Cisco 5505 Administration Guide - Page 54

Enabling AnyConnect Rekey - 8 4 nat

Page 54 highlights

Configuring, Enabling, and Using Other AnyConnect Features Chapter 5 Configuring AnyConnect Features Using ASDM • Device Management > Users/AAA > User Accounts > Add or Edit > Add or Edit User Account > VPN Policy > SSL VPN Client Figure 5-10 shows an example of configuring the keepalive messages setting for an internal group policy. Figure 5-10 Configuring Keepalive Messages Configure the Keepalive Messages field for this attributeby deselecting Inherit and entering a number, from 15 to 600 seconds, in the Interval field to enable and adjust the interval of keepalive messages to ensure that an connection through a proxy, firewall, or NAT device remains open, even if the device limits the time that the connection can be idle. Adjusting the interval also ensures that the client does not disconnect and reconnect when the remote user is not actively running a socket-based application, such as Microsoft Outlook or Microsoft Internet Explorer. Enabling AnyConnect Rekey Configuring AnyConnect Rekey specifies that SSL renegotiation takes place during rekey. When the security appliance and the SSL VPN client perform a rekey, they renegotiate the crypto keys and initialization vectors, increasing the security of the connection. To enable Rekey, use the Key Regeneration dialog box in either Group Policy or Username. The paths to this setting are: • Configuration > Remote Access VPN > Network (Client) Access > Group Policies > Add or Edit > Add or Edit Internal Group Policy > Advanced > SSL VPN Client > Key Regeneration 5-12 Cisco AnyConnect VPN Client Administrator Guide OL-12950-012

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118

5-12
Cisco AnyConnect VPN Client Administrator Guide
OL-12950-012
Chapter 5
Configuring AnyConnect Features Using ASDM
Configuring, Enabling, and Using Other AnyConnect Features
Device Management > Users/AAA > User Accounts > Add or Edit > Add or Edit User Account >
VPN Policy > SSL VPN Client
Figure 5-10
shows an example of configuring the keepalive messages setting for an internal group policy.
Figure 5-10
Configuring Keepalive Messages
Configure the Keepalive Messages field for this attributeby deselecting Inherit and entering a number,
from 15 to 600 seconds, in the Interval field to enable and adjust the interval of keepalive messages to
ensure that an connection through a proxy, firewall, or NAT device remains open, even if the device
limits the time that the connection can be idle. Adjusting the interval also ensures that the client does not
disconnect and reconnect when the remote user is not actively running a socket-based application, such
as Microsoft Outlook or Microsoft Internet Explorer.
Enabling AnyConnect Rekey
Configuring AnyConnect Rekey specifies that SSL renegotiation takes place during rekey. When the
security appliance and the SSL VPN client perform a rekey, they renegotiate the crypto keys and
initialization vectors, increasing the security of the connection.
To enable Rekey, use the Key Regeneration dialog box in either Group Policy or Username. The paths
to this setting are:
Configuration > Remote Access VPN > Network (Client) Access > Group Policies > Add or Edit >
Add or Edit Internal Group Policy > Advanced > SSL VPN Client > Key Regeneration