1-46
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring Connection Profiles, Group Policies, and Users
Group Policies
Detailed Steps
Specifying the Tunneling Protocol for the Group Policy
Specify the VPN tunnel type for this group policy by entering the
vpn-tunnel-protocol {ikev1
|
ikev2
|
l2tp-ipsec
|
ssl-client
|
ssl-clientless
} command from group-policy configuration mode.
The default value is to inherit the attributes of the Default Group Policy. To remove the attribute from
the running configuration, enter the
no
form of this command.
The parameter values for this command follow:
Command
Purpose
Step 1
group-policy
value
attributes
Example:
hostname
> en
hostname#
config t
hostname(config)#
group-policy FirstGroup attributes
hostname(config-group-policy)#
Enter group policy configuration mode.
Step 2
ipv6-address-pools value
pool-name1 pool-name2
pool-name6
Example:
hostname(config-group-policy)#
ipv6-address-pools value
ipv6-pool1 ipv6-pool2 ipv6-pool3
hostname(config-group-policy)#
Assigns the address pool named ipv6-pool to the
FirstGroup group policy.
You can assign up to six ipv6 address pools to a
group policy.
This example shows ipv6-pool1, ipv6-pool2, and
ipv6-pool3 being assigned to the FirstGroup group
policy.
Step 3
(Optional)
no ipv6-address-pools value pool-name1 pool-name2
pool-name6
Example:
hostname(config-group-policy)#
no ipv6-address-pools
value ipv6-pool1 ipv6-pool2 ipv6-pool3
hostname(config-group-policy)#
Use the
no ipv6-address-pools value pool-name
command to remove the address-pools from the
goup policy configuration and returns the address
pool setting to inherit the address pool information
from other sources such as the DfltGroupPolicy.
Step 4
(Optional)
ipv6-address-pools none
Example:
hostname(config-group-policy)#
ipv6-address-pools none
hostname(config-group-policy)#
The
ipv6-address-pools none
command disables
this attribute from being inherited from other
sources of policy, such as the DfltGrpPolicy:
Step 5
(Optional)
no ipv6-address-pools none
Example:
hostname(config-group-policy)#
no ipv6-address-pools
none
hostname(config-group-policy)#
The
no ipv6-address pools none
command
removes the
ipv6-address-pools none
command
from the group policy, restoring the default value,
which is to allow inheritance.
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......