I would love AnyConnect to be bought to MX as well. Mostly because AnyConnect works so well.
I would prefer something that supports both tcp and udp on port 443, like AnyConnect. This combination means it will work in a wide variety of scenarios, while still giving great performance (if udp 443 works in particular).
Second choice it would use IKEv2. IKEv2 seems to be more robust than IKEv1, and in particular L2TP+IKEv1.
Also I really really want the ability to assign group policies to VPN users. I would especially like the Filter-Id RADIUS attribute to be supported so I can dynamically assign the policies.