ASA - AnyConnect Management VPN Tunnel

When configuring an ASA to operate with AnyConnect clients, it is possible to create what is known as a Management VPN Tunnel.

This VPN tunnel ensures connectivity to the corporate network whenever the client is powered up, and not just when a VPN connection is established by the end-user. Below you can see the state of the Management VPN Tunnel on an AnyConnect client. Notice that the state is Connected even though the State under the Connection Information heading is Disconnected.

anyconnect-management-vpn-tunnel.png

This management tunnel allows administrators to have management access to AnyConnect devices without user intervention. This facilitates things like patch management, upgrades, and some endpoint OS login scripts.

Links:

https://forum.networklessons.com/t/cisco-any-connect-management-connection-state-is-connected/23898/2?u=lagapides

https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-appliance-asa-software/215442-configure-anyconnect-management-vpn-tunn.html

https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect47/administration/guide/b_AnyConnect_Administrator_Guide_4-7/b_AnyConnect_Administrator_Guide_4-7_chapter_01100.html#id_83215