30-79
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 30 Configuring Connection Profiles, Group Policies, and Users
Configuring User Attributes
hostname(config)#
username anyuser attributes
hostname(config-username)#
password-storage enable
hostname(config-username)
Configuring Clientless SSL VPN Access for Specific Users
The following sections describe how to customize a configuration for specific users of clientless SSL
VPN sessions. Enter username webvpn
configuration
mode by using the
webvpn
command in username
configuration mode. Clientless SSL VPN lets users establish a secure, remote-access VPN tunnel to the
security appliance using a web browser. There is no need for either a software or hardware client.
Clientless SSL VPN provides easy access to a broad range of web resources and web-enabled
applications from almost any computer that can reach HTTPS Internet sites. Clientless SSL VPN uses
SSL and its successor, TLS1, to provide a secure connection between remote users and specific,
supported internal resources that you configure at a central site. The security appliance recognizes
connections that need to be proxied, and the HTTP server interacts with the authentication subsystem to
authenticate users.
The username webvpn configuration mode
commands define access to files, URLs and TCP applications
over clientless SSL VPN sessions. They also identify ACLs and types of traffic to filter. Clientless SSL
VPN is disabled by default. These
webvpn
commands apply only to the username from which you
configure them. Notice that the prompt changes, indicating that you are now in username webvpn
configuration mode.
hostname(config-username)#
webvpn
hostname(config-username-webvpn)#
To remove all commands entered in username webvpn configuration mode, use the
no
form of this
command:
hostname(config-username)#
no webvpn
hostname(config-username)#
You do not need to configure clientless SSL VPN to use e-mail proxies.
The security appliance does not support the Microsoft Outlook Exchange (MAPI) proxy. Neither port
forwarding nor the smart tunnel feature that provides application access through a clientless SSL VPN
session supports MAPI. For Microsoft Outlook Exchange communication using the MAPI protocol,
remote users must use AnyConnect.
Note
The webvpn mode that you enter from global configuration mode lets you configure global settings for
clientless SSL VPN sessions. The username webvpn configuration mode described in this section, which
you enter from username mode, lets you customize the configuration of specific users specifically for
clientless SSL VPN sessions.
In username webvpn configuration mode, you can customize the following parameters, each of which is
described in the subsequent steps:
•
customizations
•
deny message
•
html-content-filter
•
homepage
•
filter
•
url-list
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......