69-118
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter69 General VPN Setup
AnyConnect Essentials
Note Choose Configuration > VPN > IPsec > Pre-Fragmentation, double-click the outside
interface, and set the DF Bit Setting Policy to Clear if you configure the Easy VPN Remote
connection to use TCP-encapsulated IPsec. The Clear setting lets the ASA send large
packets.
Enter Port Number—Specifies the port number to use for the IPsec over TCP connection.
Server Certificate—Configures the Easy VPN Remote connection to accept only connections to
Easy VPN servers with the specific certificates specified by the certificate map. Use this parameter
to enable Easy VPN server certificate filtering. To define a certificate map, go to Configuration >
VPN > IKE > Certificate Group Matching> Rules.
Modes
The following table shows the modes in which this feature is available:
AnyConnect Essentials
AnyConnect Essentials is a separately licensed SSL VPN client, entirely configured on the ASA, that
provides the full AnyConnect capability, with the following exceptions:
No CSD (including HostScan/Vault/Cache Cleaner)
No clientless SSL VPN
Optional Windows Mobile Support (requires AnyConnect for Windows Mobile license)
The AnyConnect Essentials client provides remote end users running Microsoft Windows Vista,
Windows Mobile, Windows XP or Windows 2000, Linux, or Macintosh OS X, with the benefits of a
Cisco SSL VPN client.
To enable AnyConnect Essentials, check the Enable AnyConnect Essentials check box on the
AnyConnect Essentials pane, which appears only if the AnyConnect Essentials license is installed on the
ASA.
When AnyConnect Essentials is enabled, AnyConnect clients use Essentials mode, and clientless SSL
VPN access is disabled. When AnyConnect Essentials is disabled, AnyConnect clients use the full
AnyConnect SSL VPN Client.
Note The status information about the AnyConnect Essentials license on the Configuration > Device
Management > Licensing > Activation Key pane simply reflects whether the AnyConnect Essentials
license is installed. This status is not affected by the setting of the Enable AnyConnect Essentials License
check box.
Firewall Mode Security Context
Routed Transparent Single
Multiple
Context System
——