# Cisco ASA Anyconnect Remote Access VPN

**URL:** https://forum.networklessons.com/t/cisco-asa-anyconnect-remote-access-vpn/833
**Category:** Lessons Discussion
**Created:** [December 19, 2016, 4:41pm UTC](https://forum.networklessons.com/t/cisco-asa-anyconnect-remote-access-vpn/833 "2016-12-19T16:41:39Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [December 19, 2016, 4:41pm UTC](https://forum.networklessons.com/t/cisco-asa-anyconnect-remote-access-vpn/833/1 "2016-12-19T16:41:39Z")

</div>

This topic is to discuss the following lesson:

> **[Cisco ASA Anyconnect Remote Access VPN](https://networklessons.com/cisco/asa-firewall/cisco-asa-anyconnect-remote-access-vpn)**
>
> This lesson explains how to configure the Cisco ASA firewall to allow remote SSL VPN users to connect with the Anyconnect client.

---

<div class="post-metadata">

### Author: ![r.grant3779](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/r/e68b1a/32.png) [@r.grant3779](https://forum.networklessons.com/u/r.grant3779)
#### Post date: [July 13, 2015, 1:02pm UTC](https://forum.networklessons.com/t/cisco-asa-anyconnect-remote-access-vpn/833/2 "2015-07-13T13:02:59Z")

</div>

Hi Rene,

For this part here -

The DNS server 8.8.8.8 will be assigned to remote VPN users.

When connected to the VPN, If the users are trying to access Internal Corporate machines via DNS name, should we provide an Internal DNS server address rather than 8.8.8.8

Thanks  
Rob

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [July 13, 2015, 1:52pm UTC](https://forum.networklessons.com/t/cisco-asa-anyconnect-remote-access-vpn/833/3 "2015-07-13T13:52:38Z")

</div>

Hi Rob,

That would work yes, there are also some other solutions. Take a look at this Cisco post:

> **[Examine the Behavior of DNS Queries and Domain Name Resolution](https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/116016-technote-AnyConnect-00.html)**
>
> This document describes how Cisco OS® handles DNS queries and the effects on domain name resolution with Cisco AnyConnect and split or full tunneling.

Rene

---

<div class="post-metadata">

### Author: ![gordonflash984](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/g/4bbf92/32.png) [@gordonflash984](https://forum.networklessons.com/u/gordonflash984)
#### Post date: [July 15, 2015, 8:26pm UTC](https://forum.networklessons.com/t/cisco-asa-anyconnect-remote-access-vpn/833/4 "2015-07-15T20:26:28Z")

</div>

Rene

Which ASA model does your configuration examples apply to? Would you give some thought to doing a video similar to the one about choosing routers and switches but topic would be choosing firewalls.

Thanks

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [July 15, 2015, 8:31pm UTC](https://forum.networklessons.com/t/cisco-asa-anyconnect-remote-access-vpn/833/5 "2015-07-15T20:31:21Z")

</div>

Hi Donald,

I used the ASA 5510 for most of these examples. The big difference between the ASA 5505 and all the other models is that it’s the only firewall that has 4 switchports.

The 5510 only has L3 interfaces, it doesn’t have switchports. The ASA 5506 that replaces the 5505 also doesn’t have switchports anymore.

A video for the different firewalls might be a good idea, for labs the ASA 5510 with security plus license is probably the best choice for now.

Rene

---

<div class="post-metadata">

### Author: ![gordonflash984](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/g/4bbf92/32.png) [@gordonflash984](https://forum.networklessons.com/u/gordonflash984)
#### Post date: [July 16, 2015, 4:36am UTC](https://forum.networklessons.com/t/cisco-asa-anyconnect-remote-access-vpn/833/6 "2015-07-16T04:36:14Z")

</div>

Rene

I was asking because Cisco Packet Tracer 6.2 has a 5505 under it’s Security device category.  
I will add an ASA 5510 to the physical lab after I pass the CCNA exam. I have to keep reminding myself to not spend a lot of time for now on things that are not going to be on the CCNA exam. It is easy to get distracted by topics not on the exam.

Thanks for your response

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [July 16, 2015, 12:03pm UTC](https://forum.networklessons.com/t/cisco-asa-anyconnect-remote-access-vpn/833/7 "2015-07-16T12:03:21Z")

</div>

Hi Donald,

Ah I see…well the 5505 is similar but it uses a VLAN interface for the switchports (similar to a SVI interface on a multilayer switch).

The best results are achieved when you focus on one thing at a time…it’s so easy to get distracted, there are so many things that are worth checking out 🙂

Rene

---

<div class="post-metadata">

### Author: ![gordonflash984](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/g/4bbf92/32.png) [@gordonflash984](https://forum.networklessons.com/u/gordonflash984)
#### Post date: [July 19, 2015, 5:56am UTC](https://forum.networklessons.com/t/cisco-asa-anyconnect-remote-access-vpn/833/8 "2015-07-19T05:56:22Z")

</div>

Rene

Thanks for your response and the great content.

---

<div class="post-metadata">

### Author: ![sims](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/s/c6cbf5/32.png) [@sims](https://forum.networklessons.com/u/sims)
#### Post date: [November 29, 2015, 12:00pm UTC](https://forum.networklessons.com/t/cisco-asa-anyconnect-remote-access-vpn/833/9 "2015-11-29T12:00:14Z")

</div>

Hi,

How to avoid user selecting “group-alias” if multiple group available like “sales” ,“finance”.

How to avoid user choosing a group which he should not . if the sales user choose finance he may get access to the finance resources ?

Thanks

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [December 1, 2015, 2:53pm UTC](https://forum.networklessons.com/t/cisco-asa-anyconnect-remote-access-vpn/833/10 "2015-12-01T14:53:19Z")

</div>

Hi,

I don’t have an example for it but it’s possible to assign users to certain groups and to disable the selection. They won’t be able to select any group aliases then.

Rene

---

<div class="post-metadata">

### Author: ![faiqmahdi](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/f/a698b9/32.png) [@faiqmahdi](https://forum.networklessons.com/u/faiqmahdi)
#### Post date: [January 24, 2016, 2:19pm UTC](https://forum.networklessons.com/t/cisco-asa-anyconnect-remote-access-vpn/833/11 "2016-01-24T14:19:22Z")

</div>

Hi

I have ASA 5520 VPN Plus license with latest IOS disk0:/asa917-k8.bin

```auto
Licensed features for this platform:
Maximum Physical Interfaces : Unlimited perpetual
Maximum VLANs : 150 perpetual
Inside Hosts : Unlimited perpetual
Failover : Active/Active perpetual
Encryption-DES : Enabled perpetual
Encryption-3DES-AES : Enabled perpetual
Security Contexts : 20 perpetual
GTP/GPRS : Enabled perpetual
AnyConnect Premium Peers : 250 perpetual
AnyConnect Essentials : 750 perpetual
Other VPN Peers : 750 perpetual
Total VPN Peers : 750 perpetual
Shared License : Enabled perpetual
AnyConnect for Mobile : Enabled perpetual
AnyConnect for Cisco VPN Phone : Enabled perpetual
Advanced Endpoint Assessment : Enabled perpetual
UC Phone Proxy Sessions : 100 perpetual
Total UC Proxy Sessions : 100 perpetual
Botnet Traffic Filter : Enabled perpetual
Intercompany Media Engine : Disabled perpetual
Cluster : Disabled perpetual

This platform has an ASA 5520 VPN Plus license.

```

My question is, can we use AnyConnect VPN Client Software-4.2.01035 with my existing Firewall?  
[https://software.cisco.com/download/release.html?mdfid=286281283&amp;softwareid=282364313&amp;release=4.2.01035&amp;relind=AVAILABLE&amp;rellifecycle=&amp;reltype=latest](https://software.cisco.com/download/release.html?mdfid=286281283&amp;softwareid=282364313&amp;release=4.2.01035&amp;relind=AVAILABLE&amp;rellifecycle=&amp;reltype=latest)

---

<div class="post-metadata">

### Author: ![faiqmahdi](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/f/a698b9/32.png) [@faiqmahdi](https://forum.networklessons.com/u/faiqmahdi)
#### Post date: [January 25, 2016, 1:32pm UTC](https://forum.networklessons.com/t/cisco-asa-anyconnect-remote-access-vpn/833/12 "2016-01-25T13:32:47Z")

</div>

Hi

I tested today AnyConnect VPN Client Software-4.2.01035 with my ASA and glad it works perfectly with Rene article.

Rene, your ASA articles are amazing which so far I am testing, just a quick note, if you can add NAT statements also related to the configuration that will be great or if you add a Note that particular configuration require NAT changes as well.  
e.g. to make the Split Tunnel work we need a deny statement in NAT so it will be helpful.

Thanks and amazing work, everything work for me like a charm.

Stay blessed

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [January 25, 2016, 6:25pm UTC](https://forum.networklessons.com/t/cisco-asa-anyconnect-remote-access-vpn/833/13 "2016-01-25T18:25:59Z")

</div>

Hi Syed,

Good to hear everything is working. I’ll add a separate post for NAT exemption but for now, you can use this:

```auto
object network INSIDE
 subnet 192.168.1.0 255.255.255.0

```

```auto
object network VPN_POOL
 subnet 192.168.10.0 255.255.255.0

```

`nat (INSIDE,OUTSIDE) source static INSIDE,INSIDE destination static VPN_POOL VPN_POOL`

Basically this rule means that the source addresses from INSIDE will be translated to INSIDE and the destination addresses in VPN\_POOL will be translated to VPN\_POOL. In other words…the source and destination addresses will remain the same and no NAT is performed.

I think you will be fine with the anyconnect client btw, best to just test it.

Hope this helps!

Rene

---

<div class="post-metadata">

### Author: ![sachy32](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/s/e274bd/32.png) [@sachy32](https://forum.networklessons.com/u/sachy32)
#### Post date: [January 27, 2016, 5:19pm UTC](https://forum.networklessons.com/t/cisco-asa-anyconnect-remote-access-vpn/833/14 "2016-01-27T17:19:54Z")

</div>

Hi Rene,

I’ve recently setup the Anyconnect on my Corporate network for Windows users and it’s working beautifully, thanks to you. The only issue i have now is trying to get an iPad to connect using the Anyconnect, as it uses the Anyconnect App that it not pushed to the ipad when the user authenticates.

Have you seen or do you know a way of making the iPad work ? (Andriod devices work fine using the App, so I’m thinking its a Apple certificate blocking thing ???)

Any help would be great.

Many thanks

Neil

---

<div class="post-metadata">

### Author: ![sachy32](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/s/e274bd/32.png) [@sachy32](https://forum.networklessons.com/u/sachy32)
#### Post date: [January 28, 2016, 12:22pm UTC](https://forum.networklessons.com/t/cisco-asa-anyconnect-remote-access-vpn/833/15 "2016-01-28T12:22:57Z")

</div>

Ignore that last post Rene, I’ve just found out that the Domain chaps have pushed MobileIron out on the iPad fleet, and they are preventing SSL certificate installs. :o)

---

<div class="post-metadata">

### Author: ![yannaing.ml](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/y/edb3f5/32.png) [@yannaing.ml](https://forum.networklessons.com/u/yannaing.ml)
#### Post date: [February 11, 2016, 11:09am UTC](https://forum.networklessons.com/t/cisco-asa-anyconnect-remote-access-vpn/833/16 "2016-02-11T11:09:58Z")

</div>

I want to use two asa5525-X firewall (Active/Active) design in main office. Branch office want to use anyconnect vpn client. Is it possible or not?

---

<div class="post-metadata">

### Author: ![christinelane](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/c/c37758/32.png) [@christinelane](https://forum.networklessons.com/u/christinelane)
#### Post date: [March 24, 2016, 11:33pm UTC](https://forum.networklessons.com/t/cisco-asa-anyconnect-remote-access-vpn/833/17 "2016-03-24T23:33:01Z")

</div>

Can you tell me what, if anything, needs to be done to allow authentication with Smart cards for AnyConnect VPN’s?

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [March 25, 2016, 4:35pm UTC](https://forum.networklessons.com/t/cisco-asa-anyconnect-remote-access-vpn/833/18 "2016-03-25T16:35:24Z")

</div>

@Mark I believe that on ASA 9 you can only use IPsec site-to-site VPN in active/active mode, not anyconnect.

@Christine There are quite some different options to implement this. It’s a bit similar to this example:

> **[Cisco ASA Anyconnect Local CA](https://networklessons.com/cisco/asa-firewall/cisco-asa-anyconnect-local-ca)**
>
> This lesson teaches you how you can configure the Cisco ASA as a local CA so that it can sign user and server certificates.

In that lesson I used the ASA as a CA but you can also use an external (windows) CA server.

---

<div class="post-metadata">

### Author: ![rhardtan](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/r/4da419/32.png) [@rhardtan](https://forum.networklessons.com/u/rhardtan)
#### Post date: [May 18, 2016, 2:15pm UTC](https://forum.networklessons.com/t/cisco-asa-anyconnect-remote-access-vpn/833/19 "2016-05-18T14:15:16Z")

</div>

Hi Rene,

Do you know which zone/security level the user belongs to after connecting via anyconnect ?

The reason I ask is because after logging in via anyconnect I can’t SSH to my router (as I normally would if I am directly on the inside network).

Thanks in advanced.

Richard

---

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [May 21, 2016, 2:37pm UTC](https://forum.networklessons.com/t/cisco-asa-anyconnect-remote-access-vpn/833/20 "2016-05-21T14:37:48Z")

</div>

Hi Richard,

The VPN traffic does terminate on the outside interface. Usually we use the **sysopt connection permit-vpn** command to permit IPsec traffic to bypass any access-list. If you don’t use it, then you’ll need to explicitly permit your IPsec traffic to the inside.

It could be an issue on your ASA but have you also checked your router has a route back to the ASA?

Rene

[Next page](https://forum.networklessons.com/t/cisco-asa-anyconnect-remote-access-vpn/833.md?page=2)
