In response to recent vulnerabilities in Ivanti Connect Secure, many enterprises are reevaluating their VPN strategy. This guide provides a comprehensive step-by-step migration path to Cisco Secure Client (formerly AnyConnect), covering configuration mapping, deployment, and troubleshooting essentials.
Why Replace Ivanti VPN?
Ivanti Connect Secure (formerly Pulse Secure) has recently been impacted by several zero-day vulnerabilities that exposed enterprise VPN systems to remote exploitation. This has prompted many IT teams to transition to more robust and secure alternatives.
Cisco Secure Client—previously known as Cisco AnyConnect and now part of Cisco Secure Access—offers a stable, widely adopted VPN and endpoint visibility solution. It integrates seamlessly with Cisco security platforms and supports posture validation, telemetry, and secure tunneling.
What Is Cisco Secure Client?
Cisco Secure Client is the next-generation VPN client developed by Cisco. It replaces the legacy AnyConnect client and operates under the Cisco Secure Access platform. It offers:
- SSL and IPsec VPN tunneling
- Support for SAML, certificate-based, and multi-factor authentication
- Host posture validation (via Cisco ISE or posture modules)
- Network telemetry through Network Visibility Module (NVM)
- Compatibility with Windows, macOS, Linux, Android, and iOS
- Integration with Cisco ISE, Duo, Umbrella, and SecureX
Step-by-Step Migration Guide
Step 1: Review Current Ivanti VPN Configuration
Gather information from the existing Ivanti (Connect Secure) setup, including:
- VPN gateway address (e.g., vpn.company.com)
- Authentication methods (LDAP, RADIUS, SAML)
- Split tunneling or full tunnel settings
- DNS and IP address assignment policies
- Host Checker posture requirements
This configuration will guide your Cisco profile creation.
Step 2: Map Ivanti Settings to Cisco Secure Client
Cisco Secure Client uses XML-based profile configuration files. You can use Cisco's Profile Editor tool or manually construct XML files to match Ivanti policies.
| Configuration Element | Ivanti VPN | Cisco Secure Client |
| Gateway Address | vpn.company.com | Same |
| Authentication | LDAP / SAML | LDAP / SAML / Certificate |
| Split Tunnel Rules | ACL-based | SplitInclude / SplitExclude in XML |
| DNS Settings | Policy server | Profile-defined or ISE-pushed |
| Endpoint Posture | Host Checker | Cisco ISE + Posture Module |
Note: For SAML configurations, ensure your Identity Provider (IdP) like Okta or Azure AD supports both Ivanti and Cisco integrations.
Step 3: Conduct Pilot Testing
Before full deployment, run pilot tests with selected users:
- Install Cisco Secure Client with VPN module
- Load .xml configuration profiles into the correct directory
- Test VPN connection, authentication (especially SAML), tunnel behavior
- Monitor client logs for connection or posture issues
Step 4: Full Deployment
Roll out Cisco Secure Client organization-wide using enterprise tools:
- Windows/macOS: Microsoft Intune, SCCM, Group Policy
- Mobile Devices: Cisco Secure Client from App Store / Google Play
- Pre-load VPN profiles via MDM or include in deployment package
- Optional modules: Umbrella roaming, Duo MFA, Network Visibility Module
Ensure users are briefed on how to connect and authenticate using the new client.
Step 5: Decommission Ivanti
Once all endpoints have transitioned:
- Remove or revoke old Ivanti VPN profiles
- Uninstall Ivanti clients from user devices
- Validate all routes, DNS resolution, and posture policies are working in Cisco
- Ensure Cisco Secure Client licensing (plus ASA or FTD headend) is in place
Troubleshooting Common Issues

Frequently Asked Questions
Q1: Is Cisco Secure Client the same as AnyConnect?
A: Yes. Cisco Secure Client is the new name for AnyConnect and part of Cisco Secure Access, offering enhanced features and integration.
Q2: Can I directly import Ivanti VPN profiles into Cisco?
A: No. You need to manually rebuild them using Cisco’s XML profile structure.
Q3: Does Secure Client support SAML-based authentication?
A: Yes. It supports SAML via integration with identity providers such as Okta and Azure AD.
Q4: Can I deploy Secure Client via MDM or GPO?
A: Yes. Cisco Secure Client is compatible with most enterprise deployment platforms including Intune, Jamf, and SCCM.
Conclusion
Migrating from Ivanti VPN to Cisco Secure Client helps organizations enhance remote access security and prepare for modern zero-trust networking. With careful planning and configuration mapping, the transition can be smooth, scalable, and transparent to users.





































































































































