We use the solution to controls the VPN tunnel between people outside connected to the internet into the office network. This is done by prompting them for a username and password for security.
Some of the main features of the solution are it has the ability to integrate with our Active Directory to allow each user to have one less password to have to remember and it has great functionality.
There is one very specific improvement that could be done regarding users logging in. When a user logs in with an expired password we did not know that the password reset function would prompt them for a new password and this system was able to be deployed on this solution. For 10 years, every 30 days, the salespeople who did not want to go inside and reset their password at the 29-day mark, would call me up and have me reset their password for them to gain access. Additionally, it would be beneficial to have at the level that I am at, the ability to sign in to this solution before you log in to the Windows environment without having to upgrade the license. This should be included in the full packages.
Alternatively, when Cisco notices customers do not have this feature turned on they could call up its customers and inform them they do not have it turned on and could walk them through how to do it. It turned out to be just two lines of code to accomplish the task. In our case, during any of the interactions with Cisco over the years, they could have just mentioned to us this feature that would have real value-added to your employees. We do have a CCNA in-house and he did not realize that he could turn that feature on very easily. The white paper was probably available, but since our network administrator did not know about it, he never suggested setting it up.
In an upcoming release, there should be better reporting capabilities, this is something that is available in premium packages, or if you were to get a Cisco ISE. Essentially, the upgraded reporting shows a live version of what is going on, but it does not show you historical information unless you hook it up to a SCIM, Cisco ISE, or Cisco ACS. This should be included in all packages and you should not have to upgrade or purchase other solutions.
I have been using this solution for approximately 10 years.
When it comes to the stability of the solution it is stable, functional, and it just works.
We plan to increase our usage when our employee base increases.
I would rate the scalability of the Cisco AnyConnect Secure Mobility Client a ten out of 10.
Currently, on a day-to-day basis, there are approximately 85 users using the solution but we have 221 registered users that could use it at any given time.
The support could be more proactive in their recommendations. I noticed that the Cisco support agents tend to leave customers to do what they need to do in many ways, and you can choose how you want to do it. However, it would be great if they could proactively be involved in best practices and let other customers know how most people are doing it.
Previously we had a standard Cisco VPN client, but it was not as functional as it did not have the ability to tie into the Active Directory.
The initial setup was pretty simple. However, we did have onboarding support assist us with it. Our network administrator at the beginning of an install will always call Cisco support to get the expert on the phone. They provided us with white papers on how to do the setup allowing any setup moving forward is done correctly the first time. We did also purchase the premium support, for which there was no additional fee for the installation guideance.
Our in-house team did the implementation with their premium support tech agent on the line through a WebEx. The during of the implementation took approximately two hours.
We have a network administrator to do any maintenance that is required for the solution, but once we set it up, there really was no maintenance needed. However, we did attach an SSL to link it and set up a DNS entry to allow our users the ability to go to a specific entry instead of just typing in the IP address with the enhanced security.
We pay for an annual subscription. Additionally to the subscription, we thought in order to connect this solution to the Active Directory we had to purchase a Cisco ACS, Access Control System. It turns out we did not actually need it.
My advice to those wanting to implement this solution is you could purchase the license for this solution and set it up with your ASA directly without having to purchase a Cisco ACS.
I rate Cisco AnyConnect Secure Mobility Client a nine out of ten.