/mcpNote To use the phone with both certificate and password authentication, create a user with the phone MAC address. Username matching is case sensitive. For example: username CP-7975G-SEP001AE2BC16CB password k1kLGQIoxyCO4ti9 encrypted Complete ASA Prerequisites for AnyConnect Use this procedure to complete ASA Prerequisites for AnyConnect. Procedure Step 1 Install ASA software (version 8.0.4 or later) and a compatible ASDM. Step 2 Install a compatible AnyConnect package. Step 3 Activate License. a) Check features of the current license using the following command: show activation-key detail b) If necessary, obtain a new license with additional SSL VPN sessions and enable the Linksys phone. Step 4 Make sure that you configure a tunnel-group with a non-default URL as follows: tunnel-group phonevpn type remote-access tunnel-group phonevpn general-attribute address-pool vpnpool tunnel-group phonevpn webvpn-attributes group-url https://172.18.254.172/phonevpn enable Consider the following when configuring non-default URL: • If the IP address of the ASA has a public DNS entry, you can replace it with a Fully Qualified Domain Name (FQDN). • You can only use a single URL (FQDN or IP address) on the VPN gateway in Unified Communications Manager. • It is preferred to have the certificate CN or subject alternate name match the FQDN or IP address in the group-url. • If the ASA certificate CN or SAN does not match with the FQDN or IP address, uncheck the host ID check box in the Unified Communications Manager. Configure ASA for VPN Client on IP Phone Use this procedure to configure ASA for VPN Client on IP Phone. Feature Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs 89 Remote Network Access Complete ASA Prerequisites for AnyConnect