Cisco AnyConnect
Institutes and facilities of the TU Dresden can use the recommended software Cisco AnyConnect Secure Mobility Client in order to have protected access from the according institute networks to the TU Dresden network.
Cisco AnyConnect uses VPN Tunnel via the default SSL port (TCP 443) and DTLS port (UDP 443). Both ports must be opened in your firewall otherweise the performance could get low.
When building the VPN connection your PC will get an IP address from within the according network.
Cisco AnyConnect has some features to afford:
- obviously less connection problems in external networks, because https is not as restricted as IPSec VPN
- automatical reconnection during a network change, e.g. via WLAN
- siginificantly easier installation of the software
- automatical software update via the VPN-Gateway
- Linux version independent from the kernel version
Installation
AnyConnect is supported by the following operating systems:
Operating System | Automatical Installation via Browser |
Configuration for manual Installation |
Information |
---|---|---|---|
Windows 7 SP1, 8.1, 10 (32bit and 64bit) |
Yes | Windows 7, 8.1, Windows 10 |
Windows 8 - ATTN: Windows 8 ist not supported by the current Version of AnyConnect Windows 10: the Cisco AnyConnect Client SHOULD be deinstalled before Upgrade |
Linux 64bit | No | Linux 64bit | officially supported are: Linux Red Hat 6, 7 & Ubuntu 14.04 (LTS),16.04 (LTS), and 18.04 (LTS) (64-bit only) ( it may also work with other distributions) -- Ubuntu 15.x is not supported please use openconnect |
Mac OS X 10.11, 10.12, 10.13 and 10.14 | Yes | Mac OS X 10.11, 10.12, 10.13, and 10.14 | AnyConnect will NOT work with MacOSX 10.5 and it is no longer supported for MacOSX versions 10.6 to 10.10 also |
Windows Mobile 5.0, 6.0, 6.1 and 6.5 |
Yes |
Cisco AnyConnect Software
The Client Software Cisco AnyConnect is necessary for the use of SSL VPN. Due to trademark and licensing laws a software download is only allowed with a valid ZIH Login. Admin rights are necessary for the first installation.
Windows - ATTENTION: when upgrading Windows the Cisco AnyConnect Client SHOULD be deinstalled before the upgrade. Otherwise, the software may not work any longer.
The installation files for Windows have to be stored as *.msi files and the Transform-File as *.mst . If this should not work automatically, you have to right-click on the link and choose the option "save target as...". Afterwards you have to select "All files" and complete the file's name with ".msi". The file can now be stored properly.
Version AnyConnect 4.6.03049:
- AnyConnect for Linux 64bit (Version 4.6.03049)
- AnyConnect for Mac OS X (Version 4.6.03049)
- AnyConnect for Windows (Version 4.6.03049)
Transform-File (.mst) for Windows - turn Customer Experience Feedback(CEF) off: To enable the transform file run the following command in cmd window (CEF thus is being turned OFF):
msiexec -i anyconnect-win-4_6_03049-core-vpn-predeploy-k9.msi TRANSFORMS=anyconnect-win-disable-customer-experience-feedback-4_6_03049.mst - DART - AnyConnect Problem Analyzer
- NAM - Network Access Manager
- PE - Profile Editor Tool (Windows)
Version AnyConnect 4.5.03040:
- AnyConnect for Linux 64bit (Version 4.5.03040)
- AnyConnect for Mac OS X (Version 4.5.03040)
- AnyConnect for Windows (Version 4.5.03040)
Transform-File (.mst) for Windows - turn Customer Experience Feedback(CEF) off: To enable the transform file run the following command in cmd window (CEF thus is being turned OFF):
msiexec -i anyconnect-win-4_5_03040-core-vpn-predeploy-k9.msi TRANSFORMS=anyconnect-win-disable-customer-experience-feedback-4_5_03040.mst - DART - AnyConnect Problem Analyzer
- NAM - Network Access Manager
- PE - Profile Editor Tool (Windows)
Version AnyConnect 4.5.01044:
- AnyConnect für Linux 64bit (Version 4.5.01044)
- AnyConnect für Mac OS X auf Intel (Version 4.5.01044)
- AnyConnect für Windows (Version 4.5.01044)
Transform-Datei (.mst) für Windows - Abschalten des Customer Experience Feedback(CEF) : To enable the transform file run the following command in cmd window (CEF thus is being turned OFF):
msiexec -i anyconnect-win-4-5-01044-core-vpn-predeploy-k9.msi TRANSFORMS=anyconnect-win-disable-customer-experience-feedback-4-5-01044.mst
!! older version but 4.5.01044 are not recommended anymore due to vulnerabilities !!
The AnyConnect versions for mobiles: