How to Migrate from Ivanti VPN to Cisco Secure Client (AnyConnect)

Follow Us:

In response to recent vulnerabilities in Ivanti Connect Secure, many enterprises are reevaluating their VPN strategy. This guide provides a comprehensive step-by-step migration path to Cisco Secure Client (formerly AnyConnect), covering configuration mapping, deployment, and troubleshooting essentials.


Why Replace Ivanti VPN?

Ivanti Connect Secure (formerly Pulse Secure) has recently been impacted by several zero-day vulnerabilities that exposed enterprise VPN systems to remote exploitation. This has prompted many IT teams to transition to more robust and secure alternatives.

Cisco Secure Client—previously known as Cisco AnyConnect and now part of Cisco Secure Access—offers a stable, widely adopted VPN and endpoint visibility solution. It integrates seamlessly with Cisco security platforms and supports posture validation, telemetry, and secure tunneling.


What Is Cisco Secure Client?

Cisco Secure Client is the next-generation VPN client developed by Cisco. It replaces the legacy AnyConnect client and operates under the Cisco Secure Access platform. It offers:

  • SSL and IPsec VPN tunneling
  • Support for SAML, certificate-based, and multi-factor authentication
  • Host posture validation (via Cisco ISE or posture modules)
  • Network telemetry through Network Visibility Module (NVM)
  • Compatibility with Windows, macOS, Linux, Android, and iOS
  • Integration with Cisco ISE, Duo, Umbrella, and SecureX


Step-by-Step Migration Guide

Step 1: Review Current Ivanti VPN Configuration

Gather information from the existing Ivanti (Connect Secure) setup, including:

  • VPN gateway address (e.g., vpn.company.com)
  • Authentication methods (LDAP, RADIUS, SAML)
  • Split tunneling or full tunnel settings
  • DNS and IP address assignment policies
  • Host Checker posture requirements

This configuration will guide your Cisco profile creation.

Step 2: Map Ivanti Settings to Cisco Secure Client

Cisco Secure Client uses XML-based profile configuration files. You can use Cisco's Profile Editor tool or manually construct XML files to match Ivanti policies.

Configuration Element Ivanti VPN Cisco Secure Client
Gateway Address vpn.company.com Same
Authentication LDAP / SAML LDAP / SAML / Certificate
Split Tunnel Rules ACL-based SplitInclude / SplitExclude in XML
DNS Settings Policy server Profile-defined or ISE-pushed
Endpoint Posture Host Checker Cisco ISE + Posture Module

Note: For SAML configurations, ensure your Identity Provider (IdP) like Okta or Azure AD supports both Ivanti and Cisco integrations.

Step 3: Conduct Pilot Testing

Before full deployment, run pilot tests with selected users:

  • Install Cisco Secure Client with VPN module
  • Load .xml configuration profiles into the correct directory
  • Test VPN connection, authentication (especially SAML), tunnel behavior
  • Monitor client logs for connection or posture issues

Step 4: Full Deployment

Roll out Cisco Secure Client organization-wide using enterprise tools:

  • Windows/macOS: Microsoft Intune, SCCM, Group Policy
  • Mobile Devices: Cisco Secure Client from App Store / Google Play
  • Pre-load VPN profiles via MDM or include in deployment package
  • Optional modules: Umbrella roaming, Duo MFA, Network Visibility Module

Ensure users are briefed on how to connect and authenticate using the new client.

Step 5: Decommission Ivanti

Once all endpoints have transitioned:

  • Remove or revoke old Ivanti VPN profiles
  • Uninstall Ivanti clients from user devices
  • Validate all routes, DNS resolution, and posture policies are working in Cisco
  • Ensure Cisco Secure Client licensing (plus ASA or FTD headend) is in place


Troubleshooting Common Issues

Migrating from Ivanti VPN to Cisco Secure Client troubleshooting


Frequently Asked Questions

Q1: Is Cisco Secure Client the same as AnyConnect?
A: Yes. Cisco Secure Client is the new name for AnyConnect and part of Cisco Secure Access, offering enhanced features and integration.

Q2: Can I directly import Ivanti VPN profiles into Cisco?
A: No. You need to manually rebuild them using Cisco’s XML profile structure.

Q3: Does Secure Client support SAML-based authentication?
A: Yes. It supports SAML via integration with identity providers such as Okta and Azure AD.

Q4: Can I deploy Secure Client via MDM or GPO?
A: Yes. Cisco Secure Client is compatible with most enterprise deployment platforms including Intune, Jamf, and SCCM.


Conclusion

Migrating from Ivanti VPN to Cisco Secure Client helps organizations enhance remote access security and prepare for modern zero-trust networking. With careful planning and configuration mapping, the transition can be smooth, scalable, and transparent to users.