The Virtual Private Network (VPN) client software is required for access to Carleton University resources that are restricted to on-campus use.  It provides a secure encrypted channel from your home to the campus and allows access to many campus resources.

Staff/Faculty if you already have the Cisco VPN software installed you do not need to re-install, you just need to update the connection server, click here for the steps to update the connection server to

ITS Imaged Staff PC’s on the CUNET Domain

You can install the Cisco client using the ‘Software Center’ on ITS imaged PC’s that are members of the CUNET domain without the need for administrative rights.

  1.  Type ‘software center’ in the search tool on the task bar of your computer, click to open the Software Center.
  2.  On the ‘Applications’ menu on the left hand side, you will see the ‘Cisco AnyConnect’, click on it and choose ‘Install’
    This must be done while the computer in on campus

Windows 10/11

    1. Go to: and login with your MC1 Username and Password.
    2. On the following page, click “Continue”.


  1. Press “Download for Windows”
  2. Depending on your browser:
    1. In Google Chrome, open the downloaded .exe file;
    2. In Microsoft Edge, click “Run” in the message bar at the bottom of the page; and
    3. In Mozilla Firefox, select “Save File” in the pop-up window. Click on the blue Downloads arrow in the top bar of the browser, and click on the downloaded file
  3. Follow the prompts to run the Cisco Anyconnect Security Mobility Client Setup.
    If a security message appears, click “Yes” to allow the software to be installed.

Using the Cisco AnyConnect Security Mobility Client

Beginning in November 2022, multifactor authentication (MFA) is required when using the Cisco AnyConnect Security Mobility Client. To use the VPN Service with MFA, begin by using the “Start Menu” item to launch the Cisco AnyConnect Security Mobility Client window.

  • In the dropdown menu type:


CarletonU-RemoteVPN or

  • and click Connect.

  • You will be prompted for a Username, Password and Second Password

  • Enter your MyCarletonOne (MC1) account (do not include & password.
  • The Second Password asks for the Duo second factor that you would like to use. You have two options:
    1. Recommended method for first-time users of the VPN with MFA: Enter a passcode (6-digit pin) from the Duo mobile application on your phone. To do this, open the Duo app on your phone and follow these instructions. You can also use a hardware token associated with your Duo account, or a bypass code created by the Service Desk. OR
    2. Enter the word push to have Duo push an authentication prompt to your default mobile application, or the word phone to receive a phone call to your default phone number. Accept the prompt to proceed.
  • The first time you connect to the VPN service using Duo MFA, the Cisco AnyConnect VPN client will download an updated profile, which will include a longer timeout value when using the push or phone methods. We recommend that you use a passcode the first time you use this configuration.
  • Once you’ve completed all fields, click OK.
  • You will be presented with the policy and privacy acknowledgement to accept before establishing the connection. Once connected you should have access to all the same resources allowed to you. Click Accept to proceed.

  • After you connect using Duo MFA, when you next launch the Cisco AnyConnect VPN client you should see an alternate profile available. Please use CarletonU-RA-Duo, CarletonU-RemoteVPN-Duo, or other Duo enabled profile that has been assigned to you when connecting to the VPN service in the future.

Please contact the ITS Service Desk if you would like any assistance.