1-87
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring Connection Profiles, Group Policies, and Users
Supporting a Zone Labs Integrity Server
Enabling Application Access on Clientless SSL VPN Sessions for a Group Policy
To enable application access for this group policy, enter the port-forward command in group-policy
webvpn configuration mode. Port forwarding is disabled by default.
Before you can enter the port-forward command in group-policy webvpn configuration mode to enable
application access, you must define a list of applications that you want users to be able to use in a
clientless SSL VPN session. Enter the port-forward command in global configuration mode to define
this list.
To remove the port forwarding attribute from the group-policy configuration, including a null value
created by issuing the port-forward none command, enter the no form of this command. The no option
allows inheritance of a list from another group policy. To prevent inheriting a port forwarding list, enter
the port-forward command with the none keyword. The none keyword indicates that there is no
filtering. It sets a null value, thereby disallowing a filtering, and prevents inheriting filtering values.
The syntax of the command is as follows:
hostname(config-group-webvpn)# port-forward {value listname | none}
hostname(config-group-webvpn)# no port-forward
The listname string following the keyword value identifies the list of applications users of clientless SSL
VPN sessions can access. Enter the port-forward command in webvpn configuration mode to define the
list.
Using the command a second time overrides the previous setting.
The following example shows how to set a port-forwarding list called ports1 for the internal group policy
named FirstGroup:
hostname(config)# group-policy FirstGroup internal attributes
hostname(config-group-policy)# webvpn
hostname(config-group-webvpn)# port-forward value ports1
hostname(config-group-webvpn)#
Configuring the Port-Forwarding Display Name
Configure the display name that identifies TCP port forwarding to end users for a particular user or group
policy by using the port-forward-name command in group-policy webvpn configuration mode. To
delete the display name, including a null value created by using the port-forward-name none command,
enter the no form of the command. The no option restores the default name, Application Access. To
prevent a display name, enter the port-forward none command. The syntax of the command is as
follows:
hostname(config-group-webvpn)# port-forward-name {value name | none}
hostname(config-group-webvpn)# no port-forward-name
The following example shows how to set the name, Remote Access TCP Applications, for the internal
group policy named FirstGroup:
hostname(config)# group-policy FirstGroup internal attributes
hostname(config-group-policy)# webvpn
hostname(config-group-webvpn)# port-forward-name value Remote Access TCP Applications
hostname(config-group-webvpn)#
Configuring the Maximum Object Size to Ignore for Updating the Session Timer
Network devices exchange short keepalive messages to ensure that the virtual circuit between them is
still active. The length of these messages can vary. The keep-alive-ignore command lets you tell the
ASA to consider all messages that are less than or equal to the specified size as keepalive messages and
not as traffic when updating the session timer. The range is 0 through 900 KB. The default is 4 KB.