Cisco 5505 Administration Guide - Page 53

Enabling AnyConnect Keepalives - nat

Page 53 highlights

Chapter 5 Configuring AnyConnect Features Using ASDM Figure 5-9 Compression Setting Configuring, Enabling, and Using Other AnyConnect Features By default, for groups and users, SSL compression is set to Inherit. If you deselect Inherit, the default is enabled (equivalent to deflate in the CLI). Note For compression to work, it must be enabled both globally (by the compression svc command configured from global configuration mode) and for the specific group policy or username. If either is set to disable (or to the none or the no form of the command), compression is disabled. Enabling AnyConnect Keepalives You can adjust the frequency of keepalive messages to ensure that an AnyConnect client or SSL VPN connection through a proxy, firewall, or NAT device remains open, even if the device limits the time that the connection can be idle. Adjusting the frequency also ensures that the client does not disconnect and reconnect when the remote user is not actively running a socket-based application, such as Microsoft Outlook or Microsoft Internet Explorer. To set the frequency of keepalive messages, use the Keepalive Messages setting in either Group Policy or Username. The paths to this setting are: • Configuration > Remote Access VPN > Network (Client) Access > Group Policies > Add or Edit > Add or Edit Internal Group Policy > Advanced > SSL VPN Client • Configuration > Remote Access VPN > Network (Client) Access > AAA Setup > Local Users > Add or Edit > Add or Edit User Account > VPN Policy > SSL VPN Client OL-12950-012 Cisco AnyConnect VPN Client Administrator Guide 5-11

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118

5-11
Cisco AnyConnect VPN Client Administrator Guide
OL-12950-012
Chapter 5
Configuring AnyConnect Features Using ASDM
Configuring, Enabling, and Using Other AnyConnect Features
Figure 5-9
Compression Setting
By default, for groups and users, SSL compression is set to Inherit. If you deselect Inherit, the default is
enabled (equivalent to
deflate
in the CLI).
Note
For compression to work, it must be enabled both globally (by the
compression svc
command
configured from global configuration mode) and for the specific group policy or username. If
either
is set to disable (or to the
none
or the
no
form of the command), compression is disabled.
Enabling AnyConnect Keepalives
You can adjust the frequency of keepalive messages to ensure that an AnyConnect client or SSL VPN
connection through a proxy, firewall, or NAT device remains open, even if the device limits the time that
the connection can be idle. Adjusting the frequency also ensures that the client does not disconnect and
reconnect when the remote user is not actively running a socket-based application, such as Microsoft
Outlook or Microsoft Internet Explorer.
To set the frequency of keepalive messages, use the Keepalive Messages
setting in either Group Policy
or Username. The paths to this setting are:
Configuration > Remote Access VPN > Network (Client) Access > Group Policies > Add or Edit >
Add or Edit Internal Group Policy > Advanced > SSL VPN Client
Configuration > Remote Access VPN > Network (Client) Access > AAA Setup > Local Users > Add
or Edit > Add or Edit User Account > VPN Policy > SSL VPN Client