Cisco 5505 Administration Guide - Page 59

Configuring AnyConnect Features Using CLI, Enabling Datagram Transport Layer Security (DTLS) - modulator

Page 59 highlights

6 C H A P T E R Configuring AnyConnect Features Using CLI The AnyConnect client includes the following features, which you configure on the security appliance: • Enabling Datagram Transport Layer Security (DTLS) with AnyConnect (SSL) Connections, page 6-1 • Prompting Remote Users, page 6-2 • Enabling IPv6 VPN Access, page 6-3 • Enabling Modules for Additional AnyConnect Features, page 6-4 • Configuring Certificate-only Authentication, page 6-5 • Using Compression, page 6-5 • Configuring the Dynamic Access Policies Feature of the Security Appliance, page 6-6 • Configuring the Dynamic Access Policies Feature of the Security Appliance, page 6-6 • Cisco Secure Desktop Support, page 6-6 • Enabling AnyConnect Rekey, page 6-6 • Enabling and Adjusting Dead Peer Detection, page 6-7 • Enabling AnyConnect Keepalives, page 6-8 Enabling Datagram Transport Layer Security (DTLS) with AnyConnect (SSL) Connections Datagram Transport Layer Security avoids latency and bandwidth problems associated with some SSL-only connections, including AnyConnect connections, and improves the performance of real-time applications that are sensitive to packet delays. DTLS is a standards-based SSL protocol that provides a low-latency data path using UDP. For detailed information about DTLS, see RFC 4347 (http://www.ietf.org/rfc/rfc4347.txt). Datagram Transport Layer Security (DTLS) allows the AnyConnect client establishing an SSL VPN connection to use two simultaneous tunnels-an SSL tunnel and a DTLS tunnel. Using DTLS avoids latency and bandwidth problems associated with some SSL connections and improves the performance of real-time applications that are sensitive to packet delays. If you do not enable DTLS, SSL VPN connections connect with an SSL VPN tunnel only. OL-12950-012 Cisco AnyConnect VPN Client Administrator Guide 6-1

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118

CHAPTER
6-1
Cisco AnyConnect VPN Client Administrator Guide
OL-12950-012
6
Configuring AnyConnect Features Using CLI
The AnyConnect client includes the following features, which you configure on the security appliance:
Enabling Datagram Transport Layer Security (DTLS) with AnyConnect (SSL) Connections,
page 6-1
Prompting Remote Users, page 6-2
Enabling IPv6 VPN Access, page 6-3
Enabling Modules for Additional AnyConnect Features, page 6-4
Configuring Certificate-only Authentication, page 6-5
Using Compression, page 6-5
Configuring the Dynamic Access Policies Feature of the Security Appliance, page 6-6
Configuring the Dynamic Access Policies Feature of the Security Appliance, page 6-6
Cisco Secure Desktop Support, page 6-6
Enabling AnyConnect Rekey, page 6-6
Enabling and Adjusting Dead Peer Detection, page 6-7
Enabling AnyConnect Keepalives, page 6-8
Enabling Datagram Transport Layer Security (DTLS) with
AnyConnect (SSL) Connections
Datagram Transport Layer Security avoids latency and bandwidth problems associated with some
SSL-only connections, including AnyConnect connections, and improves the performance of real-time
applications that are sensitive to packet delays. DTLS is a standards-based SSL protocol that provides a
low-latency data path using UDP. For detailed information about DTLS, see RFC 4347
Datagram Transport Layer Security (DTLS) allows the AnyConnect client establishing an SSL VPN
connection to use two simultaneous tunnels—an SSL tunnel and a DTLS tunnel. Using DTLS avoids
latency and bandwidth problems associated with some SSL connections and improves the performance
of real-time applications that are sensitive to packet delays.
If you do not enable DTLS, SSL VPN connections connect with an SSL VPN tunnel only.