Cisco AnyConnect
Institutes and facilities of the TU Dresden can use the Cisco AnyConnect Secure Mobility Client software in order to have protected access from the according institute networks to the TU Dresden network.
Cisco AnyConnect uses VPN Tunnel via the default SSL port (TCP 443) and DTLS port (UDP 443). Both ports must be opened in your firewall otherweise the performance could get low.
When building the VPN connection your PC will get an IP address from within the according network.
Cisco AnyConnect has some features to afford:
- obviously less connection problems from within external networks, because HTTPS is not as restricted as IPSec VPN
- automatical reconnection during a network change, e.g. via WLAN
- siginificantly easier installation of the software
- automatic software update via the VPN-Gateway
- Linux version independent from the kernel version
Installation
AnyConnect is supported by the following operating systems:
Operating System | Automatical Installation via Browser |
Configuration for manual Installation |
supported versions |
---|---|---|---|
Windows 10 and 11 x86(32bit) and x64(64bit) |
Yes | Windows 10 | Windows 11 (64-bit) and current Microsoft supported versions of Windows 10 x86 (32-bit) and x64 (64-bit) |
Linux 64bit | No | Linux 64bit | officially supported are: Linux Red Hat 9.x and 8.x & Ubuntu LTS 22.04 and 20.04 ( it may also work with other distributions) |
Mac OS X 13, 2, 11 (all 64-bit only) | Yes | Mac OS X | macOS 14 Sonoma, macOS 13 Ventura, and macOS 12 Monterey, and macOS 11 Big Sur (all 64-bit) |
Cisco AnyConnect Software
The Client Software Cisco AnyConnect is necessary for the use of SSL VPN. Due to trademark and licensing laws a software download is only allowed with a valid ZIH Login. Admin rights are necessary for the first installation.
From 11.01.2024, the VPN Gateway will have a new server certificate and AnyConnect will check this against the new TU Dresden root certificate:
SectigoChain.pem
If you get an error like "Untrusted VPN server certificate" you can import this root certificate chain to the trusted root certificate store on your local system.
Windows - ATTENTION: when upgrading Windows the Cisco AnyConnect Client should be deinstalled before the upgrade. Otherwise, the software may not work any longer.
The installation files for Windows have to be stored as *.msi files and the Transform-File as *.mst . If this should not work automatically, you have to right-click on the link and choose the option "save target as...". Afterwards you have to select "All files" and complete the file's name with ".msi" and ".mst" respectively. The file is stored properly then.
Version AnyConnect 4.10.08025
- AnyConnect for Linux 64bit (Version 4.10.08025)
- AnyConnect for Mac OS X on ARM and Intel Platform (Version 4.10.08025)
- AnyConnect for Windows (Version 4.10.08025)
- Transform-File (.mst) for Windows - Turn Customer Experience Feedback (CEF) off:
To enable the transform file run the following command in cmd window (so CEF is being turned OFF):
msiexec -i anyconnect-win-4_10_08025-core-vpn-predeploy-k9.msi TRANSFORMS=anyconnect-win-disable-customer-experience-feedback-4_10_08025.mst - NAM (Version 4.10.08025) - Network Access Management Tool for Windows
for network access management in Windows when using 802.1X for network authentication on dyport.- to manage cable and WiFi data network connections via the NAM module, the file tud-nam-profile.nsp has to be copied to
C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\Network Access Manager\system and rename it to "configuration.xml" - to manage only cable data network connections via the NAM module and WiFi connections via the on-board tools of the Windows operating system, the file
tud-nam-profile_NoWifi.nsp has to be copied to
C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\Network Access Manager\system and rename it to "configuration.xml"
- to manage cable and WiFi data network connections via the NAM module, the file tud-nam-profile.nsp has to be copied to
- PE (Version 4.10.08025) - Profile Editor Tool for Windows
- DART (Version 4.10.08025) - AnyConnect Problem Analyzer for Windows
- AnyConnect for Windows ARM (Version 4.10.08025)
Version AnyConnect 4.10.07061 and for Windows Systems in version 4.10.07062
- AnyConnect for Linux 64bit (Version 4.10.07061)
- AnyConnect for Mac OS X on ARM and Intel Platform (Version 4.10.07061)
- AnyConnect for Windows (Version 4.10.07062)
- Transform-File (.mst) for Windows - Turn Customer Experience Feedback (CEF) off:
To enable the transform file run the following command in cmd window (CEF thus is being turned OFF):
msiexec -i anyconnect-win-4_10_07062-core-vpn-predeploy-k9.msi TRANSFORMS=anyconnect-win-disable-customer-experience-feedback-4_10_07062.mst - NAM (Version 4.10.07062) - Network Access Management Tool for Windows
for network access management in Windows when using 802.1X for network authentication on dyport.- to manage cable and WiFi data network connections via the NAM module, the file tud-nam-profile.nsp has to be copied to
C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\Network Access Manager\system and rename it to "configure.xml" - to manage only cable data network connections via the NAM module and WiFi connections via the on-board tools of the Windows operating system, the file
tud-nam-profile_NoWifi.nsp has to be copied to
C:\ProgramData\Cisco\Cisco AnyConnect Secure Mobility Client\Network Access Manager\system and rename it to "configure.xml"
- to manage cable and WiFi data network connections via the NAM module, the file tud-nam-profile.nsp has to be copied to
- PE (Version 4.10.07061) - Profile Editor Tool for Windows
- DART (Version 4.10.07062) - AnyConnect Problem Analyzer for Windows
- AnyConnect for Windows ARM (Version 4.10.07061)
!! older versions are not recommended anymore due to vulnerabilities !!
Old AnyConnect versions for "Windows Mobile" (not supported anymore).