Cisco AnyConnect Secure Mobility Client Useful Tips For Windows

The three most commonly encountered issues when connecting with the Cisco AnyConnect Secure Mobility Client can be fixed by altering your browser settings. If you are having problems please see the following notes:

In these notes the term "Security Gateway" refers to the Cisco device to which the Cisco AnyConnect Secure Mobility Client connects. Examples of Security Gateways include the Adaptive Security Appliance 5500 and Catalyst 6000.

The complete release notes for this product cover additional issues and are available from Cisco's website.

Adding a Security Gateway to the List of Trusted Sites (IE)

We recommend that Microsoft Internet Explorer (MSIE) users add the Security Gateway to the list of trusted sites. Doing so enables the ActiveX control to install with minimal interaction from the user. This is particularly important for users of Windows XP SP2 with enhanced security. See the following sections for instructions.

Follow these steps to use Microsoft Internet Explorer to add a Security Gateway to the list of trusted sites:

  1. Go to Tools > Internet Options > Trusted Sites.
    The Internet Options window opens.
  2. Click the Security tab.
  3. Click the Trusted Sites icon.
  4. Click Sites.
    The Trusted Sites window opens.
  5. Type the host name or IP address of the Security Gateway. Use a wildcard such as https://*.yourcompany.com to allow all Security Gateways within the yourcompany.com domain to be used to support multiple sites.
  6. Click Add.
  7. Click OK.
    The Trusted Sites window closes.
  8. Click OK in the Internet Options window.

Adding a Security Certificate in Response to Browser Alert Windows

SSL uses certificates to identify peers in a connection. The Security Gateway has a certificate installed that is used to establish its identity. This certificate may be issued from a widely trusted source, such as Verisign or Thawte, that your computer is already configured to trust, or it may be a self-signed certificate that your computer will not trust automatically. This results in the Security warnings during connection establishment.

This section explains how to install a self-signed certificate as a trusted root certificate on a client in response to the browser alert windows.

In Response to a Microsoft Internet Explorer "Security Alert" Window

The Microsoft Internet Explorer Security Alert window opens when you establish a Microsoft Internet Explorer connection to a Security Gateway that uses an untrusted certificate. The upper half of the Security Alert window shows the following text:

Information you exchange with this site cannot be viewed or changed by others. However, there is a problem with the site's security certificate. The security certificate was issued by a company you have not chosen to trust. View the certificate to determine whether you want to trust the certifying authority.

Follow this procedure to install a self-signed certificate as a trusted root certificate on a client in response to a Microsoft Internet Explorer Security Alert window:

  1. Click View Certificate in the Security Alert window.
    The Certificate window opens.
  2. Click Install Certificate.
    The Certificate Import Wizard Welcome opens.
  3. Click Next.
    The Certificate Import Wizard - Certificate Store window opens.
  4. Select the "Automatically select the certificate store based on the type of certificate" option.
  5. Click Next.
    The Certificate Import Wizard - Completing window opens.
  6. Click Finish.
    Another Security Warning window prompts "Do you want to install this certificate?"
  7. Click Yes.
    The Certificate Import Wizard window indicates the import is successful.
  8. Click OK to close this window.
  9. Click OK to close the Certificate window.
  10. Click Yes to close the Security Alert window.
    The Security Gateway window opens, signifying the certificate is trusted.

In Response to a Netscape, Mozilla, or Firefox "Certified by an Unknown Authority" Window

The following procedure explains how to install a self-signed certificate as a trusted root certificate on a client in response to a "Web Site Certified by an Unknown Authority" window. This window opens when you establish a Netscape, Mozilla, or Firefox connection to a Security Gateway that is not recognized as a trusted site. This window shows the following text:

Unable to verify the identity of <Hostname_or_IP_address> as a trusted site.

Install the certificate as a trusted root certificate as follows:

  1. Click Examine Certificate in the "Web Site Certified by an Unknown Authority" window.
    The Certificate Viewer window opens.
  2. Click the Accept this certificate permanently option.
  3. Click OK.
    The Security Gateway window opens, signifying the certificate is trusted.

Internet Explorer HTTP 1.1 Settings

There are two checkboxes under Internet Explorer's advanced settings that should be checked when using the VPN Client.

If you have Internet Explorer configured with a proxy, you must activate the Use HTTP 1.1 through proxy connections setting to use the VPN Client. Additionally, the Use HTTP 1.1 setting must be checked. If these option are not set, the VPN connection will not come up, and the installation process will appear to hang indefinately.

You can check to see if Internet Explorer is configured to use a proxy by going to Tools > Options > Connections > LAN Settings. If any of the checkboxes on the resulting dialog box are checked you may be connecting through a proxy.

In Internet Explorer, choose Internet Options from the Tools menu. Click the Advanced tab, and under the HTTP 1.1 Settings, check Use HTTP 1.1 through proxy connections and Use HTTP 1.1.