- Install Cisco AnyConnect Secure Mobility Client on a Mac Computer
- Available Languages
- Download Options
- Objective
- Introduction
- AnyConnect Software Version
- Install AnyConnect Secure Mobility Client
- Prerequisites
- Check these other articles out!
- Applicable Devices | Software Version
- Licensing Information
- Step 1
- Step 2
- Step 3
- Step 4
- Step 5
- Step 6
- Step 7
- Step 8
- Step 9
- Step 10
- Step 11
- Step 12
- Step 13
- Additional Resources
- AnyConnect App
- View a video related to this article.
- VPN Clients For Mac OS X FAQ
- Available Languages
- Contents
- Introduction
- General Questions
- Q. What options do I have in order to provide remote access to Mac users?
- Q. How do I uninstall Cisco VPN Client on Mac OS X?
- Q. What are the feature differences between the Cisco Remote Access VPN Client and AnyConnect VPN Client?
- IPsec VPN Questions
- Q. If I want to use IPsec, should I use the built-in Mac VPN Client or the Cisco Remote Access VPN Client?
- Q. How do I configure the Mac built-in VPN Client?
- Q. I tried to use the built-in Mac Client on Lion, but I receive a phase 2 mismatch. What should I do?
- Q. Are there any compatibility issues with the Cisco Remote Access VPN Client?
- Q. Where can I download the Cisco Remote Access VPN Client?
- Q. I tried to use Cisco VPN Client, but received Error 51. What should I do?
- Q. Does the built-in Mac VPN Client support ESP-NULL transforms?
Install Cisco AnyConnect Secure Mobility Client on a Mac Computer
Available Languages
Download Options
Objective
This article shows you how to download and install the Cisco AnyConnect Secure Mobility Client version 4.9.x on a Mac Computer.
This article is only applicable to the RV34x series routers, not Enterprise products.
Introduction
AnyConnect Secure Mobility Client is a modular endpoint software product. It not only provides Virtual Private Network (VPN) access through Secure Sockets Layer (SSL) and Internet Protocol Security (IPsec) Internet Key Exchange version2 (IKEv2) but also offers enhanced security through various built-in modules.
AnyConnect Software Version
Install AnyConnect Secure Mobility Client
This toggled section provides details and tips for beginners.
Prerequisites
- You need to purchase client license(s) from a partner like CDW or through your company’s device procurement. There are options for 1 user (L-AC-PLS-3Y-S5) or packets of licenses including one year for 25 users (AC-PLS-P-25-S). Other license options available as well, including perpetual licenses. For more details on licensing, check out the links in the Licensing Information section below.
- Download the latest version of firmware available for your router.
Check these other articles out!
Applicable Devices | Software Version
- RV340 | 1.0.03.21 (Download latest)
- RV340W | 1.0.03.21 (Download latest)
- RV345 | 1.0.03.21 (Download latest)
- RV345P | 1.0.03.21 (Download latest)
Licensing Information
AnyConnect client licenses allow the use of the AnyConnect desktop clients as well as any of the AnyConnect mobile clients that are available. You will need a client license to download and use the Cisco AnyConnect Secure Mobility Client. A client license enables the VPN functionality and are sold in packs of 25 from partners like CDW or through your company’s device procurement.
Want to know more about AnyConnect licensing? Here are some resources:
Step 1
Open a web browser and navigate to the Cisco Software Downloads webpage.
Step 2
In the search bar, start typing ‘Anyconnect’ and the options will appear. Select AnyConnect Secure Mobility Client v4.x.
Step 3
Download the Cisco AnyConnect VPN Client. Most users will select the AnyConnect Pre-Deployment Package (Mac OS) option.
The images in this article are for AnyConnect v4.9.x, which was latest version at the time of writing this document.
Step 4
Double-click the installer.
Step 5
Step 6
Go over the Supplemental End User License Agreement and then click Continue.
Step 7
Step 8
Choose the components to be installed by checking or unchecking the corresponding check boxes. All components are installed by default.
The items you select in this screen will appear as options in AnyConnect. If deploying AnyConnect for end-users, you may want to consider deselecting options.
Step 9
Step 10
Step 11
(Optional) Enter your password in the Password field.
Step 12
Click Install Software.
Step 13
You have now successfully installed the AnyConnect Secure Mobility Client Software on your Mac computer.
Additional Resources
AnyConnect App
To try out AnyConnect on mobile devices, the App can be downloaded from Google Play store or Apple store.
View a video related to this article.
Источник
VPN Clients For Mac OS X FAQ
Available Languages
Contents
Introduction
This document answers frequently asked questions about Cisco’s VPN Client solutions available on Mac OS X.
Tip: Cisco recommends that you migrate to the AnyConnect VPN Client for both Secure Sockets Layer (SSL) as well as IPsec. The built-in IPsec client on Mac OS is an Apple product, so any questions/upgrades/bug fixes and other issues on the client side need to be addressed by Apple while the Cisco Remote Access VPN client is EOS. Therefore, no fixes will be put in for this client.
General Questions
Q. What options do I have in order to provide remote access to Mac users?
There are three VPN Client solutions that can be implemented, dependent upon the Mac OS Version.
VPN Client | Technology/Protocol | Mac OS X 10.10 Yosemite | Mac OS X 10.11 El Capitan | |||||
Mac Built-in VPN Client | IPsec | X | X | X | X | X | X | |
Cisco Remote Access IPsec Client | IPsec | X | X | |||||
Cisco AnyConnect Secure Mobility Client | SSL, IKEv2/IPsec | X* | X | X** | X*** | X | X | X**** |
*Mac OS X 10.5 (Leopard) is no longer supported in AnyConnect Release 3.1. Also, PowerPC support was dropped in Release 3.0 and later.
**Mac OS X 10.7 (Lion) is supported in AnyConnect Releases 2.5.3051 and 3.0.3054 and later.
***Mac OS X 10.8 (Mountain Lion) is supported in AnyConnect Releases 3.0.08057 and 3.1 and later.
****MAC OS X 10.11 (El Capitan) is supported in Anyconnect 4.1.04011 and later. El Capitan support will not be provided in AnyConnect 3.x as new OS support ended in July 2015. Refer to End-of-Sale and End-of-Life Announcement for the Cisco AnyConnect Secure Mobility Client Version 3.x.
Q. How do I uninstall Cisco VPN Client on Mac OS X?
In order to uninstall the Cisco VPN Client, complete these steps:
- Enter these commands in order to clean out the old Cisco VPN kernel extension and reboot the system.
- If you installed the Cisco VPN for Mac version 4.9.01.0180 package, enter these commands in order to delete the misplaced files. The deletion of these files will not affect your system, since applications do not use these misplaced files in their current location.
- Enter these commands if you no longer need the old Cisco VPN Client or Shimo.
Q. What are the feature differences between the Cisco Remote Access VPN Client and AnyConnect VPN Client?
This is beyond the scope of this document, but fundamentally SSL VPN has more features than the Cisco Remote Access Software VPN Client as it is a newer technology and new features are rolled into each new release of AnyConnect. The latest AnyConnect Mobility Client, Version 3.0, includes the same feature-rich support for both SSL VPN and IKEv2.
IPsec VPN Questions
Q. If I want to use IPsec, should I use the built-in Mac VPN Client or the Cisco Remote Access VPN Client?
A. Although it is possible to use either VPN Client, the advantages of each are explained here.
Note: Cisco recommends that you use AnyConnect, which allows you to take advantage of Next Generation Encryption (NGE) ciphers and advancements in the IKEv2 protocol.
Mac VPN Client
- + The Apple built-in client ensures support as the Mac OS evolves.
- + The client is integrated into Mac OS X 10.6 and later.
- + Faster to configure as it does not require installation of another application.
- — Not built into Mac OS X 10.5.
Cisco Remote Access VPN Client
- + Supported in Mac OS X 10.5 and 10.6.
- — Requires installation of another software application on your Mac.
- — In early 2011 Mac began to ship Mac OS X 10.6 with a 64-bit kernel. This is not supported by the Cisco Remote Access VPN Client and results in Error 51 after install. Refer to Cisco IPsec VPN Client on MAC OS X generates the error «Error 51: Unable to communicate with the VPN subsystem».
Q. How do I configure the Mac built-in VPN Client?
In Mac OS X 10.6 and later:
- Choose System Preferences > Network.
- Click the lock button in order to unlock it and make changes.
- Click the plus sign
above the unlocked lock button in order to add an interface.
- From the Interface drop-down list, choose VPN.
- From the VPN Type drop-down list, choose Cisco IPSec.
- In the Service Name text box, type an easy to remember interface name such as ‘Corp IPsec VPN’.
- Click OK and then select this new interface.
- Click the new VPN interface in order to configure the interface.
- Server Address-VPN headend’s outside interface IP address (WAN/publicly routable IP address)
- Account Name-Username
- Account Password-User’s password
- Click Authentication Settings.
- Under Machine Authentication, click the radio button for your respective authentication mechanism (pre-shared-key or certificate authentication).
- If a pre-shared key that matches the pre-shared-key defined on the VPN headend is used, type the key into the Shared Secret dialog box.
- Enter the Group Name that matches the one defined in the EZVPN configuration on the VPN headend device (ASA ‘tunnel-group’, IOS ‘crypto ipsec client ezvpn group’).
Q. I tried to use the built-in Mac Client on Lion, but I receive a phase 2 mismatch. What should I do?
If your Microsoft Windows clients work or your older Macs that use the Cisco Remote Access VPN Clients work, and only the Lion machines do not seem to be able to connect, then it is likely a phase 2 mismatch issue. You see this error message if you enable ‘debug crypto ipsec’ on the ASA. This essentially means the transform sets used probably do not support the encryption used by the Mac built-in client. For Lion, the client uses 3DES or AES. It does not support DES. In order to work around this issue, either switch the transform set to use 3DES completely or add multiple transform sets as shown here:
This issue is usually caused by running an ASA software release earlier than Release 8.4. The later ASA software comes with all transforms sets defined by default, so additional configuration is not required to make it work.
Q. Are there any compatibility issues with the Cisco Remote Access VPN Client?
Refer to the Software Release Notes first for compatibility guidelines. Note the Error 51 compatibility issue between the Cisco Remote Access VPN Client and 64-bit Mac kernel mentioned later in this document.
Q. Where can I download the Cisco Remote Access VPN Client?
- Open the Cisco Support Page.
- Click Download Software.
- Choose Products > Security > Virtual Private Networks (VPN) > Cisco VPN Clients > Cisco VPN Client.
- Choose Cisco VPN Client v4.x.
- Choose Mac OS.
Note: The VPN Client v5.x was only released for Windows PCs. The latest Mac release is v4.9.
Q. I tried to use Cisco VPN Client, but received Error 51. What should I do?
Q. Does the built-in Mac VPN Client support ESP-NULL transforms?
No, the built-in client does not support this transform set.
Источник