Cisco ASA 5505 User Manual

Page 1516

Advertising
background image

67-90

Cisco ASA 5500 Series Configuration Guide using the CLI

Chapter 67 Configuring Connection Profiles, Group Policies, and Users

Configuring User Attributes

To remove the port forwarding attribute from the configuration, including a null value created by issuing
the port-forward none command, enter the no form of this command. The no option allows inheritance
of a list from the group policy. To disallow filtering and prevent inheriting a port forwarding list, enter
the port-forward command with the none keyword.

hostname(config-username-webvpn)# port-forward {value listname | none}

hostname(config-username-webvpn)# no port-forward

hostname(config-username-webvpn)#

The listname string following the keyword value identifies the list of applications users of clientless SSL
VPN can access. Enter the port-forward command in configuration mode to define the list.

Using the command a second time overrides the previous setting.

Before you can enter the port-forward command in username webvpn configuration mode to enable
application access, you must define a list of applications that you want users to be able to use in a
clientless SSL VPN session. Enter the port-forward command in global configuration mode to define
this list.

The following example shows how to configure a portforwarding list called ports1:

hostname(config-group-policy)# webvpn

hostname(config-username-webvpn)# port-forward value ports1

hostname(config-username-webvpn)#

Configuring the Port-Forwarding Display Name

Configure the display name that identifies TCP port forwarding to end users for a particular user by using
the port-forward-name command in username webvpn configuration mode. To delete the display name,
including a null value created by using the port-forward-name none command, enter the no form of
the command. The no option restores the default name, Application Access. To prevent a display name,
enter the port-forward none command.

hostname(config-username-webvpn)# port-forward-name {value name | none}

hostname(config-username-webvpn)# no port-forward-name

The following example shows how to configure the port-forward name test:

hostname(config-group-policy)# webvpn

hostname(config-username-webvpn)# port-forward-name value test

hostname(config-username-webvpn)#

Configuring the Maximum Object Size to Ignore for Updating the Session Timer

Network devices exchange short keepalive messages to ensure that the virtual circuit between them is
still active. The length of these messages can vary. The keep-alive-ignore command lets you tell the
ASA to consider all messages that are less than or equal to the specified size as keepalive messages and
not as traffic when updating the session timer. The range is 0 through 900 KB. The default is 4 KB.

To specify the upper limit of the HTTP/HTTPS traffic, per transaction, to ignore, use the
keep-alive-ignore command in group-policy attributes webvpn configuration mode:

hostname(config-group-webvpn)# keep-alive-ignore size

hostname(config-group-webvpn)#

The no form of the command removes this specification from the configuration:

hostname(config-group-webvpn)# no keep-alive-ignore

hostname(config-group-webvpn)#

The following example sets the maximum size of objects to ignore as 5 KB:

Advertising