![]() |
Table Of Contents
AnyConnect Secure Mobility Client Features, Licenses, and OSs, Release 3.1
AnyConnect Essentials and Premium Licenses
Advanced Endpoint Assessment License
Cisco Secure Mobility for AnyConnect License
AnyConnect License Combinations
AnyConnect Deployment and Configuration
Connect and Disconnect Features
Authentication and Encryption Features
AnyConnect Network Access Manager
AnyConnect Secure Mobility Modules
Hostscan and Posture Assessment
Reporting and Troubleshooting Modules
AnyConnect Secure Mobility Client Features, Licenses, and OSs, Release 3.1
Published: December 13, 2012Revised: August 27, 2013This document identifies the AnyConnect Release 3.1 features, license requirements, and endpoint operating systems AnyConnect features supports.
Supported Operating Systems
Cisco AnyConnect Secure Mobility Client 3.1 supports the following operating systems.
* In the upcoming AnyConnect 3.2 release, support for Linux 32-bit will be phased out.
Note
After April 8, 2014, Microsoft will no longer provide new security updates, non-security hotfixes, free or paid assisted support options, or online technical content updates for Windows XP (http://www.microsoft.com/en-us/windows/endofsupport.aspx). On the same date, Cisco will stop providing customer support for AnyConnect releases running on Windows XP, and we will not offer Windows XP as a supported operation system for future AnyConnect releases.
See the Release Notes for Cisco AnyConnect Secure Mobility Client, Release 3.1 for OS requirements and support notes.
See the Feature Matrix below for license information and operating system limitations that apply to AnyConnect modules and features.
License Options
The AnyConnect Secure Mobility client requires license activation to support VPN sessions and web security. The license(s) required depend on the AnyConnect VPN Client and Secure Mobility features that will be used, and the number of sessions you want to support. One or more of the following AnyConnect licenses may be required for your deployment:
AnyConnect Essentials and Premium Licenses
•
You can activate either an AnyConnect Essentials license or an AnyConnect Premium license on a Cisco ASA 8.2(x) or later, but you cannot activate both licenses together. Some features require later versions of the ASA, as indicated in the Features Table. Choose the license you will activate based on the AnyConnect Secure Mobility features you will use.
•
In addition to AnyConnect connectivity, an AnyConnect Essentials license activated on the ASA supports sessions established using Cisco's legacy VPN client and full tunneling access to enterprise applications. Clientless VPN access and Cisco Secure Desktop are not available with an AnyConnect Essentials license.
•
An ASA activated with an AnyConnect Premium license supports all access allowed by the AnyConnect Essentials license plus the following AnyConnect premium features:
–
Clientless VPN access: Allows a remote user to use a browser to establish a VPN session, and lets specific applications use the browser to access that session.
–
Cisco Secure Desktop: For both browser-based and AnyConnect sessions.
–
Post Log-in Always-on VPN: Establishes a VPN session automatically after the user logs in to a computer. For more information, see Always-on VPN. This feature also includes a Connect Failure policy and Captive Portal Hotspot Detection and Remediation.
Note
You can also enable always-on by activating a Cisco Secure Mobility for AnyConnect license on the WSA with an AnyConnect Essentials license on the ASA.
–
Endpoint assessment: Ensures that your choice of antivirus software versions, antispyware versions, associated update definitions, firewall software versions, and corporate property verification checks comply with policies to qualify a session to be granted access to the VPN.
Endpoint remediation requires an Advanced Endpoint Assessment License in addition to the AnyConnect Premium License as described below.
–
Quarantine: Uses Dynamic Access Policies to quarantine non-compliant AnyConnect users. You can notify users with a custom message.
•
Neither the AnyConnect Essentials or Premium license is required for:
–
The Network Access Manager module. It is licensed without charge for use with Cisco wireless access points, wireless LAN controllers, switches, and RADIUS servers. A current SmartNet contract is required on the related Cisco equipment.
–
The DART module and Customer Feedback function.
AnyConnect Mobile License
The activation of an AnyConnect Mobile license on the ASA supports mobile access but does not provide support for AnyConnect features. This option is available with either an AnyConnect Essentials or an AnyConnect Premium license.
AnyConnect 3.1 does not currently support mobile devices. You must activate this license on the ASA if you expect connectivity from Android or Apple iOS devices running older versions of AnyConnect.
AnyConnect Flex License
An AnyConnect Flex license provides business continuity support for licensed features only. Business continuity increases the number of licensed remote access VPN sessions to prepare for temporary spikes in usage during cataclysmic events such as pandemics. Each Flex license is ASA-specific and provides support for sixty days. The count can consist of both contiguous and noncontiguous days.
Advanced Endpoint Assessment License
You must activate an Advanced Endpoint Assessment license in conjunction with an AnyConnect Premium license. It allows the initiation of endpoint remediation.
Endpoint remediation is initiated when a connection has been disallowed by Dynamic Access Policies (DAPs) on the ASA. Endpoint remediation attempts to remediate various aspects of antivirus, antispyware, and personal firewall protection on the endpoint, only if that software allows a separate application to initiate remediation. If the endpoint remediation is successful, DAP allows a subsequent connection.
Cisco Secure Mobility for AnyConnect License
A Cisco Secure Mobility for AnyConnect license activated on the WSA provides services for browser-based SSL sessions and AnyConnect VPN sessions such as:
•
Malware defense.
•
Acceptable use policy enforcement.
•
Data leakage prevention for the web.
•
Protection for the endpoint from websites found to be unsafe by granting or denying all HTTP and HTTPS requests.
•
Administrator access to Internet usage reports for all VPN sessions.
The Cisco Secure Mobility for AnyConnect license must be activated as follows:
•
A Cisco Secure Mobility for AnyConnect Premium license activation on the WSA requires activation of either an AnyConnect Premium or an AnyConnect Essentials license on the ASA.
•
A Cisco Secure Mobility for AnyConnect Essentials license activation on the WSA requires activation of an AnyConnect Essentials license on the ASA. You cannot use a Cisco Secure Mobility for AnyConnect Essentials license activated on a WSA in combination with an AnyConnect Premium license activated on an ASA.
Note
Post Log-in Always-on VPN, a Premium feature, is enabled by activating a Cisco Secure Mobility for AnyConnect license on the WSA with an AnyConnect Essentials license on the ASA.
•
The Cisco Secure Mobility for AnyConnect license activated on the WSA must match or exceed the number of VPN sessions supported by the AnyConnect license activated on the ASA.
This Cisco Secure Mobility license for AnyConnect, Premium or Essentials, is in addition to the activated Cisco IronPort Web Security Appliance license.
For more information, see the Cisco IronPort Web Security Appliances Introduction.
AnyConnect License Combinations
Sessions License License Option Basic Access Mobile Access Client-
less Access Post Log-in Always-on VPN Malware Defense, Acceptable Use Policy Enforcement, and Data Leakage Prevention on the Web Endpoint Assess-
ment Endpoint Reme-
diationAnyConnect Essentials
(base license)
+
AnyConnect Mobile
+
Cisco Secure Mobility for AnyConnect Essentials
+
AnyConnect Flex1
AnyConnect Premium SSL VPN Edition
(base license)
+
AnyConnect Mobile
+
Cisco Secure Mobility for AnyConnect Premium
+
Advanced Endpoint Assessment
+
AnyConnect Flex1
1 A flex license provides business continuity support for mobile access, malware defense, acceptable use policy enforcement, data leakage prevention on the web, and endpoint remediation features only if those features are licensed.
Features Matrix
AnyConnect 3.1 modules and features, with their minimum release requirements, license requirements and supported operating systems. are listed in the following sections:
•
AnyConnect Deployment and Configuration
–
Connect and Disconnect Features
–
Authentication and Encryption Features
•
AnyConnect Network Access Manager
•
AnyConnect Secure Mobility Modules
–
Hostscan and Posture Assessment
•
Reporting and Troubleshooting Modules
–
DART
AnyConnect Deployment and Configuration
Anyconnect Core VPN Client
Core Features
Connect and Disconnect Features
Authentication and Encryption Features
Interfaces
AnyConnect Network Access Manager
AnyConnect Secure Mobility Modules
Hostscan and Posture Assessment
Telemetry
Feature Minimum AnyConnect Release Minimum ASA/ASDM Release License Required Windows Mac LinuxTelemetry
3.0
ASA 8.4(1)
ASDM 6.4(1)
WSA 7.0
(see below)
yes
no
no
Telemetry License Requirements
(Cisco Secure Mobility for AnyConnect Essentials and AnyConnect Essentials) or (Cisco Secure Mobility for AnyConnect Premium and (AnyConnect Essentials or AnyConnect Premium)
Web Security
Web Security License Requirements:
(AnyConnect Essentials or AnyConnect Premium) and Cisco Secure Mobility for Cisco Cloud Web Security and (Cisco Cloud Web Security Web Filtering or Cisco Cloud Web Security Malware Scanning)
Reporting and Troubleshooting Modules
Customer Experience Feedback
Feature Minimum AnyConnect Release Minimum ASA/ASDM Release License Required Windows Mac LinuxCustomer Experience Feedback
3.1
ASA 8.4(1)
ASDM 7.0
Essentials
yes
yes
no
DART
Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: www.cisco.com/go/trademarks. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1110R)
Any Internet Protocol (IP) addresses and phone numbers used in this document are not intended to be actual addresses and phone numbers. Any examples, command display output, network topology diagrams, and other figures included in the document are shown for illustrative purposes only. Any use of actual IP addresses or phone numbers in illustrative content is unintentional and coincidental.
© 2012 Cisco Systems, Inc. All rights reserved.