Remote Access VPN Overview
You can use the FDM to configure remote access VPN over SSL using the AnyConnect Client sofware.
When the AnyConnect Client negotiates an SSL VPN connection with the FTD device, it connects using Transport Layer Security (TLS) or Datagram Transport Layer Security (DTLS). DTLS avoids latency and bandwidth problems associated with some SSL connections and improves the performance of real-time applications that are sensitive to packet delays. The client and the FTD device negotiate the TLS/DTLS version to use. DTLS is used if the client supports it.
Maximum Concurrent VPN Sessions By Device Model
There is a maximum limit to the number of concurrent remote access VPN sessions allowed on a device based on the device model. This limit is designed so that system performance does not degrade to unacceptable levels. Use these limits for capacity planning.
Device Model |
Maximum Concurrent Remote Access VPN Sessions |
---|---|
ASA 5506-X, 5506H-X, 5506W-X |
50 |
ASA 5508-X |
100 |
ASA 5512-X, ASA 5515-X |
250 |
ASA 5516-X |
300 |
ASA 5525-X |
750 |
ASA 5545-X |
2500 |
ASA 5555-X |
5000 |
Firepower 2110 |
1500 |
Firepower 2120 |
3500 |
Firepower 2130 |
7500 |
Firepower 2140 |
10,000 |
FTDv: |
250 |
ISA 3000 |
25 |
Downloading the AnyConnect Client Software
Before you can configure a remote access VPN, you must download the AnyConnect Client software to your workstation. You will need to upload these packages when defining the VPN.
You should download the latest AnyConnect Client version, to ensure that you have the latest features, bug fixes, and security patches. Regularly update the packages on the FTD device.
Note |
You can upload one AnyConnect Client package per operating system: Windows, Mac, and Linux. You cannot upload multiple versions for a given OS type. |
Obtain the AnyConnect Client software packages from software.cisco.com. You need to download the “Full Installation Package” versions of the clients.
How Users Can Install the AnyConnect Client Software
To complete a VPN connection, your users must install the AnyConnect Client software. You can use your existing software distribution methods to install the software directly. Or, you can have users install the AnyConnect Client directly from the FTD device.
Users must have Administrator rights on their workstations to install the software.
Once the AnyConnect Client is installed, if you upload new AnyConnect Client versions to the system, the AnyConnect Client will detect the new version on the next VPN connection the user makes. The system will automatically prompt the user to download and install the updated client software. This automation simplifies software distribution for you and your clients.
If you decide to have users initially install the software from the FTD device, tell users to perform the following steps.
Note |
Android and iOS users should download the AnyConnect Client from the appropriate App Store. |
Procedure
Step 1 |
Using a web browser, open https://ravpn-address , where ravpn-address is the IP address or hostname of the outside interface on which you are allowing VPN connections. You identify this interface when you configure the remote access VPN. The system prompts the user to log in. |
Step 2 |
Log into the site. Users are authenticated using the directory server configured for the remote access VPN. Log in must be successful to continue. If log in is successful, the system determines if the user already has the required version of the AnyConnect Client. If the AnyConnect Client is absent from the user’s computer, or is down-level, the system automatically starts installing the AnyConnect Client software. When installation is finished, AnyConnect Client completes the remote access VPN connection. |