The Virtual Private Network (VPN) client software is required for access to Carleton University resources that are restricted to on-campus use.  It provides a secure encrypted channel from your home to the campus and allows access to many campus resources.

Staff/Faculty if you already have the Cisco VPN software installed you do not need to re-install, you just need to update the connection server, click here for the steps to update the connection server to

Mac OS

  1. Go to: and login with your MC1 Username and Password.
  2. On the following page, click “Continue”.

  3. Click on the “Download for macOS” button.
  4. Open the Cisco AnyConnect file you just downloaded, and it will present the .dmg package:
  5. The Install AnyConnect Security Client window will appear, click on Continue and accept the
    License agreement.
    In some circumstances depending on your computer system configuration, automatic installation may fail and you will be prompted to manually download installer package. Click “AnyConnect VPN” to continue.

    1. Depending on your browser:
      1. In Google Chrome, open the downloaded .exe file;
      2. In Microsoft Edge, click “Run” in the message bar at the bottom of the page; and
      3. In Mozilla Firefox, select “Save File” in the pop-up window. Click on the blue Downloads arrow in the top bar of the browser, and click on the downloaded file.
  6. Follow the prompts to run the Cisco Anyconnect Security Mobility Client Setup.
  7. In many Mac computers, security settings will prompt you to approve the Cisco Anyconnect Extension
    Open the System Preferences and, following the usual processes, click the Allow button.
  8. Returning to the install screens click through until you reach this message:

Using the Cisco AnyConnect Security Mobility Client

Beginning in November 2022, multifactor authentication (MFA) is required when using the Cisco AnyConnect Security Mobility Client. To use the VPN Service with MFA, you can launch the Cisco AnyConnect Security Mobility Client window in whichever way you choose to launch applications on your Mac.

Next, take the following steps,In the dropdown menu type:

  • Staff
  • Student
    CarletonU-RemoteVPN or

and click Connect.

  • You will be prompted for a Username, Password and Second Password

  • In the Username field, enter your MyCarletonOne (MC1) account (do not include In the Password field, enter your MC1 password.
  • The Second Password or DUO Passcode asks for the Duo second factor that you would like to use. You have two options:
    1. Recommended method for first-time users of the VPN with MFA: Enter a passcode (6-digit pin) from the Duo mobile application on your phone. To do this, open the Duo app on your phone and follow these instructions. You can also use a hardware token associated with your Duo account, or a bypass code created by the Service Desk. OR
    2. Enter the word push to have Duo push an authentication prompt to your default mobile application, or the word phone to receive a phone call to your default phone number. Accept the prompt to proceed.
  • The first time you connect to the VPN service using Duo MFA, the Cisco AnyConnect VPN client will download an updated profile, which will include a longer timeout value when using the push or phone methods. We recommend that you use a passcode the first time you use this configuration.
  • Once you’ve completed all fields, click OK.
  • You will be presented with the policy and privacy acknowledgement to accept before establishing the connection. Once connected you should have access to all the same resources allowed to you. Click Accept to proceed.

  • After you connect using Duo MFA, when you next launch the Cisco AnyConnect VPN client you should see an alternate profile available. Please use CarletonU-RA-Duo, CarletonU-RemoteVPN-Duo, or other Duo enabled profile that has been assigned to you when connecting to the VPN service in the future.

Please contact the ITS Service Desk if you would like any assistance.