EXTERNAL VPN MAC OS
ANYCONNECT CLIENT GUIDE
V ERSION 0.3
Document Information:
Prepared by: Piotr Witkowski [piotr.witkowski@harman.com] Prepare Date: 04.05.2020
Reviewed by: Review Date:
Version History:
Ver. Ver. Date. Revised by Description Filename
No. dd/mm/yyyy
0.1 04.05.2020 Piotr Witkowski Initial draft External_VPN_MACOS_client_guide
0.2 04.11.2020 Piotr Witkowski Added Cisco DUO External_VPN_MACOS_client_guide
0.3 21.08.2021 Piotr Witkowski Minor fixes External_VPN_MACOS_client_guide
Page 2 / 8 Version 0.3 Public
HARMAN
Table of Contents:
1. Purpose of document............................................................................................................4
1. AnyConnect External VPN service.........................................................................................4
2. Supported systems................................................................................................................4
3. How to read this document...................................................................................................4
4. Prerequisites.........................................................................................................................4
5. Installation...........................................................................................................................4
6. Establish VPN connection to Harman....................................................................................6
7. Cisco DUO MFA application..................................................................................................8
Public Version 0.3 3/8
HARMAN
1. Purpose of document
Purpose of this document is to provide instruction for external contractors / consultants how to install
AnyConnect VPN application on MAC OS based systems.
1. AnyConnect External VPN service
Cisco AnyConnect External VPN service is method of accessing Harman resources while being
connected to untrusted network. Untrusted network means any IP enabled network which is not under
Harman authority for instance: customer network, home broadband network, 3G/4G/5G mobile network,
free Wi-Fi network at airport or any other public places.
IP network MUST provide access to Internet on port 443 for both TCP and UDP (DTLS) protocols. Port
UDP/443 is not mandatory but assure the best performance and quality.
2. Supported systems
AnyConnect for MAC OS requirements: MAC OS X ver. 10.8 and onwards.
3. How to read this document
Enabling External Cisco AnyConnect on MAC OS is relatively simple process. Therefore, go through all
below points. Don’t miss anything!
4. Prerequisites
Before you install and connect first time you need to follow below prerequisites points
You should receive account (Login/Pass) credentials from your Harman contact person
You should have provisioned Harman Multi Factor Authentication MFA app on your mobile device.
Ask Harman contact person for help if you haven’t received any.
You should receive e-mail from Harman contact person which contains URL links for AnyConnect
binaries for specific platform. Download all related files – binary and profile.
5. Installation
You should have downloaded AnyConnect package “dmg” file. Double click on “AnyConnect”
package. Installation process starts.
Page 4 / 8 Version 0.3 Public
HARMAN
Again, double click on “AnyConnect” package. Installation process starts.
Accept End Users license by clicking “Agree”.
Once installation finish, you should receive appropriate note.
6. Unzip previously downloaded profile file vpn-external.7z
7. Copy extracted XML profile vpn-external.xml to /opt/cisco/anyconnect/profile
8. Open “AnyConnect” app.
Public Version 0.3 5/8
HARMAN
6. Establish VPN connection to Harman
Decide to which gateway you wish to connect.
Harman recommends connecting to the gateway which is the closest to destination server or
application which you want to connect. For example, if you are based in Europe and want to
connect to server / application which is hosted in Harman US region. It’s better to connect “Harman
Chicago”.
In some cases, it’s better to connect to the closest gateway of your physical location. For example,
users in China may prefer to connect via “Harman – Shenzhen” gateway.
Click connect to establish VPN connection
Provide credentials
Username: Login-name provided by Harman
Password: Password provided by Harman
Second Password: 6-digit code generated by your Multi Factor authentication app installed on
device (mobile).
Second Password [push] – Instead of typing 6-digit code which may not always be convenient,
there is an option to type “push” string. Immediately on mobile device push message appears from
DUO app. Just click “Approve” to get connected.
Page 6 / 8 Version 0.3 Public
HARMAN
Secured Padlock means VPN connection has been successfully established.
User may disconnect anytime by clicking “disconnect” button under AnyConnect app.
Public Version 0.3 7/8
HARMAN
7. Cisco DUO MFA application
Cisco DUO is MFA (multi-factor-authentication) app which provides second authentication method
DUO can be provisioned via self-service portal https://mfaselfservice.harman.com/
After DUO is activated it should look like below
Hide button
refresh
Important note: The same code cannot be used twice. In order to get new code, you must:
o Click “refresh” button
o Click “hide” button (new code is then generated every 15sec)
o Close / Open app (app must be completely closed on the system)
Instead of typing 6-digit code, there is possible to type “push” string as secondary password. Push
message will be sent immediately to mobile in order to “approve”. After its approved VPN
connection will be established.
Page 8 / 8 Version 0.3 Public
HARMAN