Cisco ASA Series Cli Configuration Manual page 1719

Software version 9.0 for the services module
Hide thumbs Also See for ASA Series:
Table of Contents

Advertisement

Chapter 1
Configuring Connection Profiles, Group Policies, and Users
Supporting a Zone Labs Integrity Server
The following example, entered in group-policy webvpn configuration mode, configures auto-signon for
the user named anyuser, using basic authentication, to servers with IP addresses ranging from 10.1.1.0
to 10.1.1.255:
The following example commands configure auto-signon for users of clientless SSL VPN sessions,
using either basic or NTLM authentication, to servers defined by the URI mask https://*.example.com/*:
hostname(config)# group-policy ExamplePolicy attributes
hostname(config-group-policy)# webvpn
hostname(config-group-webvpn)# auto-signon allow uri https://*.example.com/* auth-type all
hostname(config-group-webvpn)#
The following example commands configure auto-signon for users of clientless SSL VPN sessions,
using either basic or NTLM authentication, to the server with the IP address 10.1.1.0, using subnet mask
255.255.255.0:
hostname(config)# group-policy ExamplePolicy attributes
hostname(config-group-policy)# webvpn
hostname(config-group-webvpn)# auto-signon allow ip 10.1.1.0 255.255.255.0 auth-type all
hostname(config-group-webvpn)#
Specifying the Access List for Clientless SSL VPN Sessions
Specify the name of the access list to use for clientless SSL VPN sessions for this group policy or
username by using the filter command in webvpn mode. Clientless SSL VPN access lists do not apply
until you enter the filter command to specify them.
To remove the access list, including a null value created by issuing the filter none command, enter the
no form of this command. The no option allows inheritance of a value from another group policy. To
prevent inheriting filter values, enter the filter value none command.
Access lists for clientless SSL VPN sessions do not apply until you enter the filter command to specify
them.
You configure ACLs to permit or deny various types of traffic for this group policy. You then enter the
filter command to apply those ACLs for clientless SSL VPN traffic.
ACLname
hostname(config-group-webvpn)# filter {value
| none}
hostname(config-group-webvpn)# no filter
The none keyword indicates that there is no webvpntype access list. It sets a null value, thereby
disallowing an access list and prevents inheriting an access list from another group policy.
The ACLname string following the keyword value provides the name of the previously configured access
list.
Note
Clientless SSL VPN sessions do not use ACLs defined in the vpn-filter command.
The following example shows how to set a filter that invokes an access list named acl_in for the group
policy named FirstGroup:
hostname(config)# group-policy FirstGroup attributes
hostname(config-group-policy)# webvpn
hostname(config-group-webvpn)# filter acl_in
hostname(config-group-webvpn)#
Cisco ASA Series CLI Configuration Guide
1-85

Advertisement

Table of Contents
loading

Table of Contents