Cisco Cisco AnyConnect Secure Mobility Client v2.x Technical Manual

Page of 15
Contents
Introduction
Prerequisites
Requirements
Components Used
Background Information
Cisco Anyconnect Secure Mobility Client
Internet Protocol Flow Information Export (IPFIX)
IPFIX Collector
Splunk
Topology
Configure
Anyconnect NVM client profile
Configure NVM client profile via ASDM
Configure NVM client profile via Anyconnect Profile Editor
Configure Web-Deployment on Cisco ASA
Configure Web-Deployment on Cisco ISE
Trusted Network Detection
Deploy
Step 1. Configure Anyconnect NVM on Cisco ASA/ISE
Step 2. Set up IPFIX Collector component
Step 3. Set up Splunk with Cisco NVM App
Verify
Validate Anyconnect NVM installation
Validate Collector status as Running
Validate Splunk
Troubleshoot
Packet Flow
Basic troubleshoot steps
Trusted Network Detection (TND)
Flow Templates
Recommended Release
Related Defects
Related Links
Introduction
This document describes the method to install and configure the Cisco AnyConnect Network
Visibility Module (NVM) on an end-user system using AnyConnect 4.2.x or higher.
The Cisco AnyConnect NVM is used as a medium for deploying security analytics. NVM
empowers organizations to see endpoint & user behavior on their network, collects flows from
endpoints both on and off-premise along with additional context like users, applications, devices,
locations and destinations.