Cisco Anyconnect Vpn Linux



Cisco AnyConnect VPN in Linux (Ubuntu 19.10) Hojjat. Cisco AnyConnect can be installed through the Graphic User Interface (GUI) or Command Line (CLI). Certain Departmental Pools, Full Tunnel VPN, and Split Tunnel VPN Pools require Two Factor Authentication (2FA) through Duo Security to connect. Using Duo and VPN is outlined in Using Duo Append Mode with Cisco AnyConnect.

Kmgmt-785-AnyConnect-Linux-Ubuntu

Objective

The objective of this article is to guide you through installing, using, and the option of uninstalling AnyConnect VPN Client v4.9.x on Ubuntu Desktop.

Introduction

The Cisco AnyConnect Virtual Private Network (VPN) Mobility Client provides remote users with a secure VPN connection. It provides the benefits of a Cisco Secure Sockets Layer (SSL) VPN client and supports applications and functions unavailable to a browser-based SSL VPN connection. Commonly used by remote workers, AnyConnect VPN lets employees connect to the corporate network infrastructure as if they were physically at the office, even when they are not. This adds to the flexibility, mobility, and productivity of your workers. Cisco AnyConnect is compatible with Windows 7, 8, 8.1, and 10, Mac OS X 10.8 and later, and Linux Intel (x64).

Follow the steps in this article to install the Cisco AnyConnect VPN Mobility Client on a Ubuntu Desktop. In this article, Ubuntu version 20.04 is used.

If you are using a Windows computer, click here to view an article on how to install AnyConnect on Windows.

If you are using a Mac computer, click here to view an article on how to install AnyConnect on Mac.

AnyConnect Software Version

  • AnyConnect - v4.9.x (Download latest)

Table of Contents

Installing AnyConnect Secure Mobility Client v4.9.x

Step 1

Cisco Vpn Client For Linux

Download the AnyConnect Pre-Deployment Package for Linux from Cisco Software Downloads.

The latest release at the time of publication was 4.9.01095.

Step 2

Cisco Anyconnect Vpn Linux

Open the Terminal by pressing Ctrl+Alt+T on your keyboard. To navigate to the folder where you have downloaded the AnyConnect Client Package, use the command, ‘cddirectory name’. For more information on the ‘cd’ command, click here.

In this example, the file is placed on the Desktop.

The directory may be different based on the location of the AnyConnect file download. For long filenames or paths, start typing some characters and press the tab key on your keyboard. The filename will auto-populate. If it doesn't even after you press tab twice, it indicates that you need to type more number of unique characters. Alternately, you can use the 'ls' command to list the files in your current directory.

Step 3

The initial download is a tarball archive (several files packed into one), which must be extracted. The command ‘tar xvffilename’ will extract the contents to the same directory in which the initial file is located.

For more information on the ‘tar’ command, click here.

Step 4

Once the folder is extracted, use the ‘cddirectory name’ command again to navigate into the folder.

cd [Directory Name]

Step 5

After navigating into the main folder, ‘cd’ into the vpn sub-folder.

Cisco

Step 6

To run the AnyConnect install script, type ‘sudo ./vpn_install.sh’. This will begin the installation process using superuser permissions.

sudo ./vpn_install.sh

For more details on the 'sudo' command, click here.

Step 7

Accept the terms in the license agreement to complete the installation by typing ‘y’.

The AnyConnect installation should complete, and the Terminal window can be closed.

Using AnyConnect Secure Mobility Client v4.9.x

Step 1

To access the Anyconnect app, open the Terminal by pressing Ctrl+Alt+T on your keyboard. Use the command, ‘/opt/cisco/anyconnect/bin/vpnui’.

/opt/cisco/anyconnect/bin/vpnui

If you encounter any errors through the Terminal, you can access the app from the applications menu as shown below.

To access the applications menu using the User Interface (UI), click on the start icon (appears as nine dots on the lower left corner). Choose the Anyconnect app.

Alternatively, press Super+A (Super key is the windows icon key) on your keyboard to bring up the search bar. Start typing 'Anyconnect' and the app will appear.

Step 2

Click on the Anyconnect app.

Step 3

Enter the IP Address or Hostname of your desired server followed by the port number.

For RV340 family, the default port number is 8443.

Step 4

Some connections may not be secure using a trusted SSL certificate. By default, AnyConnect Client will block connection attempts to these servers.

Uncheck Block connections to untrusted servers to connect to these servers.

Uninstalling AnyConnect Secure Mobility Client v4.9.x

Step 1

Cisco Anyconnect Vpn Download Free

Using Terminal, navigate to the folder that contains the uninstall shell script using the ‘cd’ command.

In a default installation, these files will be located in /opt/cisco/anyconnect/bin/.

Step 2

To run the Anyconnect uninstall script, enter ‘sudo ./vpn_uninstall.sh’

This will begin the uninstall process using superuser permissions. For more information on the 'sudo' command, click here.

Step 3

At the prompt, enter the sudo password and the client software will complete uninstallation.

Conclusion

There you have it! You have now successfully learned the steps to install, use, and uninstall the Cisco AnyConnect Secure Mobility Client v4.9.x on Ubuntu Desktop.

For community discussions on Site-to-Site VPN, go to the Cisco Small Business Support Community page and do a search for Site-to-Site VPN.

AnyConnect App

The Anyconnect App can be downloaded from the Google Play store or the Apple store.

Additional Resources

Connect to Cornell's VPN using Cisco AnyConnect software.

To use Cornell's Virtual Private Network (VPN) with campus networks and services, you must use Cisco AnyConnect VPN software. See the How to Install Cisco VPN Software page for instructions.

Connect to CU VPN with NetID Login

  1. At the command line (in a Terminal window), enter:
    /opt/cisco/anyconnect/bin/vpnui &
    or
    launch via Applications - Internet - Cisco AnyConnect Secure Mobility Client.
  2. In the AnyConnect window be sure that cuvpn.cuvpn.cornell.edu is selected in the Connect To box, then click Connect.
  3. In the Cisco AnyConnect window:
    • In the Group box, select CornellVPN to log in to CU VPN.
    • In the User Name box, enter your Cornell NetID or GuestID.
      Note: If you are connecting to a departmental VPN, enter your NetID and the name of the departmental group, for example, pqs665@departmental_group_name.
    • In the Password box, enter your NetID password.
  4. Click Connect. You're now connected to CU VPN.
Login Failed: If you see a message that the login failed, you may be attempting to connect to a departmental VPN where Two-Step Login is required. See Connect to CU VPN using Two-Step Login.

Connect to CU VPN with Two-Step Login

Duo Security provides documentation on how to log in to the Cisco AnyConnect client used with Cornell's VPN service. For more information, see Logging in with Cisco AnyConnect Client.

Cisco Anyconnect Vpn Linux
  1. At the command line (in a Terminal window), enter:
    /opt/cisco/anyconnect/bin/vpnui &
    or
    launch via Applications - Internet - Cisco AnyConnect Secure Mobility Client.
  2. In the AnyConnect window be sure that cuvpn.cuvpn.cornell.edu is selected in the Connect To box, then click Connect.
  3. In the Cisco AnyConnect window:
    • In the Group box, select Two-Step_Login. This is required for departmental VPNs with Two-Step Login enabled, but you can use it any time.
    • In the User Name box, enter your Cornell NetID or GuestID.
      Note: If you are connecting to a departmental VPN, enter your NetID and the name of the departmental group, for example, pqs665@departmental_group_name.
    • In the Password box, enter your NetID password.
    • In the DUO Passcode (push/sms/phone) box, enter the method you use to complete Two-Step Login:
      push
      phone
      a 7-digit passcode
      SMS to receive a new set of passcodes. (You'll need to log in again.)
  4. Click Connect.
  5. If you entered push or phone, complete the Two-Step Login process.
    You're now connected to CU VPN.

Cisco Anyconnect Secure Mobility Linux

If you don't have access to the default device you use for Two-Step Login, you can use an alternate device. In Step 3 above, enter the method you use to complete Two-Step Login followed by a number, for example push2 or phone2. To see the devices you have set up and the numbers to use for each, go to Your Two-Step Login Devices and use the number in the Device Number column.