For additional information on AnyConnect licensing on the RV340 series routers, check out the article AnyConnect Licensing for the RV340 Series Routers.
The objective of this document is to show you the Features matrix of the Cisco AnyConnect Secure Mobility Client and the minimum release requirements, license requirements, and supported operating systems.
AnyConnect Deployment and Configuration
Connect and Disconnect Features
Authentication and Encryption Features
Feature |
Minimum ASA or ASDM Release |
License Required |
Windows |
Mac |
Linux |
---|---|---|---|---|---|
Deferred Upgrades |
ASA 9.0 ASDM 7.0 |
Plus |
yes |
yes |
yes |
Windows Services Lockdown |
ASA 8.0 (4) ASDM 6.4 (1) |
Plus |
yes |
no |
no |
Update Policy, Software and Profile Lock |
ASA 8.0 (4) ASDM 6.4 (1) |
Plus |
yes |
yes |
yes |
Auto Update |
ASA 8.0 (4) ASDM 6.3 (1) |
Plus |
yes |
yes |
yes |
Web Launch (32-bit browsers only) |
ASA 8.0 (4) ASDM 6.3 (1) |
Plus |
yes |
yes |
yes |
Pre-deployment |
ASA 8.0 (4) ASDM 6.3 (1) |
Plus |
yes |
yes |
yes |
Auto Update Client Profiles |
ASA 8.0 (4) ASDM 6.4 (1) |
Plus |
yes |
yes |
yes |
AnyConnect Profile Editor |
ASA 8.4 (1) ASDM 6.4 (1) |
Plus |
yes |
yes |
yes |
User Controllable Features |
ASA 8.0 (4) ASDM 6.3 (1) |
Plus |
yes |
yes |
no |
Core Features
Feature |
Minimum ASA or ASDM Release |
License Required |
Windows |
Mac |
Linux |
---|---|---|---|---|---|
SSL Transport Layer Security (TLS & Datagram TLS), including Per App VPN |
ASA 8.0 (4) ASDM 6.3 (1) |
Plus |
yes |
yes |
yes |
TLS Compression |
ASA 8.0 (4) ASDM 6.3 (1) |
Plus |
yes |
yes |
yes |
DTLS fallback to TLS |
ASA 8.4.2.8 ASDM 6.3 (1) |
Plus |
yes |
yes |
yes |
IPsec/IKEv2 |
ASA 8.4 (1) ASDM 6.4 (1) |
Plus |
yes |
yes |
yes |
Split tunneling |
ASA 8.0 (x) ASDM 6.3 (1) |
Plus |
yes |
yes |
no |
Split Domain Name System (DNS) |
ASA 8.0 (4) ASDM 6.3 (1) |
Plus |
yes |
yes |
no |
Ignore Browser Proxy |
ASA 8.3 (1) ASDM 6.3 (1) |
Plus |
yes |
yes |
no |
Proxy Auto Config (PAC) file generation |
ASA 8.0 (4) ASDM 6.3 (1) |
Plus |
yes |
no |
no |
Internet Explorer tab lockdown |
ASA 8.0 (4) ASDM 6.3 (1) |
Plus |
yes |
no |
no |
Optimal Gateway Selection |
ASA 8.0 (4) ASDM 6.3 (1) |
Plus |
yes |
yes |
no |
Global Site Selector (GSS) compatibility |
ASA 8.0 (4) ASDM 6.4 (1) |
Plus |
yes |
yes |
yes |
Local LAN Access |
ASA 8.0 (4) ASDM 6.3 (1) |
Plus |
yes |
yes |
yes |
Tethered device access via client firewall rules, for synchronization |
ASA 8.3 (1) ASDM 6.3 (1) |
Plus |
yes |
yes |
yes |
Local printer access via client firewall rules |
ASA 8.3 (1) ASDM 6.3 (1) |
Plus |
yes |
yes |
yes |
IPv6 |
ASA 9.0 ASDM 7.0 |
Plus |
yes |
yes |
no |
Further IPv6 implementation |
ASA 9.7.1 ASDM 7.7.1 |
Plus |
yes |
yes |
yes |
Connect and Disconnect Features
Feature |
Minimum ASA or ASDM Release |
License Required |
Windows |
Mac |
Linux |
---|---|---|---|---|---|
Simultaneous Clientless & AnyConnect connections |
ASA8.0 (4) ASDM 6.3 (1) |
Apex |
yes |
yes |
yes |
Start Before Logon (SBL) |
ASA 8.0 (4) ASDM 6.3 (1) |
Plus |
yes |
no |
no |
Run script on connect & disconnect |
ASA 8.0 (4) ASDM 6.3 (1) |
Plus |
yes |
yes |
yes |
Minimize on connect |
ASA 8.0 (4) ASDM 6.3 (1) |
Plus |
yes |
yes |
yes |
Auto connect on start |
ASA 8.0 (4) ASDM 6.3 (1) |
Plus |
yes |
yes |
yes |
Auto reconnect (disconnect on system suspend, reconnect on system resume) |
ASA 8.0 (4) ASDM 6.3 (1) |
Plus |
yes |
yes |
no |
Remote User VPN Establishment (permitted or denied) |
ASA 8.0 (4) ASDM 6.3 (1) |
Plus |
yes |
no |
no |
Logon Enforcement (terminate VPN session if another user logs in) |
ASA 8.0 (4) ASDM 6.3 (1) |
Plus |
yes |
no |
no |
Retain VPN session (when user logs off, and then when this or another user logs in) |
ASA 8.0 (4) ASDM 6.3 (1) |
Plus |
yes |
no |
no |
Trusted Network Detection (TND) |
ASA 8.0 (4) ASDM 6.3 (1) |
Plus |
yes |
yes |
no |
Always on (VPN must be connected to access network) |
ASA 8.0 (4) ASDM 6.3 (1) |
Plus |
yes |
yes |
no |
Always on exemption via Directory Access Protocol (DAP) |
ASA 8.3 (1) ASDM 6.3 (1) |
Plus |
yes |
yes |
no |
Connect Failure Policy (Internet access allowed or disallowed if VPN connection fails) |
ASA 8.0 (4) ASDM 6.3 (1) |
Plus |
yes |
yes |
no |
Captive Portal Detection |
ASA 8.0 (4) ASDM 6.3 (1) |
Plus |
yes |
yes |
no |
Captive Portal Remediation |
ASA 8.0 (4) ASDM 6.3 (1) |
Plus |
yes |
yes |
no |
Authentication and Encryption Features
Feature |
Minimum ASA or ASDM Release |
License Required |
Windows |
Mac |
Linux |
---|---|---|---|---|---|
Certificate only authentication |
ASA 8.0 (4) ASDM 6.3 (1) |
Plus |
yes |
yes |
yes |
RSA SecurID /SoftID integration |
Plus |
yes |
no |
no |
|
Smartcard support |
Plus |
yes |
yes |
no |
|
Simple Certificate Enrollment Protocol (SCEP) (requires Posture Module if Machine ID is used) |
Plus |
yes |
yes |
no |
|
List & select certificates |
Plus |
yes |
no |
no |
|
FIPS |
Plus |
yes |
yes |
yes |
|
Secure Hash Algorithm (SHA)-2 for IPsec IKEv2 (Digital Signatures, Integrity, & PRF) |
ASA 8.0 (4) ASDM 6.4 (1) |
Plus |
yes |
yes |
yes |
Strong Encryption Advanced Encryption Standard (AES-256 & 3des-168) |
Plus |
yes |
yes |
yes |
|
Network Security Appliance (NSA) Suite-B (IPsec only) |
ASA 9.0 ASDM 7.0 |
Apex |
yes |
yes |
yes |
Enable Certificate Revocation List (CRL) check |
n/a |
Apex |
yes |
no |
no |
SAML 2.0 SSO |
ASA 9.7.1 ASDM 7.7.1 |
Apex or VPN only |
yes |
yes |
yes |
Multiple-certificate authentication |
ASA 9.7.1 ASDM 7.7.1 |
Plus, Apex, or VPN only |
yes |
yes |
yes |
Interfaces
Feature |
Minimum ASA or ASDM Release |
License Required |
Windows |
Mac |
Linux |
---|---|---|---|---|---|
Graphical User Interface (GUI) |
ASA 8.0 (4) ASDM 6.3 (1) |
Plus |
yes |
yes |
yes |
Command Line |
yes |
yes |
yes |
||
Application Programming Interface |
yes |
yes |
yes |
||
Microsoft Component Object Module (COM) |
yes |
no |
no |
||
Localization of User Messages |
yes |
yes |
no |
||
Custom MSI transforms |
yes |
no |
no |
||
User defined resource files |
yes |
yes |
no |
||
Client Help |
ASA 9.0 ASDM 7.0 |
yes |
yes |
yes |