Cisco ASA 5505 User Manual

Page 1515

Advertising
background image

67-89

Cisco ASA 5500 Series Configuration Guide using the CLI

Chapter 67 Configuring Connection Profiles, Group Policies, and Users

Configuring User Attributes

Applying a URL List

You can specify a list of URLs to appear on the home page for a user who has established a clientless
SSL VPN session. First, you must create one or more named lists by entering the url-list command in
global configuration mode. To apply a list of servers and URLs to a particular user of clientless SSL
VPN, enter the url-list command in username webvpn configuration mode.

To remove a list, including a null value created by using the url-list none command, enter the no form
of this command. The no option allows inheritance of a value from the group policy. To prevent
inheriting a url list, enter the url-list none command.

hostname(config-username-webvpn)# url-list {listname displayname url | none}

hostname(config-username-webvpn)# no url-list

The keywords and variables used in this command are as follows:

displayname—Specifies a name for the URL. This name appears on the portal page in the clientless
SSL VPN session.

listname—Identifies a name by which to group URLs.

none—Indicates that there is no list of URLs. Sets a null value, thereby disallowing a URL list.
Prevents inheriting URL list values.

url—Specifies a URL that users of clientless SSL VPN can access.

There is no default URL list.

Using the command a second time overrides the previous setting.

The following example shows how to set a URL list called AnyuserURLs for the user named anyuser:

hostname(config)# username anyuser attributes

hostname(config-username)# webvpn

hostname(config-username-webvpn)# url-list value AnyuserURLs

hostname(config-username-webvpn)#

Enabling ActiveX Relay for a User

ActiveX Relay lets a user who has established a Clientless SSL VPN session use the browser to launch
Microsoft Office applications. The applications use the session to download and upload Microsoft Office
documents. The ActiveX relay remains in force until the Clientless SSL VPN session closes.

To enable or disable ActiveX controls on Clientless SSL VPN sessions, enter the following command in
username webvpn configuration mode:

activex-relay {enable | disable}

To inherit the activex-relay command from the group policy, enter the following command:

no activex-relay

The following commands enable ActiveX controls on Clientless SSL VPN sessions associated with a
given username:

hostname(config-username-policy)# webvpn

hostname(config-username-webvpn)# activex-relay enable

hostname(config-username-webvpn)

Enabling Application Access for Clientless SSL VPN Sessions

To enable application access for this user, enter the port-forward command in username webvpn
configuration mode. Port forwarding is disabled by default.

Advertising