Cisco AnyConnect Client Installation Guide B27838, published June 23, 2015
2015 CDK Global, LLC. All rights reserved. The CDK logo is a trademark of CDK Global, LLC. Search Keywords: Cisco AnyConnect Installation Guide, AnyConnect Installation, AnyConnect, VPN, Cisco, B27838. ii
Table of Contents Windows OS-based Installation... 4 Supported OS version... 4 Installation Procedure... 4 Download and Auto-Configure Cisco AnyConnect... 4 Download and Manually Configure the Cisco AnyConnect... 5 How to connect after install... 5 Mac OS-based Installation... 5 Supported OS version... 5 Installation Procedure... 5 Download and Auto-Configure Cisco AnyConnect... 5 Download AnyConnect from Cisco and Manually Configure... 6 How to connect after install... 7 Linux OS-based Installation... 7 Supported OS Version... 7 Installation Procedure... 7 Download and Auto Configure the Cisco AnyConnect... 7 Download AnyConnect from Cisco and Manually Configure... 7 How to connect after install... 8 Android OS-based Installation... 8 Installation Procedure... 9 Device Configuration... 9 How to connect after install... 10 Apple ios-based Installation... 10 Installation Procedure... 10 Device Configuration... 10 How to connect after install... 11 Learn More... 12 B27838, published June 23, 2015
Windows OS-based Installation The following sections describe AnyConnect installation for desktop and laptop systems with a Microsoft Windows Operating System. Note: Windows RT is not supported as of AnyConnect 3.1 Supported OS version Windows XP SP3 x86 (32-bit) Windows XP SP2 x64 (64-bit) Windows Vista x86 (32-bit) and x64 (64-bit) Windows 7 x86 (32-bit) and x64 (64-bit) Windows 8, 8.1, and 8.1 Update 1 x86 (32-bit) and x64 (64-bit) Installation Procedure You can download and automatically configure Any Connect (which uses xml profiles in the Cisco ASA) by accessing the Cisco ASA webpage or by downloading and configuring the ASA. Both are show in the sections below. Download and Auto-Configure Cisco AnyConnect 1. Open a web browser and enter the following URL https://<url. ADDRESS of Cisco ASA>, using either the internal or external IP Address of the Cisco ASA or Hostname (whichever is applicable). Note: You may receive certificate errors depending on if a valid certificate for Cisco ASA has been published. Click the certificate error in the URL bar to view the certificate. Import/Install this certificate to prevent certificate errors in the future. Import it to the local machine and place it in the Trusted Root Certification Authorities certificate store. You may need administrator privileges to do this. 2. Select your group and login using your VPN username and password. Note: The webpage will detect the OS and the browser used. Depending on the browser used, the webpage may or may not try to install by ActiveX. 3. The webpage will first try to install by ActiveX. This will only work if using Internet Explorer as browser. Click Allow, Install or Connect Anyway to proceed through any install prompts received. You will need administrator privileges for the install to proceed. 4. Once the installation is complete, it will automatically connect to the VPN. If it fails, it will install by Java. 5. The webpage will try to install by Java, click Allow/Proceed/Continue/Connect Anyway through the install prompts received. Note: For Java installation to work, you may need to add the url you are using for the AnyConnect installation on your browser to the Java control panel security exception list and set signed code certification revocation checking to 4
Mac OS-based Installation do not check on Java control panel advance settings temporarily before installation. If Java fails, you will be given prompts to either retry or download the executable file and install manually. Refer to the Download and Manually Configure Cisco AnyConnect section below. 6. Once a VPN connection has been established, a message will display indicating the connection was successful. Download and Manually Configure the Cisco AnyConnect 1. Download the Cisco AnyConnect installer/executable file either from the Cisco site, a file store server or from the download link when the web installation of the Cisco AnyConnect fails. 2. Run the executable and install until completion. Use default settings. 3. Run the Cisco AnyConnect application and input the internet IP/hostname of the Cisco ASA then connect. It will now connect to the VPN and download the necessary settings or for future use. How to connect after install 1. Run the Cisco AnyConnect application and select your VPN connection site from the dropdown menu then click Connect. 2. Select your group. Login using your VPN credentials. 3. You will be now connected by VPN to your office network. A popup will display you have successfully connected and there will also be an icon in the system tray. Mac OS-based Installation The following sections describe AnyConnect installation for desktop and laptop systems with a Mac OS X Operating System. Supported OS version Mac OS X 10.8 (Mountain Lion) x86 (32-bit) or x64 (64-bit) Mac OS X 10.9 (Mavericks) x86 (32-bit) or x64 (64-bit) Mac OS X 10.10 (Yosemite) x86 (32-bit) or x64 (64-bit) Installation Procedure Download and Auto-Configure Cisco AnyConnect 1. Open a web browser and enter the following URL https://<url. ADDRESS of Cisco ASA>, using either the internal or external IP Address of the Cisco ASA or hostname (whichever is applicable). Note: You may receive certificate errors depending on if a valid certificate for Cisco ASA has been published. Click the certificate error in the URL bar to view the certificate. Import/Install this certificate to prevent certificate errors in the 5
future. Import it to the local machine and place it in the Trusted Root Certification Authorities certificate store. You may need administrator privileges to do this. 2. Select your group. Login using your VPN username and password. 3. The file will mount a disk image named AnyConnect <version number>. Open this disk image and launch the file AnyConnect.pkg. 4. Click Continue on the Install VPN Client pop-up window that appears. 5. Click Continue on the remaining prompts, until you get to the Software License Agreement. At this page, click Agree on the slide-down menu. 6. From the Standard Install window, click Install and enter your computer username and password. Once the install is complete, click Close. Note: You must be the Administrator of the machine to install. 7. Navigate to Applications/Cisco and open Cisco AnyConnect VPN Client. 8. In the Connect To field, enter the internal or external IP Address or hostname of the Cisco ASA and click Select 9. Enter your VPN username and password and click Connect. 10. Once the connection is established, Cisco AnyConnect will minimize and you will see the AnyConnect logo with a small lock in your menu bar. Download AnyConnect from Cisco and Manually Configure 1. Download the Cisco AnyConnect installer/executable file either from the Cisco site, a file server or from the Web link when the web installation of the Cisco AnyConnect fails. 2. The file will mount a disk image named AnyConnect <version number>. Open the disk image and launch the file AnyConnect.pkg. 3. Click Continue on the Install VPN Client pop-up window that appears. 4. Click Continue on the remaining prompts, until you get to the Software License Agreement. At this page, click Agree on the slide-down menu. 5. From the Standard Install window, click Install and enter your computer username and password. Once the install is complete, click Close. Note: You must be the Administrator of the machine to install. 6. Navigate to Applications/Cisco and open Cisco AnyConnect VPN Client. 7. In the Connect To field, enter the internal or external IP Address or hostname of the Cisco ASA and click Select 8. Enter your VPN username and password and click Connect. 9. Once the connection is established, Cisco AnyConnect will minimize and you will see the AnyConnect logo with a small lock in your menu bar. 6
Linux OS-based Installation How to connect after install 1. Run the Cisco AnyConnect application and select your VPN connection site from the dropdown menu then click Connect. 2. Select your group. Login using your VPN credentials. 3. You will now be connected by VPN to your office network. A popup will display you have successfully connected and there will also be an icon in the system tray. Linux OS-based Installation The following sections describe AnyConnect installation for desktop and laptop systems with a Linux Operating System. Note: The required file for installing Linux Cisco AnyConnect from the Cisco ASA may not be available due to flash size constraint. Supported OS Version Red Hat Enterprise Linux 6.x (32-bit) and 6.4 (64-bit) Ubuntu 9.x, 10.x, and 11.x (32-bit) and Ubuntu 12.04 & 12.10 (64-bit) Installation Procedure Download and Auto Configure the Cisco AnyConnect 1. Open a web browser and enter the following URL https://<url. ADDRESS of Cisco ASA>, using either the internal or external IP Address of the Cisco ASA or hostname (whichever is applicable). Note: You may receive certificate errors depending on if a valid certificate for Cisco ASA has been published. Enable any option that lets you save the certificate or add as an exemption for future use. 2. Select your group. Login using your VPN username and password. 3. Installation will begin and requires that Java runtime and plugin is installed on the machine and browser. 4. While the webpage tries to install Cisco AnyConnect, some verification prompts will appear. Click Allow/Run to proceed. If Java fails, you will be given prompts to either retry or download the executable file and install manually. Refer to the Download and Manually Configure Cisco AnyConnect section below. Download AnyConnect from Cisco and Manually Configure 1. Download the Cisco AnyConnect installer/executable file either from the Cisco site, a file server or from the Web link when the web installation of the Cisco AnyConnect fails. 7
2. Open a terminal and navigate to the location of the downloaded file. Extract the file. Replace the version number with the version of the Cisco AnyConnect you have. 3. Navigate to the directory that contains the vpnsetup.sh file. 4. Enter the following to make sure the script is executable. 5. Enter the following to verify your Administrative rights. Note. You may need to use the su command in other Linux distributions to get administrative rights. 6. Once the setup begins, you should see the following: 7. Run the Cisco AnyConnect application and input the internet IP/hostname of the Cisco ASA then connect. It will now connect to the VPN and download the necessary settings or for future use. How to connect after install 1. Run the Cisco AnyConnect application and select your VPN connection site from the dropdown menu then click Connect. 2. Select your group and login using your VPN credentials. 3. You will now be connected by VPN to your office network. A popup will display you have successfully connected and there will also be an icon in the system tray. Android OS-based Installation The following sections describe AnyConnect installation on a tablet and smartphone with an Android Operating System. Note: A generic AnyConnect version can be used on any Android device running Android v4.0 or later. 8
Android OS-based Installation Installation Procedure AnyConnect for Android is available for download only from the Android Market. Note: You cannot download it from the Cisco website or after connecting to a secure gateway. Cisco provides brand-specific AnyConnect packages that offer full-featured VPN connections for these devices. These brand-specific AnyConnect clients are provided in partnership with the device vendors and are the preferred AnyConnect clients for supported devices. 1. Use the following to determine if your device is one of the supported devices and install the appropriate brand-specific AnyConnect package. Samsung Devices, install Samsung AnyConnect Note: For supported Samsung versions for AnyConnect Release 3.0: Samsung Devices HTC Devices, install HTC AnyConnect Note: For supported HTC versions for AnyConnect Release 3.0: HTC Devices Kindle Devices, install Cisco AnyConnect (Kindle Tablet Edition). Note: For supported Kindle versions for AnyConnect Release 3.0: Kindle Devices 2. Determine if your device is running Android (Ice Cream Sandwich) or later to install AnyConnect ICS+. Device Configuration 1. Tap the AnyConnect Icon to start the AnyConnect app. 2. If this is the first time that you are starting AnyConnect after installing or upgrading, accept the displayed End User License Agreement to continue. 3. Tap Add New VPN Connection to configure a connection entry. 4. Optional: Choose Description to enter a descriptive name for the connection entry. Enter a unique name for this connection entry. Note: If not specified, the Server Address is used as the default. Use any letters, spaces, numbers, or symbols on the keyboard display. This field is case-sensitive. 5. Choose Server Address to enter the address of the secure gateway. 6. Enter the internal or external IP address or hostname of the Cisco ASA, including a group if specified by your administrator. 7. Tap Done in both the Advanced window and the Connection Editor window to save the connection values. 8. Toggle AnyConnect to ON to establish VPN connection. 9
How to connect after install 1. Tap the AnyConnect icon to start the AnyConnect app. 2. Toggle AnyConnect to ON to establish VPN connection. 3. Select your group and login using your VPN credentials. 4. You will now be connected by VPN to your office network. A popup will display you have successfully connected and there will also be an icon in the system tray. Apple ios-based Installation The following sections describe AnyConnect installation on a tablet and smartphone with an Apple ios Operating System. Installation Procedure Determine if the Apple ios device is supported by AnyConnect 3.0 using the following link: Supported Apple ios Devices. Install the Cisco AnyConnect Secure Mobility client, as follows: 1. Open the Apple App Store. 2. Search for Cisco AnyConnect 3. Tap AnyConnect 4. Tap Get, then tap Install App. Device Configuration 1. Tap the AnyConnect Icon to start the AnyConnect app. 2. If this is the first time that you are starting AnyConnect after installing or upgrading, accept the displayed End User License Agreement to continue. 3. A confirmation opens the first time you start AnyConnect on the device. Tap Add New VPN Connection to configure a connection entry. Optional: Choose Description to enter a descriptive name for the connection entry. Enter a unique name for this connection entry. Note: If not specified, the Server Address is used as the default. Use any letters, spaces, numbers, or symbols on the keyboard display. This field is case-sensitive. 4. Choose Server Address to enter the address of the secure gateway. Enter the domain name or IP address of the secure gateway, including a group, if specified by your administrator. 5. Tap Done in both the Advanced window and the Connection Editor window to save the connection values. 6. Toggle AnyConnect to ON to establish VPN connection. 10
Apple ios-based Installation How to connect after install 1. Tap the AnyConnect icon to start the AnyConnect app. 2. Toggle AnyConnect to ON to establish VPN connection. Note: You may receive a block page saying that you are connecting to an untrusted server. This is due to the Cisco ASA not using a published certificate and it is normal. Click Change Settings and disable Block Untrusted Servers to allow the VPN connection. Retry the VPN connection and you will be given an option to view certificate Detail and Import it. 3. Select your group and login using your VPN credentials. 4. You will now be connected by VPN to your office network. A popup will display you have successfully connected and there will also be an icon in the system tray. Note: If you disabled the Block Untrusted Servers under step 2, you may now enable it again as you already imported the certificate and is now trusted. 11
Learn More Release Essentials For information about new product releases, go to your application Help menu and select Release Essentials. Online Help Get instant information about your application screen. Click the Help button context help in CDK Drive and other applications. or F1 for Service Connect Get expert support and guidance without picking up the phone or leaving your desktop. You can search the document library, collaborate with industry peers in the Service Connect Community, web chat with Support, and more. Click the Service Connect tab on your desktop to get started, or download the mobile app for Apple or Android. CDK Learning Connect Access hundreds of training courses, easy-to-use tools, and interactive resources. Log in for current schedules, registration, instructor-led learning, and e-learning. USA and Canada: cdklearningconnect.com Canada Français: cdklearningconnect.fr Additional Resources Forms and Supplies Call the number below and request supplies using the EasySource catalog number, or send an email to easysource@cdk.com with the following information: CMF number, dealership name, contact name, phone. USA: 800-237-2372 Canada: 877.847.9276 12