• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Cisco AnyConnect (server) support?

Scheduled Pinned Locked Moved Development
5 Posts 5 Posters 8.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • E
    einervonvielen
    last edited by Apr 19, 2016, 2:37 PM

    As Cisco´s AnyConnect client is very popular, I suggest to add support for it

    There´s "OpenConnect VPN Server". According to the homepage: "It implements the OpenConnect SSL VPN protocol, and has also (currently experimental) compatibility with clients using the AnyConnect SSL VPN protocol."

    • http://www.infradead.org/ocserv/
    1 Reply Last reply Reply Quote 0
    • J
      jimp Rebel Alliance Developer Netgate
      last edited by Apr 26, 2016, 3:21 PM

      The fine print of the Cisco VPN client license states that it's a violation of the license to use them with anything other than Cisco devices.

      So while you might be able to get away with installing that server and using it personally or for your company, including support for that as a feature in a distribution like pfSense may not go over so well legally.

      http://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/200191-AnyConnect-Licensing-Frequently-Asked-Qu.html#anc51

      Q. Can I use AnyConnect to make VPN connections with non-Cisco VPN head-ends?

      A. No, AnyConnect's VPN services may only be used with appropriately licensed Cisco equipment. Use of AnyConnect with non-Cisco VPN equipment is strictly prohibited by our license agreement.

      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • I
        ilvipero
        last edited by May 29, 2016, 4:42 PM

        Hello, I would like to add a few words on this discussion. I have been helping the openconnect project with some documentation and testing, so I am available to help with further clarifications if needed.

        OpenConnect server does not breach any Cisco license, it can be installed with no such problem. Actually, it is now also available in many distributions, via repos: fedora, ubuntu, debian, etc.
        OpenConnect client is available for most operative systems, such as Windows, Linux, Mac, Android. Using OpenConnect server without AnyConnect client is therefore possible.

        I would love to see OpenConnect in PFsense. A few reasons why:

        • no need to distribute profiles to clients (IPSEC client, OpenVPN client).

        • multiple profiles can be selected when connecting to same gateway IP/Hostname. Each "profile" can assign different rules to clients (Full Tunnel, Split Tunnel, etc.) No need to create multiple server instances for different rule set, like in OpenVPN.

        • compatible with many authentication methods: certificates, pam, internal users (users configured in openconnect server), radius, kerberos, dual factor authentication.

        • can be used to establish site-to-site connections between firewalls.

        • great support of proxy-arp, this can be used to avoid tap devices and still be seen as part of the "remote LAN subnet".

        • can limit client bandwidth.

        • Intrusion prevention included with multiple configuration options.

        1 Reply Last reply Reply Quote 1
        • H
          Harvy66
          last edited by May 29, 2016, 6:55 PM

          Would it actually be able to be part of PFSense' base install since it's GPL? If it stays an optional post-install package, would it be safe from GPL and the AnyVPN client license?

          1 Reply Last reply Reply Quote 0
          • D
            djzort
            last edited by Aug 31, 2017, 9:43 AM

            If it was an optional package add-on, the GPL license doesnt taint the base at all.

            +1 to this.

            This guy brought it in via freebsd packages https://blog.dhampir.no/content/pfsense-as-a-cisco-anyconnect-vpn-client-using-openconnect

            1 Reply Last reply Reply Quote 1
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received