in using wrong settings AC needs more certificate matching events RDP+SBL: Unable to retrieve logon information to verify compliance Windows Mobile driver error with SVC rekey new-tunnel SVC MSIE proxy option auto does not work AnyConnect: Split tunnel does not work with Anyconnect Mobile Will not use certificates under certain ASA configuration Enable local LAN access not consistent with other split tunnel options Mac: VPN establishment allowed while multiple local users logged in Message Connection to the proxy server failed appears during reconnect SCEP fails in upgrade scenario 31
32 Open Caveats in Release Table 12 CSCtc17266 CSCtc65842 CSCte42921 CSCte73983 CSCtf04766 CSCtf06844 CSCtf20226 CSCtf23946 CSCtf52183 CSCtf56830 CSCtf81852 CSCtf90996 CSCtf94284 CSCtg01304 CSCtg01525 CSCtg04881 CSCtg31720 CSCtg31729 CSCtg37737 CSCtg45505 CSCtg73736 CSCth32206 CSCth35315 CSCth61000 CSCth93690 CSCti07859 CSCtj36459 CSCtj62029 Open Caveats in Cisco AnyConnect Secure Mobility Client Releases (continued) Private-side proxy on OS X doesn't support per-protocol proxy Mac GUI crash with SCEP in FIPS mode Get Unresolved Gateway Address When Trying to Connect bad apple config may cause vpnagentd to fail AnyConnect uses Windows system locale instead of install language AnyConnect SCEP enrollment not working with ASA Per Group Cert Auth Make anyconnect DNS w/ split tunnel behavior for Mac same as windows Agent does not restore DNS Suffix search list if VA dies SCEP enrollment on Mac makes private key exportable from keychain AC cert popup appears even when not requested by ASA Revocation popup when LDAP CRL on outside is blocked OGS selects inaccessible host Anyconnect may show password in clear text in RAM Split-tunneling: filtering needs to be enforced on the VPN adapter Anyconnect should have clear description for each error msg VPN Downloader always aborts first SSL handshake JPN: Status message appeared at bottom is corrupted when disconnected JPN: JPN message garbled when uninstallation runs w/o disconnection AnyConnect cannot parse PAC file and does not connect to endpoint VPN connection fails from network with unusual captive portal Captive portal can't be remediated if remediation site in private space Logging is insufficient for troubleshooting captive portal reconnect after resume blocks cisco nac agent discovery Remove GetMUSHostAddr MUS messages when MUS is not enabled AnyConnect 2.x on MAC removing e-token will not allow reconnects AC reports 'certificate validation failed' with VPN LB intermittently Cannot connect to tunnel groups with CSD enabled Can't establish tunnel with machine cert auth and untrusted server CA Caveat Resolved by AnyConnect Table 13 shows the caveat that AnyConnect Secure Mobility Client Release resolves. Table 13 Caveat Resolved by Cisco AnyConnect Secure Mobility Client Release CSCtj79104 Multicast traffic should not be tunneled with split-include tunneling config 32
33 Open Caveats in Release Caveat Resolved by AnyConnect Table 14 shows the caveat that AnyConnect Secure Mobility Client Release resolves. Table 14 Caveat Resolved by Cisco AnyConnect Secure Mobility Client Release CSCte46102 AnyConnect unable to browse websites when connected Caveat Resolved by AnyConnect Table 15 shows the caveat that AnyConnect Secure Mobility Client Release resolves. Table 15 Caveat Resolved by Cisco AnyConnect Secure Mobility Client Release CSCtk85347 Invalid certs result in connection breakage Open Caveats in AnyConnect Table 16 lists the caveats that are unresolved in Cisco AnyConnect Secure Mobility client Releases , , , and Table 16 Open Caveats in Cisco AnyConnect Secure Mobility Client Releases CSCsh69786 CSCsm69213 CSCsu52949 CSCsu70199 CSCsv49773 CSCsw37980 CSCsx48918 CSCsx62325 CSCsy34111 CSCsy48762 CSCsz56742 CSCta94621 CSCtb73073 CSCtb73259 CSCtc03052 CSCtc17266 CSCtc65842 IPv6 link local addresses are not tunneled through AnyConnect Client Anyconnect does not perform auto route correction on Mac/Linux GUI pops up certificate warning prompts on every connection attempt IPv6: Network error: windows has detected and IP address conflict Multiple local profiles for SG may result in using wrong settings AC needs more certificate matching events RDP+SBL: Unable to retrieve logon information to verify compliance Windows Mobile driver error with SVC rekey new-tunnel SVC MSIE proxy option auto does not work AnyConnect: Split tunnel does not work with Anyconnect Mobile Will not use certificates under certain ASA configuration Enable local LAN access not consistent with other split tunnel options Mac: VPN establishment allowed while multiple local users logged in Message Connection to the proxy server failed appears during reconnect SCEP fails in upgrade scenario Private-side proxy on OS X doesn't support per-protocol proxy Mac GUI crash with SCEP in FIPS mode 33
34 Open Caveats in Release Table 16 Open Caveats in Cisco AnyConnect Secure Mobility Client Releases CSCte42921 CSCte46102 CSCte73983 CSCtf06844 CSCtf20226 CSCtf23946 CSCtf52183 CSCtf56830 CSCtf81852 CSCtf90996 CSCtf94284 CSCtg01304 CSCtg01525 CSCtg04881 CSCtg31720 CSCtg31729 CSCtg37737 CSCtg45505 CSCtg73736 CSCth32206 CSCth35315 CSCth61000 CSCti07859 CSCtj36459 CSCtj62029 Get Unresolved Gateway Address When Trying to Connect AnyConnect unable to browse websites when connected bad apple config may cause vpnagentd to fail AnyConnect SCEP enrollment not working with ASA Per Group Cert Auth Make anyconnect DNS w/ split tunnel behavior for Mac same as windows Agent does not restore DNS Suffix search list if VA dies SCEP enrollment on Mac makes private key exportable from keychain AC cert popup appears even when not requested by ASA Revocation popup when LDAP CRL on outside is blocked OGS selects inaccessible host Anyconnect may show password in clear text in RAM Split-tunneling: filtering needs to be enforced on the VPN adapter Anyconnect should have clear description for each error msg VPN Downloader always aborts first SSL handshake JPN: Status message appeared at bottom is corrupted when disconnected JPN: JPN message garbled when uninstallation runs w/o disconnection AnyConnect cannot parse PAC file and does not connect to endpoint VPN connection fails from network with unusual captive portal Captive portal can't be remediated if remediation site in private space Logging is insufficient for troubleshooting captive portal reconnect after resume blocks cisco nac agent discovery Remove GetMUSHostAddr MUS messages when MUS is not enabled AC reports 'certificate validation failed' with VPN LB intermittently Cannot connect to tunnel groups with CSD enabled Can't establish tunnel with machine cert auth and untrusted server CA Caveats Resolved by AnyConnect Table 17 shows the caveats that AnyConnect Secure Mobility Client Release resolves. Table 17 Caveats Resolved by Cisco AnyConnect Secure Mobility Client Release CSCtk55194 CSCtk61455 Automatic upgrade fails, downloader unable to stop the agent Fix for OpenSSL cipher renegotiation vulnerability (CVE ) 34
35 Open Caveats in Release Caveats Resolved by AnyConnect Table 18 shows the caveats that AnyConnect Secure Mobility Client Release resolves. Table 18 Caveats Resolved by Cisco AnyConnect Secure Mobility Client Release CSCtj90974 CSCtk01166 Headend Selection Cache size causes AnyConnect client to hang Redirects appear to be sent to the client as IP address instead of FQDN Caveats Resolved by AnyConnect Table 19 shows the caveats that AnyConnect Secure Mobility Client Release resolves. Table 19 Caveats Resolved by Cisco AnyConnect Secure Mobility Client Release CSCti73316 CSCti96053 CSCte99278 CSCtj59741 CSCtc80017 CSCth40372 AnyConnect fails to connect with CSD enabled AnyConnect fails with Unable to process response from... with Auto-Conn Infinite prompting during Cert Authentication AnyConnect machine certs cause group mapping to fail if CSD is enabled Doc: StrictCertificate Trust needs to be updated Incorrect spelling in Quarantine help Caveats Resolved by AnyConnect Table 20 shows the caveats that AnyConnect Secure Mobility Client Release resolves. Table 20 Caveats Resolved by Cisco AnyConnect Secure Mobility Client Release CSCtb80457 CSCtc43955 CSCtd59583 CSCtd67178 CSCte77738 CSCtf19644 CSCtf98121 CSCtg02656 CSCtg07128 CSCtg24945 CSCtg69281 AnyConnect and ASA need to negotiate time-to-wait for authentication Anyconnect stuck in Contacting Network and does not timeout vpnagent exception in filtering code reported on WER vpnagent BEX-buffer overflow exception in autoproxy code reported to WER MinimizeOnConnect fails with SBL and TND With split-exclude, AC LocalLanAccess preference not enabled Anyconnect fails when client certificate has empty Subject IgnoreProxy does not work with SBL AnyConnect doesn't use IE's exp proxy svr settings telemetry URL req AC Windows: Failure when reconnecting due to caching of the vpn gw IP Allow administrator to configure local proxy support 35
36 Open Caveats in Release Table 20 Caveats Resolved by Cisco AnyConnect Secure Mobility Client Release CSCtg89030 CSCtg99019 CSCth03674 CSCth15323 CSCth87671 CSCti08881 CSCti33633 IOS AnyConnect fails when no image is installed for bypassdownloader PPP: VPN connection fails when PPP server name not set in the RAS entry AnyConnect SBL Fails when <BypassDownloader> is True in LocalPolicy AnyConnect 2.4 on Linux fails to connect if private keys are protected AnyConnect: DNS Searchlist Copy Error, Missing Last Entry Mac 10.6 AnyConnect Client failing during SSL Rekey Unable to reconnect when CP detected and remediation done after 2min Open Caveats in AnyConnect Table 21 lists the caveats that are unresolved in Cisco AnyConnect Secure Mobility client in AnyConnect Release Table 21 Open Caveats in Cisco AnyConnect Secure Mobility Client Release CSCsh69786 CSCsm69213 CSCsu52949 CSCsu70199 CSCsv49773 CSCsw37980 CSCsx48918 CSCsx62325 CSCsy34111 CSCsy48762 CSCsz56742 CSCta94621 CSCtb73073 CSCtb73259 CSCtc03052 CSCtc17266 CSCtc65842 CSCte42921 CSCte46102 CSCte73983 CSCtf04766 CSCtf06844 IPv6 link local addresses are not tunneled through AnyConnect Client Anyconnect does not perform auto route correction on Mac/Linux GUI pops up certificate warning prompts on every connection attempt IPv6: Network error: windows has detected and IP address conflict Multiple local profiles for SG may result in using wrong settings AC needs more certificate matching events RDP+SBL: Unable to retrieve logon information to verify compliance Windows Mobile driver error with SVC rekey new-tunnel SVC MSIE proxy option auto does not work AnyConnect: Split tunnel does not work with Anyconnect Mobile Will not use certificates under certain ASA configuration Enable local LAN access not consistent with other split tunnel options Mac: VPN establishment allowed while multiple local users logged in Message Connection to the proxy server failed appears during reconnect SCEP fails in upgrade scenario Private-side proxy on OS X doesn't support per-protocol proxy Mac GUI crash with SCEP in FIPS mode Get Unresolved Gateway Address When Trying to Connect AnyConnect unable to browse websites when connected bad apple config may cause vpnagentd to fail AnyConnect uses Windows system locale instead of install language AnyConnect SCEP enrollment not working with ASA Per Group Cert Auth 36
37 Open Caveats in Release Table 21 Open Caveats in Cisco AnyConnect Secure Mobility Client Release CSCtf20226 CSCtf23946 CSCtf52183 CSCtf56830 CSCtf81852 CSCtf90996 CSCtf94284 CSCtg01304 CSCtg01525 CSCtg04881 CSCtg31720 CSCtg31729 CSCtg45505 CSCtg52703 CSCtg73736 CSCth32206 CSCth35315 CSCth61000 CSCth93690 CSCti07859 Make anyconnect DNS w/ split tunnel behavior for Mac same as windows Agent does not restore DNS Suffix search list if VA dies SCEP enrollment on Mac makes private key exportable from keychain AC cert popup appears even when not requested by ASA Revocation popup when LDAP CRL on outside is blocked OGS selects inaccessible host Anyconnect may show password in clear text in RAM Split-tunneling: filtering needs to be enforced on the VPN adapter Anyconnect should have clear description for each error msg VPN Downloader always aborts first SSL handshake JPN: Status message appeared at bottom is corrupted when disconnected JPN: JPN message garbled when uninstallation runs w/o disconnection VPN connection fails from network with unusual captive portal AnyConnect fails on Panasonic Toughbook when using wireless Captive portal can't be remediated if remediation site in private space Logging is insufficient for troubleshooting captive portal reconnect after resume blocks cisco nac agent discovery Remove GetMUSHostAddr MUS messages when MUS is not enabled AnyConnect 2.x on MAC removing e-token will not allow reconnects AC reports 'certificate validation failed' with VPN LB intermittently Caveats Resolved by AnyConnect Table 22 shows the caveats that AnyConnect Secure Mobility Client Release resolves. Table 22 Caveats Resolved by Cisco AnyConnect Secure Mobility Client Release CSCsz78112 CSCtb11342 CSCtb73046 CSCtc25178 CSCtc35990 CSCtc41770 CSCtc85374 CSCtd00525 CSCtd23416 Long-term fix for Anyconnect with IPv6: non-english Vista Global and user preferences files may get out of sync VPN establishment allowed while multiple local users logged in on Linux Fail to establish tunnel as route table verification fails XP with IPv6 Split-DNS: only requests of type A are tunneled in AnyConnect may fail to connect if split-tunnel-list is huge AnyConnect Profile Editor: View Backup Servers can cause ASDM Hang VPN Agent crashes when locale returns NULL string Linux: Disconnect hangs for minutes following resume from sleep 37
38 Open Caveats in Release Table 22 Caveats Resolved by Cisco AnyConnect Secure Mobility Client Release CSCtd34579 CSCte63458 CSCtf38038 CSCtf16698 CSCtg33029 CSD: Group-URL Fails w/ Pre-Login Policy & Hostscan User impersonation to retrieve proxy settings fails AC on OSX leaks ipv6 traffic that should be tunneled to rogue 6to4 gw MSIE Proxy Lockdown might get stuck after PC reload Schema needs updating for Certs Open Caveats in AnyConnect Table 23 lists the caveats that are unresolved in Cisco AnyConnect Secure Mobility client in AnyConnect Release Table 23 Open Caveats in Cisco AnyConnect Secure Mobility Client Release CSCsh51779 CSCsh69786 CSCsi00491 CSCsm69213 CSCsm92424 CSCsq02996 CSCtg07128 CSCsu08798 CSCsu52949 CSCsu70199 CSCsv49773 CSCsw28876 CSCsw37980 CSCsx21485 CSCsx25806 CSCsx48918 CSCsx62325 CSCsy34111 CSCsy48762 CSCsz56742 CSCta94621 CSCtb73073 CSCtb73259 Client-side proxy & AoN tunneling: must stop direct access to proxy. IPv6 link local addresses are not tunneled through AnyConnect Client. Standalone can connect to wrong ASA from within Secure Desktop Anyconnect does not perform auto route correction on Mac/Linux Random client DPD disconnects with McAfee HIPS SW. Auto-resume sometimes fails even though head-end not timed out. AnyConnect doesn't use IE's exp proxy svr settings telemetry URL req AnyConnect Linux with certs fails if browser master password defined. GUI pops up certificate warning prompts on every connection attempt. IPv6: Network error: windows has detected and IP address conflict. Multiple local profiles for SG may result in using wrong settings. AnyConnect: Need to reboot PC to get localization catalog to load. AC needs more certificate matching events. VPN agent caches cert information. XP IPV6: AnyConnect can't ping assigned IPV6 address. RDP+SBL: Unable to retrieve logon information to verify compliance Windows Mobile driver error with SVC rekey new-tunnel SVC MSIE proxy option auto does not work AnyConnect: Split tunnel does not work with Anyconnect Mobile Will not use certificates under certain ASA configuration Enable local LAN access not consistent with other split tunnel options Mac: VPN establishment allowed while multiple local users logged in Message Connection to the proxy server failed appears during reconnect 38
39 Open Caveats in Release Table 23 Open Caveats in Cisco AnyConnect Secure Mobility Client Release CSCtb80457 CSCtc03052 CSCtc17266 CSCtc43955 CSCtc65842 CSCtc68735 CSCtd59583 CSCtd60540 CSCtd67178 CSCte42921 CSCte46102 CSCte73957 CSCte73983 CSCte85697 CSCte96715 CSCtf04766 CSCtf06844 CSCtf19644 CSCtf20226 CSCtf23946 CSCtf48078 CSCtf52183 CSCtf56830 CSCtf81852 CSCtf90996 CSCtf96386 CSCtf98121 CSCtg01304 CSCtg01525 CSCtg02656 CSCtg04881 CSCtg24945 CSCtg31720 CSCtg31729 CSCtg37737 CSCtg45505 AnyConnect and ASA need to negotiate time-to-wait for authentication SCEP fails in upgrade scenario Private-side proxy on OS X doesn't support per-protocol proxy Anyconnect stuck in Contacting Network and does not timeout Mac GUI crash with SCEP in FIPS mode WM: Long group combo box doesn't have arrows vpnagent exception in filtering code reported on WER Win 7: autoreconnect attempts after standby affects connectivity vpnagent BEX-buffer overflow exception in autoproxy code reported to WER Get Unresolved Gateway Address When Trying to Connect AnyConnect unable to browse websites when connected bad apple config causes session to hang on ASR1k after disconnect bad apple config may cause vpnagentd to fail AnyConnect install fails with -vpn driver encountered an error- message Windows client fails to negotiate AES cipher when available only on gw AnyConnect uses Windows system locale instead of install language AnyConnect SCEP enrollment not working with ASA Per Group Cert Auth With split-exclude, AC LocalLanAccess preference not enabled Make anyconnect DNS w/ split tunnel behavior for Mac same as windows Agent does not restore DNS Suffix search list if VA dies AnyConnect random disconnections SCEP enrollment on Mac makes private key exportable from keychain AC cert popup appears even when not requested by ASA Revocation popup when LDAP CRL on outside is blocked OGS selects inaccessible host Anyconnect may fail to connect when launched from ipass Anyconnect fails when client certificate has empty Subject Split-tunneling: filtering needs to be enforced on the VPN adapter Anyconnect should have clear description for each error msg IgnoreProxy does not work with SBL VPN Downloader always aborts first SSL handshake AC Windows: Failure when reconnecting due to caching of the vpn gw IP JPN: Status message appeared at bottom is corrupted when disconnected JPN: JPN message garbled when uninstallation runs w/o disconnection AnyConnect cannot parse PAC file and does not connect to endpoint VPN connection fails from network with unusual captive portal 39
40 Notices/Licensing Table 23 Open Caveats in Cisco AnyConnect Secure Mobility Client Release CSCtg52703 CSCtg89030 AnyConnect fails on Panasonic Toughbook when using wireless IOS AnyConnect fails when no image is installed for bypassdownloader Notices/Licensing See the following sections for Cisco AnyConnect Secure Mobility client license information. License Options For brief descriptions and example product numbers (SKUs) of the AnyConnect user license options, see Cisco Secure Remote Access: VPN Licensing Overview. For the latest detailed information about the AnyConnect user license options, see Managing Feature Licenses in the Cisco ASA 5500 Series Configuration Guide using the CLI, 8.2. End-User License Agreement For the end-user license agreement, go to: OpenSSL/Open SSL Project This product includes software developed by the OpenSSL Project for use in the OpenSSL Toolkit ( This product includes cryptographic software written by Eric Young This product includes software written by Tim Hudson For Open Source License information for this product, please see the following link: Related Documentation For more information, see the following documents: AnyConnect Secure Mobility Client Features, Licenses, and OSs, Release 3.0 IronPort AsyncOS for Web User Guide IronPort AsyncOS 7.0 for Web Release Notes Navigating the Cisco ASA 5500 Series Documentation Cisco AnyConnect Secure Mobility Client Administrator Guide, Release 2.5 Cisco Secure Desktop Configuration Guide for Cisco ASA 5500 Series Administrators 40
41 Related Documentation Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1110R) Any Internet Protocol (IP) addresses and phone numbers used in this document are not intended to be actual addresses and phone numbers. Any examples, command display output, network topology diagrams, and other figures included in the document are shown for illustrative purposes only. Any use of actual IP addresses or phone numbers in illustrative content is unintentional and coincidental Cisco Systems, Inc. All rights reserved. 41
Quick Startup Installation Instructions. Overview. Important Information
Overview The Cisco AnyConnect VPN Client is the next-generation VPN client, providing remote users with secure VPN connections to Washington Regional Medical System s software applications and services.
Cisco AnyConnect Secure Mobility Client VPN User Messages, Release 3.1
Cisco AnyConnect Secure Mobility Client VPN User Messages, Release 3.1 October 15, 2012 The following user messages appear on the AnyConnect client GUI. A description follows each message, along with recommended
Secure Access Using VPN
Secure Access Using VPN WHAT IS CISCO SSL VPN? Cisco is the brand name of the VPN appliance (hardware). The SSL VPN stands for Secure Sockets Layer Virtual Private Network. SSL VPN is a service that allows
DOE VPN Client Installation and Setup Guide March 2011
DOE VPN Client Installation and Setup Guide March 2011 Table of Contents Introduction... 3 System Requirements... 3 Microsoft Windows... 3 Mac OS X... 4 Windows... 4 Installation for the Cisco AnyConnect
AnyConnect VPN Client FAQ
AnyConnect VPN Client FAQ Document ID: 107391 Questions Introduction What level of rights is required for the AnyConnect client? Is a reboot required after AnyConnect is installed/upgraded? Is it possible
Cisco AnyConnect Secure Mobility Solution Guide
Cisco AnyConnect Secure Mobility Solution Guide This document contains the following information: Cisco AnyConnect Secure Mobility Overview, page 1 Understanding How AnyConnect Secure Mobility Works, page
Release Notes for Cisco AnyConnect Secure Mobility Client, Release 2.5
Release Notes for Cisco AnyConnect Secure Mobility Client, Release 2.5 Updated: May 10, 2010 This document includes the following sections: Introduction New Features New Guidelines Guidelines from Previous
Release Notes for Cisco AnyConnect VPN Client, Release 2.3.nnn
Release Notes for Cisco AnyConnect VPN Client, Release 2.3.nnn Revised: October 04, 2009, Introduction These release notes are for the following Cisco AnyConnect VPN Client releases: 2.3.2016 2.3.254 2.3.185
Clientless SSL VPN Users
Manage Passwords, page 1 Username and Password Requirements, page 3 Communicate Security Tips, page 3 Configure Remote Systems to Use Clientless SSL VPN Features, page 3 Manage Passwords Optionally, you
Release Notes for Cisco AnyConnect Secure Mobility Client, Release 3.0
Release Notes for Cisco AnyConnect Secure Mobility Client, Release 3.0 Last Updated: September 23, 2011 This document includes the following sections: Introduction, page 2 Downloading the Latest Version
The SSL device also supports the 64-bit Internet Explorer with new ActiveX loaders for Assessment, Abolishment, and the Access Client.
WatchGuard SSL v3.2 Release Notes Supported Devices SSL 100 and 560 WatchGuard SSL OS Build 355419 Revision Date January 28, 2013 Introduction WatchGuard is pleased to announce the release of WatchGuard
AnyConnect VPN Client FAQ
AnyConnect VPN Client FAQ Document ID: 107391 Contents Introduction Installation Software Upgrade Licensing Supported Devices Supported Software Log Messages Datagram Transport Layer Security (DTLS) Supported
Symbian User Guide for Cisco AnyConnect Secure Mobility Client, Release 2.4
Symbian User Guide for Cisco AnyConnect Secure Mobility Client, Release 2.4 Updated: May 31, 2011 Contents This document describes the Cisco AnyConnect Secure Mobility Client 2.4 for devices running Symbian.
Citrix Access Gateway Plug-in for Windows User Guide
Citrix Access Gateway Plug-in for Windows User Guide Access Gateway 9.2, Enterprise Edition Copyright and Trademark Notice Use of the product documented in this guide is subject to your prior acceptance
Citrix Access on SonicWALL SSL VPN
Citrix Access on SonicWALL SSL VPN Document Scope This document describes how to configure and use Citrix bookmarks to access Citrix through SonicWALL SSL VPN 5.0. It also includes information about configuring
Configure Posture. Note. Cisco AnyConnect Secure Mobility Client Administrator Guide, Release 4.1 1
The AnyConnect Secure Mobility Client offers an ASA Posture Module and an ISE Posture Module. Both provide the Cisco AnyConnect Secure Mobility Client with the ability to assess an endpoint's compliance
User Manual. Onsight Management Suite Version 5.1. Another Innovation by Librestream
User Manual Onsight Management Suite Version 5.1 Another Innovation by Librestream Doc #: 400075-06 May 2012 Information in this document is subject to change without notice. Reproduction in any manner
Network Connect Installation and Usage Guide
Network Connect Installation and Usage Guide I. Installing the Network Connect Client..2 II. Launching Network Connect from the Desktop.. 9 III. Launching Network Connect Pre-Windows Login 11 IV. Installing
Release Notes for Cisco AnyConnect VPN Client, Release 2.3.nnn
Release Notes for Cisco AnyConnect VPN Client, Release 2.3.nnn Revised: August 03, 2009, Introduction These release notes are for the following Cisco AnyConnect VPN Client releases: 2.3.2016 2.3.254 2.3.185
Dell SonicWALL SRA 7.5 Citrix Access
Dell SonicWALL SRA 7.5 Citrix Access Document Scope This document describes how to configure and use Citrix bookmarks to access Citrix through Dell SonicWALL SRA 7.5. It also includes information about
WatchGuard SSL v3.2 Update 1 Release Notes. Introduction. Windows 8 and 64-bit Internet Explorer Support. Supported Devices SSL 100 and 560
WatchGuard SSL v3.2 Update 1 Release Notes Supported Devices SSL 100 and 560 WatchGuard SSL OS Build 445469 Revision Date 3 April 2014 Introduction WatchGuard is pleased to announce the release of WatchGuard
Installing and Configuring WhatsUp Gold
Installing and Configuring WhatsUp Gold This guide provides information about installing and configuring WhatsUp Gold v14.2, including instructions on how to run the WhatsUp web interface through an Internet
To participate in the hands-on labs in this class, you need to bring a laptop computer with the following:
Course: Deploying Cisco ASA VPN Solutions Duration: 5 Day Hands-On Lab & Lecture Course Price: $ 3,495.00 Learning Credits: 35 Description: The Deploying Cisco ASA VPN Solutions (VPN) v2.0 course is a
Table of Contents. Cisco Cisco VPN Client FAQ
Table of Contents Cisco VPN Client FAQ...1 Questions...1 Introduction...2 Q. Why does the VPN Client disconnect after 30 minutes? Can I extend this time period?...2 Q. I upgraded to Mac OS X 10.3 (known
Getting Started. Symantec Client Security. About Symantec Client Security. How to get started
Getting Started Symantec Client Security About Security Security provides scalable, cross-platform firewall, intrusion prevention, and antivirus protection for workstations and antivirus protection for
Clientless SSL VPN End User Set-up
37 CHAPTER This ections is for the system administrator who sets up Clientless (browser-based) SSL VPN for end users. It summarizes configuration requirements and tasks for the user remote system. It also
Virtual Data Centre. User Guide
Virtual Data Centre User Guide 2 P age Table of Contents Getting Started with vcloud Director... 8 1. Understanding vcloud Director... 8 2. Log In to the Web Console... 9 3. Using vcloud Director... 10
Requirements on terminals and network Telia Secure Remote User, TSRU (version 7.1 R4)
Requirements on terminals and network Telia Secure Remote User, TSRU (version 7.1 R4) Content Page Introduction 2 Platform support 2 Cross Platform support 2 Web and file browsing 2 Client-side Applets
Core Protection for Virtual Machines 1
Core Protection for Virtual Machines 1 Comprehensive Threat Protection for Virtual Environments. Installation Guide e Endpoint Security Trend Micro Incorporated reserves the right to make changes to this
BlackBerry Enterprise Service 10. Version: 10.2. Configuration Guide
BlackBerry Enterprise Service 10 Version: 10.2 Configuration Guide Published: 2015-02-27 SWD-20150227164548686 Contents 1 Introduction...7 About this guide...8 What is BlackBerry Enterprise Service 10?...9
SonicWALL Mobile Connect. Mobile Connect for OS X 3.0. User Guide
SonicWALL Mobile Connect Mobile Connect for OS X 3.0 User Guide Notes, Cautions, and Warnings NOTE: A NOTE indicates important information that helps you make better use of your system. CAUTION: A CAUTION
DameWare Server. Administrator Guide
DameWare Server Administrator Guide About DameWare Contact Information Team Contact Information Sales 1.866.270.1449 General Support Technical Support Customer Service User Forums http://www.dameware.com/customers.aspx
Requirements on terminals and network Telia Secure Remote User, TSRU (version 7.3 R6)
Requirements on terminals and network Telia Secure Remote User, TSRU (version 7.3 R6) Content Page Introduction 2 Platform support 2 Cross Platform support 2 Web and file browsing 2 Client-side Applets
Symantec Integrated Enforcer for Microsoft DHCP Servers Getting Started Guide
Symantec Integrated Enforcer for Microsoft DHCP Servers Getting Started Guide Legal Notice Copyright 2006 Symantec Corporation. All rights reserved. Federal acquisitions: Commercial Software - Government
Sophos UTM. Remote Access via PPTP. Configuring UTM and Client
Sophos UTM Remote Access via PPTP Configuring UTM and Client Product version: 9.000 Document date: Friday, January 11, 2013 The specifications and information in this document are subject to change without
Cisco AnyConnect Secure Mobility Client Administrator Guide
Cisco AnyConnect Secure Mobility Client Administrator Guide Release 3.0 Last Updated: September 14, 2011 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com
BlackBerry Enterprise Service 10. Universal Device Service Version: 10.2. Administration Guide
BlackBerry Enterprise Service 10 Universal Service Version: 10.2 Administration Guide Published: 2015-02-24 SWD-20150223125016631 Contents 1 Introduction...9 About this guide...10 What is BlackBerry
ez Agent Administrator s Guide
ez Agent Administrator s Guide Copyright This document is protected by the United States copyright laws, and is proprietary to Zscaler Inc. Copying, reproducing, integrating, translating, modifying, enhancing,
Tutorial: Assigning Prelogin Criteria to Policies
CHAPTER 4 This tutorial provides an overview of the CSD configuration sequence. The configuration chapters that follow provide detailed instructions on the attributes. The sections are as follows: Overview
Verizon Remote Access User Guide
Version 17.12 Last Updated: August 2012 2012 Verizon. All Rights Reserved. The Verizon names and logos and all other names, logos, and slogans identifying Verizon s products and services are trademarks
Juniper NetScreen IPSec Dial Client. Installation Guide for Windows 2000 Windows XP Windows Vista
Juniper NetScreen IPSec Dial Client Installation Guide for Windows 2000 Windows XP Windows Vista Revision 2.0 NetScreen is a registered trademark of Juniper, Inc. Windows is a registered trademark of Microsoft
The Barracuda Network Connector. System Requirements. Barracuda SSL VPN
Barracuda SSL VPN The Barracuda SSL VPN allows you to define and control the level of access that your external users have to specific resources inside your internal network. For users such as road warriors
Allworx OfficeSafe Operations Guide Release 6.0
Allworx OfficeSafe Operations Guide Release 6.0 No part of this publication may be reproduced, stored in a retrieval system, or transmitted, in any form or by any means, electronic, mechanical, photocopy,
BlackBerry Enterprise Service 10. Version: 10.2. Installation Guide
BlackBerry Enterprise Service 10 Version: 10.2 Installation Guide Published: 2015-08-17 SWD-20150817115607897 Contents 1 About this guide...5 2 What is BlackBerry Enterprise Service 10?... 6 Key features
Introduction to Mobile Access Gateway Installation
Introduction to Mobile Access Gateway Installation This document describes the installation process for the Mobile Access Gateway (MAG), which is an enterprise integration component that provides a secure
MITA End-User VPN Troubleshooting Guide
01. Introduction MITA VPN users can be assigned one of two types of profiles Client-Based or Web-Based, depending on the type of access required. When logging on to the MITA VPN Portal https://vpn.secure.gov.mt,
SSL-VPN 200 Getting Started Guide
Secure Remote Access Solutions APPLIANCES SonicWALL SSL-VPN Series SSL-VPN 200 Getting Started Guide SonicWALL SSL-VPN 200 Appliance Getting Started Guide Thank you for your purchase of the SonicWALL SSL-VPN
For Sales Kathy Hall 402-963-4466 [email protected]
IT4E Schedule 13939 Gold Circle Omaha NE 68144 402-431-5432 Course Number Course Name Course Description For Sales Chris Reynolds 402-963-4465 [email protected] www.it4e.com v2.0 SKY Deploying Cisco ASA
Docufide Client Installation Guide for Windows
Docufide Client Installation Guide for Windows This document describes the installation and operation of the Docufide Client application at the sending school installation site. The intended audience is
Remote Filtering Software
Remote Filtering Software Websense Web Security Solutions v7.7-7.8 1996 2013, Websense, Inc. All rights reserved. 10240 Sorrento Valley Rd., San Diego, CA 92121, USA Published 2013 The products and/or
Workspot Configuration Guide for the Cisco Adaptive Security Appliance
Workspot Configuration Guide for the Cisco Adaptive Security Appliance Workspot, Inc. 1/27/2015 Cisco ASA and Workspot Overview The Cisco Adaptive Security Appliance (ASA) provides organizations with secure,
Freshservice Discovery Probe User Guide
Freshservice Discovery Probe User Guide 1. What is Freshservice Discovery Probe? 1.1 What details does Probe fetch? 1.2 How does Probe fetch the information? 2. What are the minimum system requirements
Configuring AnyConnect VPN Client Connections
CHAPTER 40 The Cisco AnyConnect SSL VPN Client provides secure SSL connections to the security appliance for remote users. Without a previously-installed client, remote users enter the IP address in their
Evaluating the Cisco ASA Adaptive Security Appliance VPN Subsystem Architecture
Deploying Cisco ASA VPN Solutions Volume 1 Course Introduction Learner Skills and Knowledge Course Goal and Course Flow Additional Cisco Glossary of Terms Your Training Curriculum Evaluation of the Cisco
Configuring SSL VPN on the Cisco ISA500 Security Appliance
Application Note Configuring SSL VPN on the Cisco ISA500 Security Appliance This application note describes how to configure SSL VPN on the Cisco ISA500 security appliance. This document includes these
Endpoint Security VPN for Mac
Security VPN for Mac E75 Release Notes 8 April 2012 Classification: [Protected] 2012 Check Point Software Technologies Ltd. All rights reserved. This product and related documentation are protected by
OnCommand Performance Manager 1.1
OnCommand Performance Manager 1.1 Installation and Setup Guide For Red Hat Enterprise Linux NetApp, Inc. 495 East Java Drive Sunnyvale, CA 94089 U.S. Telephone: +1 (408) 822-6000 Fax: +1 (408) 822-4501
Architecture and Data Flow Overview. BlackBerry Enterprise Service 10 721-08877-123 Version: 10.2. Quick Reference
Architecture and Data Flow Overview BlackBerry Enterprise Service 10 721-08877-123 Version: Quick Reference Published: 2013-11-28 SWD-20131128130321045 Contents Key components of BlackBerry Enterprise
Getting Started - Client VPN
Getting Started - Client VPN Symantec Client VPN v9.0 This chapter includes the following topics: What is new in this release on page 2 System requirements on page 3 Documentation on page 3 Upgrading to
VMware vcenter Support Assistant 5.1.1
VMware vcenter.ga September 25, 2013 GA Last updated: September 24, 2013 Check for additions and updates to these release notes. RELEASE NOTES What s in the Release Notes The release notes cover the following
SSL VPN Service. Once you have installed the AnyConnect Secure Mobility Client, this document is available by clicking on the Help icon on the client.
Contents Introduction... 2 Prepare Work PC for Remote Desktop... 4 Add VPN url as a Trusted Site in Internet Explorer... 5 VPN Client Installation... 5 Starting the VPN Application... 6 Connect to Work
vcloud Director User's Guide
vcloud Director 5.5 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition. To check for more recent editions of
Configuration Guide. BlackBerry Enterprise Service 12. Version 12.0
Configuration Guide BlackBerry Enterprise Service 12 Version 12.0 Published: 2014-12-19 SWD-20141219132902639 Contents Introduction... 7 About this guide...7 What is BES12?...7 Key features of BES12...
Implementing Core Cisco ASA Security (SASAC)
1800 ULEARN (853 276) www.ddls.com.au Implementing Core Cisco ASA Security (SASAC) Length 5 days Price $6215.00 (inc GST) Overview Cisco ASA Core covers the Cisco ASA 9.0 / 9.1 core firewall and VPN features.
Accessing the Media General SSL VPN
Launching Applications and Mapping Drives Remote Desktop Outlook Launching Web Applications Full Access VPN Note: To access the Media General VPN, anti-virus software must be installed and running on your
http://docs.trendmicro.com
Trend Micro Incorporated reserves the right to make changes to this document and to the products described herein without notice. Before installing and using the product, please review the readme files,
isupplier PORTAL ACCESS SYSTEM REQUIREMENTS
TABLE OF CONTENTS Recommended Browsers for isupplier Portal Recommended Microsoft Internet Explorer Browser Settings (MSIE) Recommended Firefox Browser Settings Recommended Safari Browser Settings SYSTEM
Release Notes for Cisco AnyConnect Secure Mobility Client, Release 3.1.00495
Release Notes for Cisco AnyConnect Secure Mobility Client, Release 3.1.00495 Last Updated: August 15, 2012 This document includes the following sections: Introduction, page 2 Downloading the Latest Version
Acronis and Acronis Secure Zone are registered trademarks of Acronis International GmbH.
1 Copyright Acronis International GmbH, 2002-2016 Copyright Statement Copyright Acronis International GmbH, 2002-2016. All rights reserved. Acronis and Acronis Secure Zone are registered trademarks of
Kaseya 2. Installation guide. Version 7.0. English
Kaseya 2 Kaseya Server Setup Installation guide Version 7.0 English September 4, 2014 Agreement The purchase and use of all Software and Services is subject to the Agreement as defined in Kaseya s Click-Accept
Citrix Access Gateway Enterprise Edition Citrix Access Gateway Plugin for Windows User Guide. Citrix Access Gateway 9.0, Enterprise Edition
Citrix Access Gateway Enterprise Edition Citrix Access Gateway Plugin for Windows User Guide Citrix Access Gateway 9.0, Enterprise Edition Copyright and Trademark Notice Use of the product documented in
A Guide to New Features in Propalms OneGate 4.0
A Guide to New Features in Propalms OneGate 4.0 Propalms Ltd. Published April 2013 Overview This document covers the new features, enhancements and changes introduced in Propalms OneGate 4.0 Server (previously
Introduction to Endpoint Security
Chapter Introduction to Endpoint Security 1 This chapter provides an overview of Endpoint Security features and concepts. Planning security policies is covered based on enterprise requirements and user
Kaseya Server Instal ation User Guide June 6, 2008
Kaseya Server Installation User Guide June 6, 2008 About Kaseya Kaseya is a global provider of IT automation software for IT Solution Providers and Public and Private Sector IT organizations. Kaseya's
Windows and MAC User Handbook Remote and Secure Connection Version 1.01 09/19/2013. User Handbook
Windows and MAC User Handbook How to Connect Your PC or MAC Remotely and Securely to Your U.S. Department of Commerce Account Developed for You by the Office of IT Services (OITS)/IT Service Desk *** For
WhatsUp Gold v16.3 Installation and Configuration Guide
WhatsUp Gold v16.3 Installation and Configuration Guide Contents Installing and Configuring WhatsUp Gold using WhatsUp Setup Installation Overview... 1 Overview... 1 Security considerations... 2 Standard
AT&T Global Network Client User s Guide
Version 9.0.2 AT&T Global Network Client User s Guide 2012 AT&T Intellectual Property. All rights reserved. AT&T, the AT&T logo and all other AT&T marks contained herein are trademarks of AT&T Intellectual
Synchronizer Installation
Synchronizer Installation Synchronizer Installation Synchronizer Installation This document provides instructions for installing Synchronizer. Synchronizer performs all the administrative tasks for XenClient
Installing Management Applications on VNX for File
EMC VNX Series Release 8.1 Installing Management Applications on VNX for File P/N 300-015-111 Rev 01 EMC Corporation Corporate Headquarters: Hopkinton, MA 01748-9103 1-508-435-1000 www.emc.com Copyright
RSM Web Gateway RSM Web Client INSTALLATION AND ADMINISTRATION GUIDE
RSM Web Gateway RSM Web Client INSTALLATION AND ADMINISTRATION GUIDE Installation and Administration Guide RSM Web Client and RSM Web Gateway 17 August, 2004 Page 1 Copyright Notice 2004 Sony Corporation.
Release Notes for Websense Email Security v7.2
Release Notes for Websense Email Security v7.2 Websense Email Security version 7.2 is a feature release that includes support for Windows Server 2008 as well as support for Microsoft SQL Server 2008. Version
Cisco IOS SSL VPN: Router-Based Remote Access for Employees and Partners
Cisco IOS SSL VPN: Router-Based Remote Access for Employees and Partners Product Overview Cisco IOS SSL VPN is the first router-based solution offering Secure Sockets Layer (SSL) VPN remote-access connectivity
Using Cisco UC320W with Windows Small Business Server
Using Cisco UC320W with Windows Small Business Server This application note explains how to deploy the Cisco UC320W in a Windows Small Business Server environment. Contents This document includes the following
Configuration Guide BES12. Version 12.1
Configuration Guide BES12 Version 12.1 Published: 2015-04-22 SWD-20150422113638568 Contents Introduction... 7 About this guide...7 What is BES12?...7 Key features of BES12... 8 Product documentation...
Endpoint Security VPN for Windows 32-bit/64-bit
Endpoint Security VPN for Windows 32-bit/64-bit E75.20 User Guide 13 September 2011 2011 Check Point Software Technologies Ltd. All rights reserved. This product and related documentation are protected
new Business Online Technical Troubleshooting Guide
new Business Online Technical Troubleshooting Guide TABLE OF CONTENTS How to install Java 1.6 Page 3 How to install Java 1.6 without ActiveX control Page 6 How to uninstall Java Runtime Environment Page
IBM Remote Lab Platform Citrix Setup Guide
Citrix Setup Guide Version 1.8.2 Trademarks IBM is a registered trademark of International Business Machines Corporation. The following are trademarks of International Business Machines Corporation in
FileMaker Server 14. FileMaker Server Help
FileMaker Server 14 FileMaker Server Help 2007 2015 FileMaker, Inc. All Rights Reserved. FileMaker, Inc. 5201 Patrick Henry Drive Santa Clara, California 95054 FileMaker and FileMaker Go are trademarks
www.novell.com/documentation SSL VPN User Guide Access Manager 3.1 SP5 January 2013
www.novell.com/documentation SSL VPN User Guide Access Manager 3.1 SP5 January 2013 Legal Notices Novell, Inc., makes no representations or warranties with respect to the contents or use of this documentation,
Installation Guide for Pulse on Windows Server 2008R2
MadCap Software Installation Guide for Pulse on Windows Server 2008R2 Pulse Copyright 2014 MadCap Software. All rights reserved. Information in this document is subject to change without notice. The software
Kaspersky Endpoint Security 8 for Linux INSTALLATION GUIDE
Kaspersky Endpoint Security 8 for Linux INSTALLATION GUIDE A P P L I C A T I O N V E R S I O N : 8. 0 Dear User! Thank you for choosing our product. We hope that this documentation will help you in your
Topaz Installation Sheet
Topaz Installation Sheet P/N 460924001E ISS 08FEB12 Content Introduction... 3 Recommended minimum requirements... 3 Setup for Internet Explorer:... 4 Topaz installation... 10 Technical support... 14 Copyright
SyncThru TM Web Admin Service Administrator Manual
SyncThru TM Web Admin Service Administrator Manual 2007 Samsung Electronics Co., Ltd. All rights reserved. This administrator's guide is provided for information purposes only. All information included
ASA 8.x: VPN Access with the AnyConnect VPN Client Using Self Signed Certificate Configuration Example
ASA 8.x: VPN Access with the AnyConnect VPN Client Using Self Signed Certificate Configuration Example Document ID: 99756 Contents Introduction Prerequisites Requirements Components Used Conventions Background
2. Installation and System requirements
RELEASE NOTES F-Secure Anti-Virus for Windows Servers Version 9.00 build 333 Copyright 1993-2010 F-Secure Corporation. All Rights Reserved. Portions Copyright 2004 BackWeb Technologies Inc. This product
Installation Notes for Outpost Network Security (ONS) version 3.2
Outpost Network Security Installation Notes version 3.2 Page 1 Installation Notes for Outpost Network Security (ONS) version 3.2 Contents Installation Notes for Outpost Network Security (ONS) version 3.2...
How To Upgrade A Websense Log Server On A Windows 7.6 On A Powerbook (Windows) On A Thumbdrive Or Ipad (Windows 7.5) On An Ubuntu 7.3.2 (Windows 8) Or Windows
Websense v7.6 Install or Upgrade Checklist Greetings from Websense Technical Support. Most Websense upgrades complete successfully, and from my years of troubleshooting, I have learned a number of steps
Networking Best Practices Guide. Version 6.5
Networking Best Practices Guide Version 6.5 Summer 2010 Copyright: 2010, CCH, a Wolters Kluwer business. All rights reserved. Material in this publication may not be reproduced or transmitted in any form
XenClient Enterprise Synchronizer Installation Guide
XenClient Enterprise Synchronizer Installation Guide Version 5.1.0 March 26, 2014 Table of Contents About this Guide...3 Hardware, Software and Browser Requirements...3 BIOS Settings...4 Adding Hyper-V
Installing and Configuring vcenter Multi-Hypervisor Manager
Installing and Configuring vcenter Multi-Hypervisor Manager vcenter Server 5.1 vcenter Multi-Hypervisor Manager 1.1 This document supports the version of each product listed and supports all subsequent
