Client VPN replacement?

Hi all - what do you use for Client VPN?

Meraki Client VPN is not an acceptable answer for us. We have spent years fighting this and now it’s gotten worse. Our IT team has discovered rebooting our MX100 fixes client VPN issues for a little while. We’ve spent months building, rebuilding, testing, patching, un-patching, our end user computers, but the one thing that apparently always works is rebooting our MX.

We need a solution that doesn’t require us to have a fulltime, salaried apologizer on the IT team.

So, who do you give your money to for client VPN? We have ~100 concurrent users at peak.

Thanks!

AnyConnect with DUO authentication.

We use the Cisco AnyConnect Secure Mobility Client with our Meraki MX.

https://documentation.meraki.com/MX/Client_VPN/AnyConnect_on_the_MX_Appliance

Because we use saml (to get the MFA) we also need a Secure Client Premier (formerly Apex) subscription.

https://documentation.meraki.com/MX/Client_VPN/AnyConnect_on_the_MX_Appliance/AnyConnect_Licensing_on_the_MX

Windows l2tp until OS updates broke it. Now using any connect

AnyConnect with DUO SAML authentication is great

I also use AnyConnect, but I am reluctant to trust it on the Merakis given how new it is and how crap Cisco’s QA has been the past several years.

I currently have a pair of ASAv instances in our Azure cloud for external VPNs and AnyConnect. Site-to-Site VPNs to our locations are ran with VMX instances.

Currently Anyconnect via firepower’s using azure AD SAML migrating to Anyconnect on 5 vmxs mixture of split and full tunnel with azure AD SAML. Also azure premium firepower for the full tunnel breakout

AnyConnect with the latest client. We do saml to 365 with the Apex licensing on a MX100 and have no issues.

Thanks to everyone for their responses. Going to re-evaluate AnyConnect licensing expenses, as well as take a look at some alternatives like zscaler. Also just discovered some github GUI projects for WireGuard, so I’m spinning up an instance to set up WG and tinker a bit.

I’ve been debating about going OpenVPN running on a pfSense install, myself.

good ol community ovpn with 2fa.

AnyConnect with Cisco secure client. Been using it for 2 years. No issues and none of the headaches of client VPN L2TP. Found out some newer firewalls will not pass data on the older protocol

We’re still using Sophos which is based on Open VPN. We kept one (virtual) appliance around when we switched to the MX gateways purely for the client VPN. Yes, we could do it on our own, but the Sophos GUI makes it much easier to manage.

We use Draytek SmartVPN client per this thread and it’s been rock solid for 4+ years.

After 4+ years of having the Windows client have to get resetup at every patch, phase of the moon, or funny look.

We have a few hundred MXes deployed and have never had a problem with the Meraki VPN.

Have you tried RMA and getting a replacement?

This has worked great for us for 3 years. Really easy to get going.

Or better yet (assuming on infra) just anyconnect with Azure AD as the SAML provider. Then you can handle MFA within Azure

It’s not new at all. It has been out of beta for around 2 years. It’s rock solid on our Merakis.

This is what I’m doing. It’s decent, but no vpn connect before login unless you’re doing certificate based VPN auth.

Oh nice, I thought it was much more recent than that. Does it have the same functionality as on ASAs? Can you define multiple profiles, time limits, things like that?