Cisco 5505 Administration Guide - Page 66

svc keepalive, svc keepalive {none, Outlook or Microsoft Internet Explorer. - firewall 10 user

Page 66 highlights

Configuring, Enabling, and Using Other AnyConnect Features Chapter 6 Configuring AnyConnect Features Using CLI hostname(config-group-policy)# webvpn hostname(config-group-policy)# svc dpd-interval gateway 30 hostname(config-group-policy)# svc dpd-interval client 10 Enabling AnyConnect Keepalives You can adjust the frequency of keepalive messages to ensure that an AnyConnect client or SSL VPN connection through a proxy, firewall, or NAT device remains open, even if the device limits the time that the connection can be idle. Adjusting the frequency also ensures that the client does not disconnect and reconnect when the remote user is not actively running a socket-based application, such as Microsoft Outlook or Microsoft Internet Explorer. To set the frequency of keepalive messages, use the svc keepalive command from group-policy webvpn or username webvpn configuration mode: [no] svc keepalive {none | seconds} none disables client keepalive messages. seconds enables the client to send keepalive messages, and specifies the frequency of the messages in the range of 15 to 600 seconds. The default is keepalive messages are disabled. Use the no form of the command to remove the command from the configuration and cause the value to be inherited: In the following example, the security appliance is configured to enable the client to send keepalive messages with a frequency of 300 seconds (5 minutes), for the existing group-policy sales: hostname(config)# group-policy sales attributes hostname(config-group-policy)# webvpn hostname(config-group-webvpn)# svc keepalive 300 Cisco AnyConnect VPN Client Administrator Guide 6-8 OL-12950-012

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118

6-8
Cisco AnyConnect VPN Client Administrator Guide
OL-12950-012
Chapter 6
Configuring AnyConnect Features Using CLI
Configuring, Enabling, and Using Other AnyConnect Features
hostname(config-group-policy)#
webvpn
hostname(config-group-policy)#
svc dpd-interval gateway 30
hostname(config-group-policy)#
svc dpd-interval client 10
Enabling AnyConnect Keepalives
You can adjust the frequency of keepalive messages to ensure that an AnyConnect client or SSL VPN
connection through a proxy, firewall, or NAT device remains open, even if the device limits the time that
the connection can be idle. Adjusting the frequency also ensures that the client does not disconnect and
reconnect when the remote user is not actively running a socket-based application, such as Microsoft
Outlook or Microsoft Internet Explorer.
To set the frequency of keepalive messages, use the
svc keepalive
command from group-policy webvpn
or username webvpn configuration mode:
[
no
]
svc keepalive {none |
seconds
}
none
disables client keepalive messages.
seconds
enables the client to send keepalive messages, and specifies the frequency of the messages
in the range of 15 to 600 seconds.
The default is keepalive messages are disabled.
Use the
no
form of the command to remove the command from the configuration and cause the value
to be inherited:
In the following example, the security appliance is configured to enable the client to send keepalive
messages with a frequency of 300 seconds (5 minutes), for the existing group-policy
sales
:
hostname(config)#
group-policy sales attributes
hostname(config-group-policy)#
webvpn
hostname(config-group-webvpn)#
svc keepalive 300