1-22
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring AnyConnect VPN Client Connections
Configuring AnyConnect Connections
[no] anyconnect ssl keepalive {none |
seconds
}
none
disables client keepalive messages.
seconds
enables the client to send keepalive messages, and specifies the frequency of the messages in
the range of 15 to 600 seconds.
The default is keepalive messages are enabled.
Use the
no
form of the command to remove the command from the configuration and cause the value to
be inherited:
In the following example, the ASA is configured to enable the client to send keepalive messages with a
frequency of 300 seconds (5 minutes), for the existing group-policy
sales
:
hostname(config)#
group-policy sales attributes
hostname(config-group-policy)#
webvpn
hostname(config-group-webvpn)#
anyconnect ssl keepalive 300
Using Compression
Compression increases the communications performance between the ASA and the client by reducing
the size of the packets being transferred for low-bandwidth connections. By default, compression for all
SSL VPN connections is enabled on the ASA, both at the global level and for specific groups or users.
Note
When implementing compression on broadband connections, you must carefully consider the fact that
compression relies on loss-less connectivity. This is the main reason that it is not enabled by default on
broadband connections.
Compression must be turned-on globally using the
anyconnect ssl compression
command from global
configuration mode, and then it can be set for specific groups or users with the
anyconnect ssl
compression
command in group-policy and username webvpn modes.
Changing Compression Globally
To change the global compression settings, use the
anyconnect ssl compression
command from global
configuration mode:
compression
no
compression
To remove the command from the configuration, use the
no
form of the command.
In the following example, compression is disabled for all SSL VPN connections globally:
hostname(config)#
no
compression
Changing Compression for Groups and Users
To change compression for a specific group or user, use the
anyconnect ssl compression
command in
the group-policy and username webvpn modes:
anyconnect ssl compression
{
deflate
|
none
}
no anyconnect ssl compression
{
deflate
|
none
}
By default, for groups and users, SSL compression is set to
deflate
(enabled).
To remove the
anyconnect ssl compression
command from the configuration and cause the value to be
inherited from the global setting, use the
no
form of the command:
In the following example, compression is disabled for the group-policy sales:
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......