Cisco Anyconnect For Mac

Contents

Cisco AnyConnect is the recommended VPN client for Mac. The built-in VPN client for Mac is another option but is more likely to suffer from disconnects. Overview Stanford's VPN allows you to connect to Stanford's network as if you were on campus, making access to restricted services possible. To connect to the VPN from your Mac you need to install the Cisco AnyConnect VPN. Hello all, Recently I deployed AnyConnect client 4.7.02036 to our users. One of our Mac users, running Mojave, who received the update, started getting this prompt when connected: Cisco AnyConnect Secure Mobility Client wants to export key. How to Upgrade Cisco AnyConnect on a Mac. How to Upgrade Cisco AnyConnect on a Mac. The following instructions are for computers NOT on Jamf Pro (Mason Self Service). If your computer is on Mason Self Service, the Cisco AnyConnect VPN should already be installed. Open the Legacy Cisco AnyConnect client (version 4.4 or earlier).

  • This page provides instructions on how to install and connect to Cisco AnyConnect client for Macintosh OS 10.6 (Snow Leopard) and later. The Cisco AnyConnect VPN client is a web-based VPN client that does not require user configuration. VPN, also called IP tunneling, is a secure method of accessing USC computing resources. You will need.
  • The Cisco AnyConnect Secure Mobility Client is compatible with the following platforms. The CD includes AnyConnect packages for Windows, Mac OS X, and Linux. Choose correct AnyConnect package from the CD to download depending on your operating system.
  • Cisco announces a change in product part numbers for the Cisco Block based (ATO) ordering method for AnyConnect Plus and Apex Licenses EOL/EOS for the Cisco AnyConnect VPN Client 2.3 and Earlier (All Versions) and 2.4 (for Desktop).

Introduction

This document briefly describes the possible error messages that appear during the installation of AnyConnect VPN client on Apple MAC machines and their corresponding resolutions.

Prerequisites

Requirements

There are no specific requirements for this document.

Components Used

The information in this document is based on these software and hardware versions:

  • Cisco ASA Security Appliance that runs software version 8.x

  • Cisco IOS® Router that runs Cisco IOS Software Release 12.4(20)T

  • Cisco AnyConnect Client software version 2.x

The information in this document was created from the devices in a specific lab environment. All of the devices used in this document started with a cleared (default) configuration. If your network is live, make sure that you understand the potential impact of any command.

Conventions

Refer to Cisco Technical Tips Conventions for more information on document conventions.

Error Messages

This section shows a list of error messages along with the solutions.

Package Corrupt Error Message

When AnyConnect 2.3 is launched from an Apple MAC machine, the Anyconnect Package corrupt or unavailable error message appears and eventually, the connection attempt fails.

Solution

This can be a problem with the absence of the MAC-related AnyConnect package on the flash of the router. Upload the suitable AnyConnect package for MAC in order to resolve this issue. Upload the corresponding AnyConnect package, which depends upon the MAC architecture. For MACs on the Intel processor, you need the i386 macos image and for MACs that run the Power PC processor (PPC) you need the powerpc macos image. These are example packages for your reference:

  • anyconnect-macosx-i386-2.5.3055-k9.pkg

  • anyconnect-macosx-powerpc-2.5.3055-k9.pkg

Split DNS Issues

When split DNS is enabled on an AnyConnect setup, it is found that all the DNS queries are sent in clear but not tunneled. This is a problem with only the Apple MAC machines and works fine with Windows machines.

Solution

This behavior is observed and filed in Cisco bug ID CSCtf03894 (registered customers only) . In order to resolve this issue, you can upgrade to the AnyConnect release 3.0.4235, which has the Split DNS Functionality Enhancement. As a workaround, you can also use the built-in IPSec VPN client supported by Apple, which does not have this issue.

SVC Error Message

The launch of AnyConnect from a Macbook Pro running OSX Leopard is not successful. The VPN gateway is ASA running 8.0.4. The connection fails and the SVC Message: 16/ERROR: Initialization failure (mem allocfailed, etc.) error message appears.

Solution

This can be a problem with the way the MAC machine attempts to connect to the ASA. First verify if any IPv6 adaptors are enabled on the MAC machine and check if MAC tries to contact ASA over the IPv6 network. If so, it fails as the IPv6 is not supported with AnyConnect. In order to resolve this, disable the IPv6 related services on the MAC machine and try to connect with an IPv4 address.

Web-based Installation Error Message when AnyConnect is Launched on MAC

There are intermittent issues with you launch the AnyConnect version 2.5 on the MAC with OSX 10.5.6. The web-based installation was unsuccessful error message appears. At that time, you are unable to download and install AnyConnect, and the browser used is Firefox. If you reboot the MAC machine, this fixes the issue temporarily, but intermittently, the issue happens again.

Solution

Verify if your VPN gateways are connected in Load-balancer mode. If it is connected, then there could be some DNS cache-related issues that cause improper DNS redirects. In order to resolve this issue, always try to map the DNS URL to connect to one specific VPN gateway only.

MAC OSX 10.6.3 is Unable to get to Internet

When you use the AnyConnect on a MAC machine, you can access the Internal Corporate network but you are unable to browse to the Internet. It neither works by FQDN nor by IP address. There is a proxy server in use for Internet traffic.

Solution

The issue can be due to the length of the PMTU. Verify the existing MTU size on the VPN gateway, for example, ASA and modify it to a lesser value. In this sample output, the mtu size is reduced to 1204 from existing 1400.

AnyConnect on MAC fails to launch to Cisco IOS Router

The attempt to launch AnyConnect in standalone mode to a Cisco IOS® Router running Cisco IOS Software Release 12.4(20)T is unsuccessful. The anyconnect internal error (state: not connected) error message appears.

Solution

Cisco IOS Software Release 12.4(20)T supports AnyConnect on MAC in standalone mode without any problem. In order to resolve this, try to use the complete URL when you connect to the Cisco IOS head-end device. This is a sample URL:

If this issue persists, contact Cisco TAC (registered customers only) for further troubleshooting.

Note: You need to have valid Cisco user credentials to contact Cisco TAC.

Wireless CSSC for an Apple MAC

Currently, the NAM module on the AnyConnect 3.0 product replaces the Cisco Secure Services Client (CSSC). Refer to Network Access Manager (Replacement for CSSC) for more information. There is no current plan to enable NAM to support MAC OSX platform.

Unable to Upgrade Firefox while AnyConnect is Installed on MAC

This error message appears when you upgrade Firefox on Apple machine version 10.6:

On machines that use softtokens, this error message appears:

It is observed that these MAC machines have AnyConnect version 2.5 installed. The current version of Firefox is 3.6.13.

Solution

This behavior has been tested and filed in Cisco bug ID CSCtn93915 (registered customers only) . As a workaround, you can try any of these described options.

  • Uninstall AnyConnect, upgrade Firefox and then install AnyConnect again.

  • Uninstall the current version of firefox then install the new version. All other upgrades after this should work fine.

Web-based Installation of AnyConnect Hangs

The authentication phase works fine but the VPN system hangs at the Using Sun Java for installation phase.

Solution

The issue could be with the Java and Web applet settings on the machine. Sometimes, Java gets stuck when you use the web launch with MAC machine. Refer to Cisco bug ID CSCtq86368 (registered customers only) for more information. In order to resolve this issue, follow the below steps.

  1. Uninstall AnyConnect.

    The fastest, safest way to sell your Apple devices for the MOST cash. CashForYourMac.com pays top dollar for MacBook Pro / Air / Retina Laptops, iMac, iMac Pro, Mac Pro, Mac Mini Desktops, iPad, iPhone, Apple Watch, and LG UltraFine Displays. Cash for macbook air. CashMacs will buy your used MacBook, IMac, Mac ProMac Mini, Iphone, Ipads for instant cash. Just give us a call or send us your inquiry by filling out the form and we will contact you immediately for a quote and pay instant cash for your Apple products.

  2. Open Java preferences.

  3. Change to run applets in their own process.

  4. Drag the 32 bit Java on top.

    If this does not help, upgrade the AnyConnect client to the latest available release.

Unable to Launch AnyConnect on MAC

You are unable to launch AnyConnect on the MAC machine due to certain incompatible software. What are other options to use this MAC machine as a remote access VPN client?

Solution

Refer to What options do I have for providing remote access to Mac users? for more information. Refer to IPSec VPN client for Apple MAC for more information and complete details.

Cisco Anyconnect For Mac Certificate Error

Unable to Download the MAC AnyConnect Package

There are issues when you download the AnyConnect for MAC software from Cisco.com.

Solution

Open the Cisco AnyConnect VPN Client home page and click on Download Software (registered customers only) on the right hand side of the web page. Choose the required software package and download with valid Cisco user credentials.

Related Information

Installing Cisco AnyConnect Secure Mobility Client

You can set up a PC to run the Cisco AnyConnect Secure Mobility Client software by installing the client software for the appropriate operating system directly on the user’s PC. The user starts the Cisco AnyConnect Secure Mobility Client software and provides the authentication credentials to establish the VPN connection.

The security appliance supports the Cisco AnyConnect Secure Mobility Client Release 3.0 (use for SSL only). The Cisco AnyConnect Secure Mobility Client is compatible with the following platforms:

 •Windows 7 (32-bit and 64-bit)

 •Windows Vista (32-bit and 64-bit)

 •Windows XP SP2+ (32-bit and 64-bit)

 •Linux Intel (2.6.x kernel)

 •Mac OS X 10.5, 10.6.x, and 10.7

You can find the software installers from the CD that is packed with the security appliance. The CD includes AnyConnect packages for Windows, Mac OS X, and Linux. Choose correct AnyConnect package from the CD to download depending on your operating system.

You can also download the Cisco AnyConnect Secure Mobility Clientsoftware by going to this site:
http://www.cisco.com/cisco/software/type.html?mdfid=283000185&catid=null

Cisco Anyconnect For Macbook

You must log in and possess a valid service contract in order to access the Cisco AnyConnect Secure Mobility Clientsoftware. A 3-year Cisco Small Business Support Service Contract (CON-SBS-SVC2) is required to download the client software from Cisco.com. If you don’t have one, contact your partner or reseller, or Cisco Support for more information.

For more information about how to download, install, and configure the Cisco AnyConnect Secure Mobility Client software, go to this site:
http://www.cisco.com/en/US/products/ps10884/tsd_products_support_series_home.html

Cisco Anyconnect Download Free

Note The Cisco AnyConnect Secure Mobility Client will keep the reconnecting state after the cable of the WAN interface on the server is plugged out and then is plugged in. In this case, you must first stop the client reconnecting, and then manually connect to the SSL VPN server.