Cisco AnyConnect Secure Mobility Client Useful Tips For OS X

The most commonly encountered issues when connecting with the Cisco AnyConnect Secure Mobility Client can be fixed by altering your browser settings. If you are having problems please see the following notes:

In these notes the term "Security Gateway" refers to the Cisco device to which the Cisco AnyConnect Secure Mobility Client connects. Examples of Security Gateways include the Adaptive Security Appliance 5500 and Catalyst 6000.

The complete release notes for this product cover additional issues and are available from Cisco's website.

Adding a Security Certificate in Response to Browser Alert Windows

SSL uses certificates to identify peers in a connection. The Security Gateway has a certificate installed that is used to establish its identity. This certificate may be issued from a widely trusted source, such as Verisign or Thawte, that your computer is already configured to trust, or it may be a self-signed certificate that your computer will not trust automatically. This results in the Security warnings during connection establishment.

This section explains how to install a self-signed certificate as a trusted root certificate on a client in response to the browser alert windows.

In Response to a Netscape, Mozilla, or Firefox "Certified by an Unknown Authority" Window

Install the certificate as a trusted root certificate as follows:

  1. Click Examine Certificate in the "Web Site Certified by an Unknown Authority" window.
    The Certificate Viewer window opens.
  2. Click the Accept this certificate permanently option.
  3. Click OK.
    The Security Gateway window opens, signifying the certificate is trusted.

In Response to "Safari can't verify the identity of the website Hostname_or_IP_address" Window

Install the certificate as a trusted root certificate as follows:

  1. Click Show Certificate in the "Safari can't verify the identity of the website Hostname_or_IP_address" window.
  2. Select the option "Always trust Hostname_or_IP_address when connecting to Hostname_or_IP_address".
  3. Click Continue.
    The Security Gateway window opens, signifying the certificate is trusted.

Allowing Java Applet Execution in Safari

By default, Safari blocks execution of Java applets. Follow these steps to enable Cisco AnyConnect Secure Mobility Client's Java applet execution.

  1. Open Safari Preferences.
  2. Select Security preference.
  3. Click Manage Website Settings... button.
  4. Select Java from the options listed on left side.
  5. Change the option from Block to Allow Always for the website "Hostname_or_IP_address" you are trying to connect to.
  6. Finally, click Done.
  7. This will allow Cisco AnyConnect Secure Mobility Client Java applet to execute. Retry the VPN connection.