The Cisco AnyConnect Secure Mobility Client can be deployed to remote users by the following methods:
• Predeploy—New installations and upgrades are done either by the end user, or by using an enterprise
software management system (SMS).
• Web Deploy—The AnyConnect package is loaded on the headend, which is either an ASA or FTD
firewall, or an ISE server. When the user connects to a firewall or to ISE, AnyConnect is deployed to
the client.
• For new installations, the user connects to a headend to download the AnyConnect client. The client
is either installed manually or automatically (web-launch).
• Updates are done by AnyConnect running on a system where AnyConnect is already installed, or
by directing the user to the ASA clientless portal.
• Cloud Update—After the Umbrella Roaming Security module is deployed, you can update any
AnyConnect modules using one of the above methods, as well as Cloud Update. With Cloud Update,
the software upgrades are obtained automatically from the Umbrella cloud infrastructure, and the update
track is dependent upon that and not any action of the administrator. By default, automatic updates from
Cloud Update are disabled.
Consider the following regarding Cloud Update:
• Only the software modules that are currently installed are updated.
• Customizations, localizations, and any other deployment types are not
supported.
• The updates occur only when logged in to a desktop and will not happen if
a VPN is established.
• With updates disabled, the latest software features and updates will not be
available.
•Disabling Cloud Update has no effect on other update mechanisms or settings
(such as web deploy, deferred updates, and so on).
• Cloud Update ignores having newer, unreleased versions of AnyConnect
(such as interim releases and patched versions).
Note
When you deploy AnyConnect, you can include optional modules that enable extra features, and client profiles
that configure the VPN and optional features.
Refer to the AnyConnect release notes for system, management, and endpoint requirements for ASA, IOS,
Microsoft Windows, Linux, and macOS.
Some third-party applications and operating systems may restrict the ISE posture agent and other processes
from necessary file access and privilege elevation. Make sure the AnyConnect installation directory (C:\Program
Files (x86)\Cisco for Windows or /opt/cisco for macOS) is trusted and/or in the allowed/exclusion/trusted
lists for endpoint antivirus, antimalware, antispyware, data loss prevention, privilege manager, or group policy
objects.
Note
Cisco AnyConnect Secure Mobility Client Administrator Guide, Release 4.8
2
Deploy AnyConnect
AnyConnect Deployment Overview