1-61
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring Connection Profiles, Group Policies, and Users
Group Policies
The following example shows how to enable browser proxy local-bypass for the group policy named
FirstGroup:
hostname(config)#
group-policy FirstGroup attributes
hostname(config-group-policy)#
msie-proxy local-bypass enable
hostname(config-group-policy)#
Configuring Group Policy Attributes for AnyConnect Secure Mobility
Client Connections
After enabling AnyConnect client connections as described in
Chapter 78, “Configuring AnyConnect
VPN Client Connections”
, you can enable or require AnyConnect features for a group policy. Follow
these steps in group-policy webvpn configuration mode:
Step 1
Enter group policy webvpn configuration mode. For example:
hostname(config)#
group-policy sales attributes
hostname(config-group-policy)#
webvpn
Step 2
To disable the permanent installation of the AnyConnect client on the endpoint computer, use the
anyconnect keep-installer
command with the
none
keyword. For example:
hostname(config-group-webvpn)#
anyconnect keep-installer
none
hostname(config-group-webvpn)#
The default is that permanent installation of the client is enabled. The client remains installed on the
endpoint at the end of the AnyConnect session.
Step 3
To enable compression of HTTP data over an AnyConnect SSL connection for the group policy, enter
the
anyconnect ssl compression
command. By default, compression is set to
none
(disabled). To enable
compression, use the
deflate
keyword. For example:
hostname(config-group-webvpn)#
anyconnect compression deflate
hostname(config-group-webvpn)#
Step 4
To enable dead peer detection (DPD) on the ASA and to set the frequency with which either the
AnyConnect client or the ASA performs DPD, use the
anyconnect dpd-interval
command:
anyconnect dpd-interval
{[
gateway
{
seconds
|
none
}] | [
client
{
seconds
|
none
}]}
By default, both the ASA and the AnyConnect client perform DPD every 30 seconds.
The gateway refers to the ASA. You can specify the frequency with which the ASA performs the DPD
test as a range of from 30 to 3600 seconds (1 hour). Specifying
none
disables the DPD testing that the
ASA performs. A value of 300 is recommended.
The client refers to the AnyConnect client. You can specify the frequency with which the client performs
the DPD test as a range of from 30 to 3600 seconds (1 hour). Specifying
none
disables the DPD testing
that the client performs. A value of 30 is recommended.
The following example configures the DPD frequency performed by the ASA (gateway) to 300 seconds,
and the DPD frequency performed by the client to 30 seconds:
hostname(config-group-webvpn)#
anyconnect dpd-interval gateway 300
hostname(config-group-webvpn)#
anyconnect dpd-interval client 30
hostname(config-group-webvpn)#
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......