37-33
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 37 Configuring Clientless SSL VPN
Configuring Application Access
Following the configuration of a port forwarding list, assign the list to group policies or usernames, as
described in the next section.
Assigning a Port Forwarding List
For each group policy and username, you can configure clientless SSL VPN to do one of the following:
•
Start port forwarding access automatically upon user login.
•
Enable port forwarding access upon user login, but require the user to start it manually, using the
Application Access
>
Start Applications
button on the clientless SSL VPN Portal Page.
Note
These options are mutually exclusive for each group policy and username. Use only one.
Table 37-4
lists the
port-forward
commands available to each group policy and username. The
configuration of each group policy and username supports only one of these commands at a time, so
when you enter one, the security appliance replaces the one present in the configuration of the group
policy or username in question with the new one, or in the case of the last command, simply removes the
port-forward
command from the group policy or username configuration.
For details, go to the section that addresses the option you want to use.
Automating Port Forwarding
To start port forwarding automatically upon user login, enter the following command in group-policy
webvpn configuration mode or username webvpn configuration mode:
port-forward auto-start
list_name
list_name
names the port forwarding list already present in the security appliance webvpn configuration.
You cannot assign more than one port forwarding list to a group policy or username. To display the port
forwarding list entries present in the security appliance configuration, enter the
show run webvpn
port-forward
command in privileged EXEC mode.
To remove the
port-forward
command from the group policy or username and inherit the [
no
]
port-forward
command from the default group-policy, use the
no
form of the command.
Table 37-4
group-policy and username webvpn port-forward Commands
Command
Description
port-forward auto-start
list_name
Starts port forwarding automatically upon user login.
port-forward enable
list_name
Enables port forwarding upon user login, but requires the user to
start port forwarding manually, using the
Application Access
>
Start Applications
button on the clientless SSL VPN portal
page.
port-forward disable
Prevents port forwarding.
no port-forward
[
auto-start
list_name
|
enable
list_name |
disable
]
Removes a
port-forward
command from the group policy or
username configuration, which then inherits the
[
no
]
port-forward
command from the default group-policy. The
keywords following the
no port-forward
command are optional,
however, they restrict the removal to the named
port-forward
command.
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......