EasyManuals Logo

Cisco 5510 - ASA SSL / IPsec VPN Edition Configuration Guide

Cisco 5510 - ASA SSL / IPsec VPN Edition
1822 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #1507 background imageLoading...
Page #1507 background image
67-43
Cisco ASA 5500 Series Configuration Guide using ASDM
OL-20339-01
Chapter 67 Clientless SSL VPN
Configuring Smart Tunnel Access
Note We strongly recommend the use of the logout button on the portal. This method pertains to clientless
SSL VPNs and logs off regardless of whether smart tunnel is used or not. The notification icon should
be used only when using standalone applications without the browser.
Without Using Notification Icon
If you choose to not use the notification icon, the VPN session closes when the user quits the browser,
and the end user is logged off after all browsers are closed. For example, if you started a smart tunnel
from Internet Explorer, the smart tunnel is turned off when no iexplore.exe is running. Smart tunnel can
determine that the VPN session has ended even if the user closed all browsers without logging out.
Note In some cases, a lingering browser process is unintentional and is strictly a result of an error.
Also, when a Secure Desktop is used, the browser process can run in another desktop even if the
user closed all browsers within the secure desktop. Therefore, smart tunnel declares all browser
instances gone when no more visible windows exist in the current desktop.
Note Portal logout still takes effect and is not impacted.
See the Cisco Security Appliance Command Reference Guide
(http://www.cisco.com/en/US/products/ps6120/prod_command_reference_list.html) for the CLI
command that configures log out properties and controls whether the user is presented with a logout icon
for logging out.
Using the Notification Icon
If you want the user to keep accessing the VPN, even after all browsers are closed, choose the
notification icon for log off. The VPN session will not close, even when the user has quit the browser;
therefore, if a user is accessing some non-browser application (such as vnc), the connectivity remains
even after all browsers are closed, but logout can still occur using the notification icon. Smart Tunnel
may not detect a log off event that happens outside of the browser (such as logging off with the console
CLI).
The clientless portal may take awhile to detect a log off and actually exit the portal, even though the user
is logged off immediately. The icon remains until the next operation that is tunneled by Smart Tunnel
(such as when an application tries to create a new connection).
Note This icon is an alternative way to log out of SSL VPN. It is not an indicator of VPN session
status.
To enable the icon in the notification area, follow these steps:
Step 1 Choose Configuration > Remote Access VPN > Clientless SSL VPN Access > Portal > Smart
Tunnels.
Step 2 Enable the Click on smart-tunnel logoff icon in the system tray radio button.
Step 3 In the Smart Tunnel Networks portion of the window, check Add and enter both the IP address and
hostname of the network which should include the icon.

Table of Contents

Other manuals for Cisco 5510 - ASA SSL / IPsec VPN Edition

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco 5510 - ASA SSL / IPsec VPN Edition and is the answer not in the manual?

Cisco 5510 - ASA SSL / IPsec VPN Edition Specifications

General IconGeneral
BrandCisco
Model5510 - ASA SSL / IPsec VPN Edition
CategoryFirewall
LanguageEnglish

Related product manuals