Getting Started with Cisco Anyconnect
AnyConnect tunnels through HTTPS
1. Enable WebVPN on the interface
webvpn
enable PUBLIC
svc ask enable
!
2. Configure AAA authentication and tunnel group
tunnel-group DefaultWEBVPNGroup type remote-access
tunnel-group DefaultWEBVPNGroup general-attributes
authentication-server-group LOCAL
!
3. If using LOCAL database, add users to the Database
username test password t3stP@ssw0rd
username test attributes
service-type remote-access
!
4. Point the ASA to an AnyConnect image
webvpn
svc image anyconnect-win-2.1.0148-k9.pkg
!
5. Enable AnyConnect
webvpn
enable PUBLIC
!
6. Add an address pool to assign an ip address to the AnyConnect
ip local pool client-pool 192.168.1.1-192.168.1.254 mask 255.255.255.0
!
7. Configure group policy
group-policy DfltGrpPolicy internal
group-policy DfltGrpPolicy attributes
vpn-tunnel-protocol svc webvpn
!
8. NAT Exemption
access-list NONAT extended permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0
!
nat (inside) 0 access-list NONAT
!
9. DNS
group-policy DfltGrpPolicy attributes
dns-server value 8.8.8.8
default-domain value
!
10. Split Tunneling + Binding to Group-Policy
access-list SPLIT standard permit 192.168.1.0 255.255.255.0
group-policy DfltGrpPolicy attributes
split-tunnel-policy tunnelspecified
split-tunnel-network value SPLIT
!
11. Autolaunch Anyconnect ( Cisco SSL VPN Client (SVC)
group-policy DfltGrpPolicy attributes
webvpn
svc ask none default svc
!
!
12. Complete Configuration :
access-list NONAT extended permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0
!
access-list SPLIT standard permit 192.168.1.0 255.255.255.0
!
ip local pool client-pool 192.168.2.1-192.168.2.254 mask 255.255.255.0
!
nat (inside) 0 access-list NONAT
!
!
webvpn
enable PUBLIC
svc ask enable
svc image disk0:/anyconnect-win-2.4.1012-k9.pkg 1
!
tunnel-group DefaultWEBVPNGroup type remote-access
tunnel-group DefaultWEBVPNGroup general-attributes
authentication-server-group LOCAL
!
group-policy DfltGrpPolicy internal
group-policy DfltGrpPolicy attributes
dns-server value 8.8.8.8
default-domain value dallas.co.uk
vpn-simultaneous-logins 50
vpn-idle-timeout none
vpn-tunnel-protocol svc webvpn
password-storage enable
address-pool client-pool
split-tunnel-policy tunnelspecified
split-tunnel-network value SPLIT
!
username ECVPN01 attributes
service-type remote-access
!
username ECVPN01 attributes
webvpn
file-browsing enable
file-entry enable
homepage value http://172.28.2.10
Summary :
Complete Configuration (nonat/split tunnel/client-pool) :
access-list NONAT extended permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0
!
access-list SPLIT standard permit 192.168.1.0 255.255.255.0
!
ip local pool client-pool 192.168.2.1-192.168.2.254 mask 255.255.255.0
!
nat (inside) 0 access-list NONAT
!
Complete Configuration (webvpn) :
webvpn
enable outside
svc enable
svc image disk0:/anyconnect-win-2.4.1012-k9.pkg 1
svc image disk0:/macimg.dmg 2
!
Complete Configuration (group-policy)
group-policy DfltGrpPolicy internal
group-policy DfltGrpPolicy attributes
dns-server value 8.8.8.8
vpn-simultaneous-logins 50
vpn-idle-timeout none
vpn-tunnel-protocol svc webvpn
password-storage enable
split-tunnel-policy tunnelspecified
split-tunnel-network-list value SPLIT
default-domain value mydomain.com
!
Tunnel-Group Configuration :
ip local pool client-pool 192.168.50.1-192.168.50.254 mask 255.255.255.0
!
tunnel-group DefaultPolicy type remote-access
tunnel-group DefaultPolicy general-attributes
address-pool client-pool
authentication-server-group (PUBLIC) LOCAL
default-group-policy DfltGrpPolicy
!
tunnel-group DfltGrpPolicy webvpn-attributes
group-alias MYVPN enable
!
webvpn
tunnel-group-list enable
!
Username Configuration :
username ECVPN01 attributes
service-type remote-access
!
username ECVPN01 attributes
webvpn
file-browsing enable
file-entry enable
homepage value http://172.28.2.10