Cisco 5505 Administration Guide - Page 42

Disabling Permanent Client Installation - specification

Page 42 highlights

Disabling Permanent Client Installation Chapter 4 Installing the AnyConnect Client on a Security Appliance Using CLI To specify SSL as a permitted tunneling protocol, first exit to global configuration mode, enter the group-policy name attributes command to enter group-policy mode, or the username name attributes command to enter username mode, and then enter the webvpn command to enter webvpn mode and change the WebVPN settings for the group or user. The following example identifies SSL as the only permitted tunneling protocol for the group-policy sales: hostname(config)# group-policy sales attributes hostname(config-group-policy)# webvpn hostname(config-group-webvpn)# vpn-tunnel-protocol svc For more information about assigning users to group policies, see "Configuring Tunnel Groups, Group Policies, and Users" in Cisco Security Appliance Command Line Configuration Guide. Disabling Permanent Client Installation Disabling permanent AnyConnect client installation enables the automatic uninstalling feature of the client. The client on the remote computer uninstalls at the end of every session. To disable permanent AnyConnect client installation for a specific group or user, use the svc keep-installer command from group-policy or username webvpn modes: svc keep-installer none The default is that permanent installation of the client is enabled. The client on the remote computer remains installed on the remote computer at the end of every session, reducing the connection time for subsequent connections. The following example configures the existing group-policy sales to not keep the client installed on the remote computer when the session terminates: hostname(config)# group-policy sales attributes hostname(config-group-policy)# webvpn hostname(config-group-policy)# svc keep-installer none Cisco AnyConnect VPN Client Administrator Guide 4-4 OL-12950-012

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118

4-4
Cisco AnyConnect VPN Client Administrator Guide
OL-12950-012
Chapter 4
Installing the AnyConnect Client on a Security Appliance Using CLI
Disabling Permanent Client Installation
To specify SSL as a permitted tunneling protocol, first exit to global configuration mode, enter the
group-policy
name
attributes
command to enter group-policy mode, or the
username
name
attributes
command to enter username mode, and then enter the
webvpn
command to enter webvpn mode and
change the WebVPN settings for the group or user.
The following example identifies SSL as the only permitted tunneling protocol for the group-policy
sales
:
hostname(config)#
group-policy sales attributes
hostname(config-group-policy)#
webvpn
hostname(config-group-webvpn)#
vpn-tunnel-protocol svc
For more information about assigning users to group policies, see “Configuring Tunnel Groups, Group
Policies, and Users” in
Cisco Security Appliance Command Line Configuration Guide
.
Disabling Permanent Client Installation
Disabling permanent AnyConnect client installation enables the automatic uninstalling feature of the
client. The client on the remote computer uninstalls at the end of every session.
To disable permanent AnyConnect client installation for a specific group or user, use the
svc keep-installer
command from group-policy or username webvpn modes:
svc keep-installer
none
The default is that permanent installation of the client is enabled. The client on the remote computer
remains installed on the remote computer at the end of every session, reducing the connection time for
subsequent connections. The following example configures the existing group-policy
sales
to
not
keep
the client installed on the remote computer when the session terminates:
hostname(config)#
group-policy sales attributes
hostname(config-group-policy)#
webvpn
hostname(config-group-policy)#
svc keep-installer none