EasyManuals Logo

Cisco 5510 - ASA SSL / IPsec VPN Edition Configuration Guide

Cisco 5510 - ASA SSL / IPsec VPN Edition
1822 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #667 background imageLoading...
Page #667 background image
31-21
Cisco ASA 5500 Series Configuration Guide using ASDM
OL-20339-01
Chapter 31 Configuring AAA Servers and the Local Database
Adding a User Account
By default, the Inherit check box is checked for each option, which means the user account inherits the
settings from the VPN policy. To override each setting, uncheck the Inherit check box, and enter a new
value:
a. Choose a group policy from the list.
b. Specify which tunneling protocols are available for use, or whether the value is inherited from the
group policy. Check the desired Tunneling Protocols check boxes to choose the VPN tunneling
protocols that are available for use. Only the selected protocols are available for use. The choices
are as follows:
–
IPSec provides the most complete architecture for VPN tunnels, and it is perceived as the most
secure protocol. Both LAN-to-LAN (peer-to-peer) connections and client-to-LAN connections
can use IPSec.
–
VPN via SSL/TLS (Clientless SSL VPN) uses a web browser to establish a secure
remote-access tunnel to a VPN Concentrator; requires neither a software nor hardware client.
Clientless SSL VPN can provide easy access to a broad range of enterprise resources, including
corporate websites, web-enabled applications, NT/AD file shares (web-enabled), e-mail, and
other TCP-based applications from almost any computer that can reach HTTPS Internet sites.
–
The SSL VPN Client lets users connect after downloading the Cisco AnyConnect Client
application. Users use a clientless SSL VPN connection to download this application the first
time. Client updates then occur automatically as needed whenever the user connects.
–
L2TP over IPSec allows remote users with VPN clients provided with several common PC and
mobile PC operating systems to establish secure connections over the public IP network to the
adaptive security appliance and private corporate networks.
Note If no protocol is selected, an error message appears.
c. Specify which filter (IPv4 or IPv6) to use, or whether to inherit the value from the group policy.
Filters consist of rules that determine whether to allow or reject tunneled data packets coming
through the adaptive security appliance, based on criteria such as source address, destination
address, and protocol. To configure filters and rules, see the Configuration > VPN > VPN General
> Group Policy pane.
d. Click Manage to display the ACL Manager pane, on which you can add, edit, and delete ACLs and
ACEs.
e. Specify whether to inherit the tunnel group lock or to use the selected tunnel group lock, if any.
Selecting a specific lock restricts users to remote access through this group only. Tunnel Group Lock
restricts users by checking if the group configured in the VPN client is the same as the user’s
assigned group. If it is not, the adaptive security appliance prevents the user from connecting. If the
Inherit check box is not checked, the default value is None.
f. Specify whether to inherit the Store Password on Client System setting from the group. Uncheck the
Inherit check box to activate the Yes and No radio buttons. Click Yes to store the login password on
the client system (potentially a less-secure option). Click No (the default) to require the user to enter
the password with each connection. For maximum security, we recommend that you not do allow
password storage. This parameter has no effect on interactive hardware client authentication or
individual user authentication for a VPN 3002.
Step 3 To change Connection Settings, uncheck the Inherit check box, and enter a new value:
a. If the Inherit check box is not checked, you can select the name of an existing access hours policy,
if any, to apply to this user or create a new access hours policy. The default value is Inherit, or, if the
Inherit check box is not checked, the default value is Unrestricted.

Table of Contents

Other manuals for Cisco 5510 - ASA SSL / IPsec VPN Edition

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco 5510 - ASA SSL / IPsec VPN Edition and is the answer not in the manual?

Cisco 5510 - ASA SSL / IPsec VPN Edition Specifications

General IconGeneral
BrandCisco
Model5510 - ASA SSL / IPsec VPN Edition
CategoryFirewall
LanguageEnglish

Related product manuals