On Wed, Jun 29, 2016 at 12:10 AM, Yick Xie <yick.xie at gmail.com> wrote: > Hello Nikos, > > As I tested the openconnect client can successfully tell them apart. That also means that in your platform the anyconnect client doesn't set server name indication. You can verify that by capturing traffic and verifying that the first handshake message contains the server name indication TLS extension. regards, Nikos