1-11
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring AnyConnect VPN Client Connections
Configuring AnyConnect Connections
•
Enabling IPv6 VPN Access, page 1-23
Configuring the ASA to Web-Deploy the Client
The section describes the steps to configure the ASA to web-deploy the AnyConnect client.
Prerequisites
Copy the client image package to the ASA using TFTP or another method.
Detailed Steps
Command
Purpose
Step 1
anyconnect image
filename order
Example:
hostname(config-webvpn)#
anyconnect
image
anyconnect-win-2.3.0254-k9.pkg 1
hostname(config-webvpn)#
anyconnect
image
anyconnect-macosx-i386-2.3.0254-k9.pkg 2
hostname(config-webvpn)#
anyconnect
image
anyconnect-linux-2.3.0254-k9.pkg 3
Identifies a file on flash as an AnyConnect client package file.
The ASA expands the file in cache memory for downloading to
remote PCs. If you have multiple clients, assign an order to the
client images with the order argument.
The ASA downloads portions of each client in the order you
specify until it matches the operating system of the remote PC.
Therefore, assign the lowest number to the image used by the
most commonly-encountered operating system.
Note
You must issue the
anyconnect enable
command after
configuring the AnyConnect images with the
anyconnect
image xyz
command. If you do not enable the
anyconnect
enable
command, AnyConnect will not operate as
expected, and
show webvpn anyconnect
considers the
SSL VPN client as not enabled rather than listing the
installed AnyConnect packages.
Step 2
enable
interface
Example:
hostname(config)#
webvpn
hostname(config-webvpn)#
enable
outside
Enables SSL on an interface for clientless or AnyConnect SSL
connections.
Step 3
anyconnect enable
Without issuing this command, AnyConnect does not function as
expected, and a
show webvpn anyconnect
command returns that
the “SSL VPN is not enabled,” instead of listing the installed
AnyConnect packages.
Step 4
ip local pool
poolname
startaddr-endaddr
mask
mask
Example:
hostname(config)#
ip local pool
vpn_users
209.165.200.225-209.165.200.254
mask 255.255.255.224
(Optional) Creates an address pool. You can use another method
of address assignment, such as DHCP and/or user-assigned
addressing.
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......