Cisco Anyconnect Client Mac

Objective

  • Cisco AnyConnect is the recommended VPN client for Mac. The built-in VPN client for Mac is another option but is more likely to suffer from disconnects.
  • Jul 30, 2020 In order to verify the Anyconnect installation and the selected modules, in the Anyconnect application, navigate to the Apple's Menu Bar Cisco Anyconnect Secure Mobility Client and select About Cisco AnyConnect as shown in the image. Confirm the Installed Modules section as shown in the image.
  • The 4.8.01090 version of Cisco AnyConnect Secure Mobility Client for Mac is provided as a free download on our website. The most popular versions of Cisco AnyConnect Secure Mobility Client for Mac are 3.1 and 3.0. Cisco AnyConnect Secure Mobility Client for Mac lies within System Tools, more precisely Remote Computing.

This article shows you how to download and install the Cisco AnyConnect Secure Mobility Client version 4.8 on a Mac Computer. This article is applicable only to Cisco Business products that includes the RV34x series routers and not Enterprise products.

Introduction

AnyConnect Secure Mobility Client is a modular endpoint software product. It not only provides Virtual Private Network (VPN) access through Secure Sockets Layer (SSL) and Internet Protocol Security (IPsec) Internet Key Exchange version2 (IKEv2) but also offers enhanced security through various built-in modules. Why use a VPN? A VPN connection allows users to access, send, and receive data to and from a private network by means of going through a public or shared network such as the Internet but still ensuring a secure connection to an underlying network infrastructure to protect the private network and its resources.

If you are using a Windows computer, click here to view an article on how to install AnyConnect on Windows.

Applicable Devices Software Version

Cisco AnyConnect provides reliable and easy-to-deploy encrypted network connectivity from any Apple iOS by delivering persistent corporate access for users on the go. Whether providing access to business email, a virtual desktop session, or most other iOS applications, AnyConnect enables business-critical application connectivity. Perhaps more importantly, while setting in these two files the parameter 'RunAtLoad' to 'false' indeed prevents the annoying reinstallation of the application 'Cisco AnyConnect Secure Mobility Client.app' as a login item after a restart, it also makes the vpn in general disfunctional.

  • RV340 - 1.0.03.17 (Download latest)
  • RV340W - 1.0.03.17 (Download latest)
  • RV345 - 1.0.03.17 (Download latest)
  • RV345P - 1.0.03.17 (Download latest)

AnyConnect and Mac Software Version

  • AnyConnect (This document uses AnyConnect version 4.8 Link to download)
  • Mac OS Catalina (10.15) is compatible with AnyConnect 4.8 and later
  • Note: You will encounter issues if you attempt to use Mac OS Catalina with earlier versions of AnyConnect (AnyConnect 4.8 Release Notes Details from Apple )

  • Mac OS Mojave (10.14) is compatible with AnyConnect 4.9.05042 and below
  • For more details about the supported operating systems (Windows, Linux, Mac) of the Cisco AnyConnect Secure Mobility Client, refer to the article on Cisco AnyConnect Secure Mobility Client Supported Operating Systems and Requirements. You can also check the Release Notes of the relevant versions for the most updated information.

Install AnyConnect Secure Mobility Client

Licensing Information

AnyConnect client licenses allow the use of the AnyConnect desktop clients as well as any of the AnyConnect mobile clients that are available.

Licensing Structure - Firmware versions 1.0.3.15 and later

Windows

As of March 2019, using RV340 series routers version 1.0.3.15 and later no longer require server licenses. Now you will need only a client license to download and use the Cisco AnyConnect Secure Mobility Client. A client license enables the VPN functionality and are sold in packs of 25 from partners like CDW or through your company's device procurement.

We recommend the following user license for use with the RV340 Series:

  • L-AC-PLS-LIC= Qty=25 Duration=12

Licensing Structure - Firmware versions 1.0.2.16 or lower

If you have not yet updated your firmware, please do so now. Do not delay. Click here to visit the downloads page for the RV34X series.

Cisco Anyconnect Client Mac

For further information and community discussion on AnyConnect licensing updates, click here.

For AnyConnect Licensing FAQs, click here.

Step 1

Download AnyConnect here.

Install the AnyConnect Pre-deployment Package for the MAC operating systems.

Step 2

Double-click the installer.

Step 3

Click Continue.

Step 4

Go over the Supplemental End User License Agreement and then click Continue.

Step 5

Click Agree.

Step 6

Choose the components to be installed by checking or unchecking the corresponding check boxes. All components are installed by default.

The items you select in this screen will appear as options in AnyConnect. If deploying AnyConnect for end-users, you may want to consider deselecting options.

Step 7

Click Continue.

Step 8

Click Install.

Step 9

(Optional) Enter your password in the Password field.

Step 10

Click Install Software.

Step 11

Click Close.

You have now successfully installed the AnyConnect Secure Mobility Client Software on your Mac computer.

Additional Resources

AnyConnect App

To try out AnyConnect on mobile devices, the App can be downloaded from Google Play store or Apple store.

View a video related to this article...

Click here to view other Tech Talks from CiscoCisco Anyconnect Client Mac

For additional information, refer to the AnyConnect configuration guide.

Client Download

Unlike the ASA, the MX does not support web deploy or web launch, a feature that allows end users to access a web page on the AnyConnect server to download the AnyConnect client. With the MX, there are download links to the client software on the AnyConnect settings page on the dashboard, however, the download links are only available to the Meraki dashboard admin and not the end user. We do not recommend sharing the down link with users as the link expires after every five minutes of loading the AnyConnect settings page.

We recommend downloading the AnyConnect client directly from Cisco.com as there may be an updated version in the Cisco repository. Refer to the doc for the AnyConnect clientrelease notes. We also recommend using either Meraki Systems Manager, an equivalent MDM solution, or Active Directory to seamlessly push the AnyConnect software client to the end user's device.

AnyConnect requires a VPN client to be installed on a client device. The AnyConnect client for Windows, MacOS, and Linux are available on the Client Connection section of the AnyConnect configuration page on the dashboard and can be downloaded by a Meraki dashboard administrator. Please note, the download links on the Meraki dashboard expire after five minutes. The AnyConnect client for mobile devices can be downloaded via the respective mobile stores. You can also download other versions (must be version 4.8 or higher) of the AnyConnect client from Cisco.com if you have an existing AnyConnect license. AnyConnect web deploy is not supported on the MX at this time.

  • Installing the AnyConnect client
  • You only need the VPN box checked. Once the client has been installed on the device, open the AnyConnect application and specify the hostname or IP address of the MX (AnyConnect server) you need to connect to.

AnyConnect Profiles

An AnyConnect profile is a crucial piece for ensuring easy configuration of the AnyConnect client software, once installed. The MX does not support the use of custom hostnames for certificates (e.g. vpn.xyz.com). The MX only supports use of the Meraki DDNS hostname for auto-enrollment and use on the MX. With the Meraki DDNS hostname (e.g. mx450-xyuhsygsvge.dynamic-m.com) not as simply as a custom hostname, the need for AnyConnect profiles cannot be overemphasized. Profiles can be used to create hostname aliases, thereby masking the Meraki DDNS with a friendly name for the end user.

Cisco AnyConnect client features are enabled in AnyConnect profiles. These profiles can contain configuration settings like server list, backup server list, authentication time out, etc., for client VPN functionality, in addition to other optional client modules like Network Access Manager, ISE posture, customer experience feedback, and web security. It is important to note that at this time, the Meraki MX does not support other optional client modules that require AnyConnect head-end support. For more details, see AnyConnect profiles.

When a profile is created, it needs to get pushed to the end user's device. There are three ways to do this.

1. Through the AnyConnect server (MX): If profiles are configured on the dashboard, the MX will push the configured profile to the user's device after successful authentication.
2. Through an MDM solution: Systems Manager, an equivalent MDM solution, or Active Directory can be used push files to specific destinations on the end user's device. Profiles can also be pushed to the following paths:

Windows
%ProgramData%CiscoCisco AnyConnect Secure Mobility ClientProfile

Mac OS X
/opt/cisco/anyconnect/profile

Cisco Anyconnect Client Mac Download

Linux
/opt/cisco/anyconnect/profile

3. Manually: Profiles can also be preloaded manually to the same paths as listed above.

How to Create a Profile

Profiles can be created using the AnyConnect profile editor. The profile editor can be downloaded from the AnyConnect Settings page on dashboard or on cisco.com. Refer to this link for more details on AnyConnect profiles.

Using the profile editor: The profile editor can be downloaded from the AnyConnect Settings page on dashboard or on Cisco.com. The profile editor only runs on Windows operating systems. The screenshot below shows a configured server ton the Server List Entry option.

When configuration is complete, save the profile. It is recommended to use a unique file name to avoid profile overrides by other AnyConnect servers, then you can upload the file to the profile update section on the AnyConnect settings page.

Cisco Anyconnect Vpn Client Mac

Please note that only VPN profiles are supported on the MX at this time. This means you cannot push NVM, NAM, or Umbrella profiles via the MX.

Cisco Anyconnect Client Mac Download

  • Select enable profiles, upload your xml file, and save your configuration
  • After a user successfully authenticates, the configured profile gets pushed to the user's device automatically
  • The result of the .xml can be seen below, after successful authentication to the AnyConnect server; this gives users the ease of selecting VPN servers on the AnyConnect client
    The Meraki DDNS hostname is not easy to remember, therefore end users are not expected to use it directly. Profiles should be used to make connecting to the AnyConnect server easy for end users.