Cisco AnyConnect Secure Mobility Client Administrator Guide, Release 4.4
The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.
Book Title
Cisco AnyConnect Secure Mobility Client Administrator Guide, Release 4.4
The AnyConnect Profile Editor
View with Adobe Reader on a variety of devices
Results
Chapter: The AnyConnect Profile Editor
The AnyConnect Profile Editor
About the Profile Editor
The Cisco AnyConnect Secure Mobility Client software package contains a profile editor for all operating systems. ASDM activates the profile editor when you load the AnyConnect client image on the ASA. You can upload a client profile from local or flash.
If you load multiple AnyConnect packages, ASDM activates the client profile editor from the newest AnyConnect package. This approach ensures that the editor displays the features for the newest AnyConnect loaded, as well as the older clients.
There is also a stand-alone profile editor which runs on Windows.
Add a New Profile from ASDM
You must first upload a client image before creating a client profile.
Profiles are deployed to administrator-defined end user requirements and authentication policies on endpoints as part of AnyConnect, and they make the preconfigured network profiles available to end users. Use the profile editor to create and configure one or more profiles. AnyConnect includes the profile editor as part of ASDM and as a stand-alone Windows program.
To add a new client profile to the ASA from ASDM:
Procedure
Open ASDM and select Configuration > Remote Access VPN > Network (Client) Access > AnyConnect Client Profile .
Enter a profile name.
From the Profile Usage drop-down list, choose the module for which you are creating a profile.
(Optional) In the Profile Location field, click Browse Flash and select a device file path for the XML file on the ASA.
(Optional) If you created a profile with the stand-alone editor, click Upload to use that profile definition.
(Optional) Choose an AnyConnect group policy from the drop-down list.
The AnyConnect VPN Profile
Cisco AnyConnect Secure Mobility Client features are enabled in the AnyConnect profiles. These profiles contain configuration settings for the core client VPN functionality and for the optional client modules Network Access Manager, ISE posture, customer experience feedback, and Web Security. The ASA deploys the profiles during AnyConnect installation and updates. Users cannot manage or modify profiles.
You can configure the ASA or ISE to deploy profiles globally for all AnyConnect users or to users based on their group policy. Usually, a user has a single profile file for each AnyConnect module installed. In some cases, you might want to provide more than one VPN profile for a user. Someone who works from multiple locations might need more than one VPN profile.
Some profile settings are stored locally on the user’s computer in a user preferences file or a global preferences file. The user file has information the AnyConnect client needs to display user-controllable settings in the Preferences tab of the client GUI and information about the last connection, such as the user, the group, and the host.
The global file has information about user-controllable settings so that you can apply those settings before login (since there is no user). For example, the client needs to know if Start Before Logon and/or AutoConnect On Start are enabled before login.
AnyConnect Profile Editor, Preferences (Part 1)
Use Start Before Logon — (Windows Only) Forces the user to connect to the enterprise infrastructure over a VPN connection before logging on to Windows by starting AnyConnect before the Windows login dialog box appears. After authenticating, the login dialog box appears and the user logs in as usual.
Show Pre-connect Message — Enables an administrator to have a one-time message displayed prior to a users first connection attempt. For example, the message can remind users to insert their smart card into its reader. The message appears in the AnyConnect message catalog and is localized.
Certificate Store —Controls which certificate store(s) AnyConnect uses for storing and reading certificates. The secure gateway must be configured accordingly and dictates to the client which one of the multiple certificate authentication combinations is acceptable for a particular VPN connection.
The value of the CertificateStore configuration in the VPN profile depends on the types of certificates that are acceptable to the secure gateway: either two user certificates or one machine and one user certificate.
All (for Windows)—One machine and one user certificate is acceptable by ASA configuration.
User (for Windows)—Two user certificates are acceptable by ASA configuration.
Certificate Store Override — Allows an administrator to direct AnyConnect to utilize certificates in the Windows machine (Local System) certificate store for client certificate authentication. Certificate Store Override only applies to SSL, where the connection is initiated, by default, by the UI process. When using IPSec/IKEv2, this feature in the AnyConnect Profile is not applicable.
You must have a predeployed profile with this option enabled in order to connect with Windows using a machine certificate. If this profile does not exist on a Windows device prior to connection, the certificate is not accessible in the machine store, and the connection fails.
True —AnyConnect will search for certificates in the Windows machine certificate store. If CertificateStore is set to all, then CertificateStoreOverride must be set to true.
False —AnyConnect will not search for certificates in the Windows machine certificate store.
AutomaticCertSelection —When multiple certificate authentication is configured on the secure gateway, you must set this value to true .
Auto Connect on Start — AnyConnect, when started, automatically establishes a VPN connection with the secure gateway specified by the AnyConnect profile, or to the last gateway to which the client connected.
Minimize On Connect — After establishing a VPN connection, the AnyConnect GUI minimizes.
Local LAN Access — Allows the user complete access to the local LAN connected to the remote computer during the VPN session to the ASA.
Enabling local LAN access can potentially create a security weakness from the public network through the user computer into the corporate network. Alternatively, you can configure the security appliance (version 8.4(1) or later) to deploy an SSL client firewall that uses the AnyConnect Client Local Print firewall rule included in the default group policy. In order to enable this firewall rule, you also must enable Automatic VPN Policy, Always on, and Allow VPN Disconnect in this editor, Preferences (Part 2).
Disable Captive Portal Detection — When an AnyConnect client receives a certificate with a common name that does not match the ASA name, a captive portal is detected. This behavior prompts the user to authenticate. Some users using self signed certificates may want to enable connection to corporate resources behind an HTTP captive portal and should thus mark the Disable Captive Portal Detection checkbox. The administrator can also determine if they want the option to be user configurable and mark the checkbox accordingly. If user configurable is selected, the checkbox appears on the Preferences tab of the AnyConnect Secure Mobility Client UI.
Auto Reconnect — AnyConnect attempts to reestablish a VPN connection if you lose connectivity. If you disable Auto Reconnect, it does not attempt to reconnect, regardless of the cause of the disconnection.
Use Auto Reconnect in scenarios where the user has control over the behavior of the client. This feature is not supported with AlwaysOn.
Auto Reconnect Behavior
DisconnectOnSuspend—AnyConnect releases the resources assigned to the VPN session upon a system suspend and does not attempt to reconnect after the system resumes.
ReconnectAfterResume (Default)—AnyConnect attempts to reestablish a VPN connection if you lose connectivity.
Auto Update — When checked, enables the automatic update of the client. If you check User Controllable, the user can override this setting in the client.
RSA Secure ID Integration (Windows only)— Controls how the user interacts with RSA. By default, AnyConnect determines the correct method of RSA interaction (automatic setting: both software or hardware tokens accepted).
Windows Logon Enforcement — Allows a VPN session to be established from a Remote Desktop Protocol (RDP) session. Split tunneling must be configured in the group policy. AnyConnect disconnects the VPN connection when the user who established the VPN connection logs off. If the connection is established by a remote user, and that remote user logs off, the VPN connection terminates.
Windows VPN Establishment — Determines the behavior of AnyConnect when a user who is remotely logged on to the client PC establishes a VPN connection. The possible values are:
Local Users Only (Default)—Prevents a remotely logged-on user from establishing a VPN connection. This is the same functionality as in prior versions of AnyConnect.
Allow Remote Users—Allows remote users to establish a VPN connection. However, if the configured VPN connection routing causes the remote user to become disconnected, the VPN connection terminates to allow the remote user to regain access to the client PC. Remote users must wait 90 seconds after VPN establishment if they want to disconnect their remote login session without causing the VPN connection to be terminated.
Clear SmartCard PIN
IP Protocol Supported — For clients with both an IPv4 and IPv6 address attempting to connect to the ASA using AnyConnect, AnyConnect needs to decide which IP protocol to use to initiate the connection. By default AnyConnect initially attempts to connect using IPv4. If that is not successful, AnyConnect attempts to initiate the connection using IPv6.
This field configures the initial IP protocol and order of fallback.
IPv4—Only IPv4 connections can be made to the ASA.
IPv6—Only IPv6 connections can be made to the ASA.
IPv4, IPv6—First, attempt to make an IPv4 connection to the ASA. If the client cannot connect using IPv4, then try to make an IPv6 connection.
IPv6, IPv4—First attempt to make an IPv6 connection to the ASA. If the client cannot connect using IPv6 then try to make an IPv4 connection.
The IP protocol failover can also happen during the VPN session. Whether performed prior to or during the VPN session, the failover is maintained until the currently used secure gateway IP address is no longer reachable. The client fails over to the IP address matching the alternate IP protocol, if available, whenever the currently used IP address address isn’t reachable.
AnyConnect Profile Editor, Preferences (Part 2)
Disable Automatic Certificate Selection (Windows only)— Disables automatic certificate selection by the client and prompts the user to select the authentication certificate.
Proxy Settings — Specifies a policy in the AnyConnect profile to control client access to a proxy server. Use this when a proxy configuration prevents the user from establishing a tunnel from outside the corporate network.
Native—Causes the client to use both proxy settings previously configured by AnyConnect, and the proxy settings configured in the browser. The proxy settings configured in the global user preferences are pre-pended to the browser proxy settings.
IgnoreProxy—Ignores the browser proxy settings on the user’s computer.
Override—Manually configures the address of the Public Proxy Server. Public proxy is the only type of proxy supported for Linux. Windows also supports public proxy. You can configure the public proxy address to be User Controllable.
Allow Local Proxy Connections — By default, AnyConnect lets Windows users establish a VPN session through a transparent or non-transparent proxy service on the local PC. Uncheck this parameter if you want to disable support for local proxy connections. Some examples of elements that provide a transparent proxy service include acceleration software provided by some wireless data cards, and network component on some antivirus software
Enable Optimal Gateway Selection (OGS), (IPv4 clients only)— AnyConnect identifies and selects which secure gateway is best for connection or reconnection based on the round trip time (RTT), minimizing latency for Internet traffic without user intervention. OGS is not a security feature, and it performs no load balancing between secure gateway clusters or within clusters. You control the activation and deactivation of OGS and specify whether end users may control the feature themselves. Automatic Selection displays in the Connect To drop-down list on the Connection tab of the client GUI.
Suspension Time Threshold (hours)— Enter the minimum time (in hours) that the VPN must have been suspended before invoking a new gateway-selection calculation. By optimizing this value in combination with the next configurable parameter (Performance Improvement Threshold), you can find the correct balance between selecting the optimal gateway and reducing the number of times to force the re-entering of credentials.
Performance Improvement Threshold (%)— The percentage of performance improvement that triggers the client to re-connect to another secure gateway following a system resume. Adjust these values for your particular network to find the correct balance between selecting the optimal gateway and reducing the number of times to force the re-entering of credentials. The default is 20%.
When OGS is enabled, we recommend that you also make the feature user-controllable.
OGS has the following limitations:
It cannot operate with Always On
It cannot operate with automatic proxy detection
It cannot operate with proxy auto-configuration (PAC) files
If AAA is used, users may have to re-enter their credentials when transitioning to a different secure gateway. Using certificates eliminates this problem.
Automatic VPN Policy (Windows and macOS only)— Enables Trusted Network Detection allowing AnyConnect to automatically manage when to start or stop a VPN connection according to the Trusted Network Policy and Untrusted Network Policy. If disabled, VPN connections can only be started and stopped manually. Setting an Automatic VPN Policy does not prevent users from manually controlling a VPN connection.
Trusted Network Policy — Action AnyConnect automatically takes on the VPN connection when the user is inside the corporate network (the trusted network).
Disconnect (Default)—Disconnects the VPN connection upon the detection of the trusted network.
Connect—Initiates a VPN connection upon the detection of the trusted network.
Do Nothing—Takes no action in the untrusted network. Setting both the Trusted Network Policy and Untrusted Network Policy to Do Nothing disables Trusted Network Detection.
Pause—AnyConnect suspends the VPN session instead of disconnecting it if a user enters a network configured as trusted after establishing a VPN session outside the trusted network. When the user goes outside the trusted network again, AnyConnect resumes the session. This feature is for the user’s convenience because it eliminates the need to establish a new VPN session after leaving a trusted network.
Untrusted Network Policy — AnyConnect starts the VPN connection when the user is outside the corporate network (the untrusted network). This feature encourages greater security awareness by initiating a VPN connection when the user is outside the trusted network.
Connect (Default)—Initiates the VPN connection upon the detection of an untrusted network.
Do Nothing—Takes no action in the trusted network. This option disables Always-On VPN. Setting both the Trusted Network Policy and Untrusted Network Policy to Do Nothing disables Trusted Network Detection.
If you are using NVM, Trusted DNS Domains and Servers are not supported because the the NVM module uses an administrator-defined trusted server and certificate hash to determine whether the user is on a trusted or untrusted network.
Trusted Servers @ https://<server>[:<port>] —The host URL that you want to add as trusted. After you click Add , the URL is added, and the certificate hash is pre-filled. If the hash is not found, an error message prompts the user to enter the certificate hash manually and click Set .
You must have a secure web server that is accessible with a trusted certificate to be considered trusted. Secure TND attempts a connection to the first configured server in the list. If the server cannot be contacted, secure TND attempts to contact the next server in the configured list. If the server can be contacted but the hash of the certificate doesn’t match, the network will be identified as «untrusted.» No other servers will be evaluated. If the hash is trusted, the «trusted» criteria is met.
You can configure this parameter only when at least one of the Trusted DNS Domains or Trusted DNS Servers is defined. If Trusted DNS Domains or Trusted DNS Servers are not defined, this field is disabled.
Always On —Determines whether AnyConnect automatically connects to the VPN when the user logs in to a computer running one of the supported Windows or macOS operating systems. You can enforce corporate policies, protecting the computer from security threats by preventing access to Internet resources when it is not in a trusted network. You can set the Always-On VPN parameter in group policies and dynamic access policies to override this setting by specifying exceptions according to the matching criteria used to assign the policy. If an AnyConnect policy enables Always-On and a dynamic access policy or group policy disables it, the client retains the disable setting for the current and future VPN sessions, as long as its criteria match the dynamic access policy or group policy on the establishment of each new session. After enabling, you will be able to configure additional parameters.
| Note | AlwaysOn is used for scenarios where the connection establishment and redundancy run without user intervention; therefore, while using this feature, you need not configure or enable Auto Reconnect in Preferences, part 1. |
Allow VPN Disconnect —Determines whether AnyConnect displays a Disconnect button for Always-On VPN sessions. Users of Always-On VPN sessions may want to click Disconnect so they can choose an alternative secure gateway for reasons such as performance issues with the current VPN session or reconnection issues following the interruption of a VPN session.
The Disconnect locks all interfaces to prevent data from leaking out and to protect the computer from internet access except for establishing a VPN session. For the reasons noted above, disabling the Disconnect button can at times hinder or prevent VPN access.
Connect Failure Policy —Determines whether the computer can access the Internet if AnyConnect cannot establish a VPN session (for example, when an ASA is unreachable). This parameter applies only if Always-On and Allow VPN Disconnect are enabled. If you choose Always-On , the fail-open policy permits network connectivity, and the fail-close policy disables network connectivity.
Closed—Restricts network access when the VPN is unreachable. The purpose of this setting is to help protect corporate assets from network threats when resources in the private network responsible for protecting the endpoint are unavailable.
Open—Permits network access when the VPN is unreachable.
A connect failure closed policy prevents network access if AnyConnect fails to establish a VPN session. It is primarily for exceptionally secure organizations where security persistence is a greater concern than always-available network access. It prevents all network access except for local resources such as printers and tethered devices permitted by split tunneling and limited by ACLs. It can halt productivity if users require Internet access beyond the VPN if a secure gateway is unavailable. AnyConnect detects most captive portals. If it cannot detect a captive portal, a connect failure closed policy prevents all network connectivity.
If you deploy a closed connection policy, we highly recommend that you follow a phased approach. For example, first deploy Always-On VPN with a connect failure open policy and survey users for the frequency with which AnyConnect does not connect seamlessly. Then deploy a small pilot deployment of a connect failure closed policy among early-adopter users and solicit their feedback. Expand the pilot program gradually while continuing to solicit feedback before considering a full deployment. As you deploy a connect failure closed policy, be sure to educate the VPN users about the network access limitation as well as the advantages of a connect failure closed policy.
If Connect Failure Policy is Closed, then you can configure the following settings:
Allow Captive Portal Remediation —Lets AnyConnect lift the network access restrictions imposed by the closed connect failure policy when the client detects a captive portal (hotspot). Hotels and airports typically use captive portals to require the user to open a browser and satisfy conditions required to permit Internet access. By default, this parameter is unchecked to provide the greatest security; however, you must enable it if you want the client to connect to the VPN if a captive portal is preventing it from doing so.
Remediation Timeout —Number of minutes AnyConnect lifts the network access restrictions. This parameter applies if the Allow Captive Portal Remediation parameter is checked and the client detects a captive portal. Specify enough time to meet typical captive portal requirements (for example, 5 minutes).
Apply Last VPN Local Resource Rules —If the VPN is unreachable, the client applies the last client firewall it received from the ASA, which may include ACLs allowing access to resources on the local LAN.
Captive Portal Remediation Browser Failover—Allows the end user to use an external browser (after closing the AnyConnect browser) for captive portal remediation.
Allow Manual Host Input —Enables users to enter different VPN addresses than those listed in the drop-down box of the AnyConnect UI. If you uncheck this checkbox, the VPN connection choices are only those in the drop-down box, and users are restricted from entering a new VPN address.
PPP Exclusion —For a VPN tunnel over a PPP connection, specifies whether and how to determine the exclusion route. The client can exclude traffic destined for the secure gateway from the tunneled traffic intended for destinations beyond the secure gateway. The exclusion route appears as a non-secured route in the Route Details display of the AnyConnect GUI. If you make this feature user controllable, users can read and change the PPP exclusion settings.
Automatic—Enables PPP exclusion. AnyConnect automatically determines the IP address of the PPP server.
Override—Enables PPP Exclusion using a predefined server IP address specified in the PPP Exclusion Server IP field. The PPP Exclusion Server IP field is only applicable to this Override method and should only be used when the Automatic options fails to detect the IP address of the PPP server.
Checking User Controllable for the PPP Exclusion Server IP field allows the end user to manually update the IP address via the preferences.xml file. Refer to the Instruct Users to Override PPP Exclusion section.
Disabled—PPP exclusion is not applied.
Enable Scripting —Launches OnConnect and OnDisconnect scripts if present on the security appliance flash memory.
Terminate Script On Next Event —Terminates a running script process if a transition to another scriptable event occurs. For example, AnyConnect terminates a running OnConnect script if the VPN session ends, and terminates a running OnDisconnect script if the client starts a new VPN session. On Microsoft Windows, the client also terminates any scripts that the OnConnect or OnDisconnect script launched, and all their script descendents. On macOS and Linux, the client terminates only the OnConnect or OnDisconnect script; it does not terminate child scripts.
Enable Post SBL On Connect Script —Launches the OnConnect script if present, and SBL establishes the VPN session. (Only supported if VPN endpoint is running Microsoft Windows.)
Retain VPN On Logoff—Determines whether to keep the VPN session when the user logs off a Windows OS.
User Enforcement —Specifies whether to end the VPN session if a different user logs on. This parameter applies only if “Retain VPN On Logoff” is checked, and the original user logged off Windows when the VPN session was up.
Authentication Timeout Values—By default, AnyConnect waits up to 12 seconds for an authentication from the secure gateway before terminating the connection attempt. AnyConnect then displays a message indicating the authentication timed out. Enter a number of seconds in the range of 10 to 120.
AnyConnect Profile Editor, Backup Servers
You can configure a list of backup servers the client uses in case the user-selected server fails. If the user-selected server fails, the client attempts to connect to the optimal server’s backup at the top of the list. If that fails, the client attempts each remaining server in the Optimal Gateway Selection list, ordered by its selection results.
Any backup servers that you configure here are only attempted when no backup servers are defined in AnyConnect Profile Editor, Add/Edit a Server List. Those servers configured in the Server List take precedence, and backup servers listed here are overwritten.
Host Address —Specifies an IP address or a Fully-Qualified Domain Name (FQDN) to include in the backup server list.
Add —Adds the host address to the backup server list.
Move Up —Moves the selected backup server higher in the list. If the user-selected server fails, the client attempts to connect to the backup server at the top of the list first, and moves down the list, if necessary.
Move Down —Moves the selected backup server down in the list.
Delete —Removes the backup server from the server list.
AnyConnect Profile Editor, Certificate Matching
Enable the definition of various attributes that can be used to refine automatic client certificate selection on this pane.
If no certificate matching criteria is specified, AnyConnect applies the following certificate matching rules:
Key Usage: Digital_Signature
Extended Key Usage: Client Auth
If any criteria matching specifications are made in the profile, neither of these matching rules are applied unless they are specifically listed in the profile.
Key Usage —Use the following Certificate Key attributes for choosing acceptable client certificates:
Decipher_Only—Deciphering data, and that no other bit (except Key_Agreement) is set.
Encipher_Only—Enciphering data, and any other bit (except Key_Agreement) is not set.
CRL_Sign—Verifying the CA signature on a CRL.
Key_Cert_Sign—Verifying the CA signature on a certificate.
Data_Encipherment—Encrypting data other than Key_Encipherment.
Non_Repudiation—Verifying digital signatures protecting against falsely denying some action, other than Key_Cert_sign or CRL_Sign.
Digital_Signature—Verifying digital signatures other than Non_Repudiation, Key_Cert_Sign or CRL_Sign.
Extended Key Usage —Use these Extended Key Usage settings. The OIDs are included in parenthesis:
Custom Extended Match Key (Max 10)—Specifies custom extended match keys, if any (maximum 10). A certificate must match all of the specified key(s) you enter. Enter the key in the OID format (for example, 1.3.6.1.5.5.7.3.11).
If a Custom Extended Match Key is created with the OID size greater than 30 characters, it is unaccepted when you click the OK button. The limit for the maximum characters for an OID is 30.
Match only certificates with Extended key usage —Previous behavior was that if a certificate distinguished name (DN) match rule is set, the client would match certificates with the specific EKU OID and all certificates with no EKU. To keep consistency but provide more clarity, you can disallow the match to certificates with no EKU. The default is to keep the legacy behavior that customers have come to expect. You must click the check box to enable the new behavior and disallow the match.
Distinguished Name (Max 10):—Specifies distinguished names (DNs) for exact match criteria in choosing acceptable client certificates.
Where are the AnyConnect Profiles located?
XML and profile files are stored locally to the users machine. The location varies based on OS.
Update 27.05.2017
Windows 8 and Windows 10 included
9 thoughts on “Where are the AnyConnect Profiles located?”
Thank you for this info. This was the first link I saw for macos.
Update:
Same location for Windows 10 Professional 64bit
%ProgramData%\Cisco\Cisco AnyConnect Secure Mobility Client\Profile
Note that ProgramData folder is hidden by default, so you must go to VIEW in Windows Explorer and opt to see hidden files.
Thanks for the update.
Where are they on an iPhone?
The AnyConnect VPN Client Profile is an XML file downloaded from the secure gateway that specifies client behavior and identifies VPN connections. Each connection entry in the VPN Client Profile specifies a secure gateway that is accessible to this endpoint device as well as other connection attributes, policies and constraints. These connection entries, in addition to the VPN connections configured manually on the device, are available to choose from when initiating a VPN connection.
Step 1 From the AnyConnect home page, tap Diagnostics > Profile.
Step 2 Choose:
Import Profile—to specify the URL of a VPN profile to import.
Delete Profile—to delete the current VPN profile from the device.
Note If you reconnect to the domain, IP address, or Group URL of the same ASA, AnyConnect reloads the VPN profile and re-enforces the security policies.
Show Profile—to show or hide the current VPN profile on your device.
I am sorry, but why is this a video? You could literraly just copy these url’s and paste them here…
JosefJezek / cisco-anyconnect-profile.md
How do you add usernames if you want for each HostEntry?
Is it possible to setup autoconnect for ios device, I mean if selected app started anyconnect vpn should be connect automatically ?
Very useful, thanks!
How do you add usernames if you want for each HostEntry?
add within HostEntry section
<User>username</User>
Footer
© 2023 GitHub, Inc.
You can’t perform that action at this time.
You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session.
Cisco AnyConnect где хранит профили?
Профили хранятся в виде XML файлов в различных директориях, в зависимости от гостевой ОС:
Windows 10
%ProgramData%\Cisco\Cisco AnyConnect Secure Mobility Client\Profile
Windows 8
%ProgramData%\Cisco\Cisco AnyConnect Secure Mobility Client\Profile
Windows 7
%ProgramData%\Cisco\Cisco AnyConnect Secure Mobility Client\Profile
Windows Vista
%ProgramData%\Cisco\Cisco AnyConnect Secure Mobility Client\Profile
Windows XP
%ALLUSERSPROFILE%\Application Data\Cisco\Cisco AnyConnect Secure Mobility Client\Profile