69-10
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter69 General VPN Setup
Group Policies
Renegotiation Method—Uncheck the Inherit check box to specify a renegotiation method different
from the default group policy. Select the None radio button to disable rekey, select either the SSL
or New Tunnel radio button to establish a new tunnel during rekey.
Note Configuring the Renegotiation Method as SSL or New Tunnel specifies that the client
establishes a new tunnel during rekey instead of the SSL renegotiation taking place during
the rekey. See the Cisco ASA 5500 Series Command Reference, 8.4 for a history of the
anyconnect ssl rekey command.
Modes
The following table shows the modes in which this feature is available:
Dead Peer Detection
Dead Peer Detection (DPD) ensures that the security appliance (gateway) or the client can quickly detect
a condition where the peer is not responding, and the connection has failed.
Fields
Gateway Side Detection—Uncheck the Disable check box to specify that DPD is performed by the
security appliance (gateway). Enter the interval, from 30 to 3600 seconds, with which the security
appliance performs DPD.
Client Side Detection—Uncheck the Disable check box to specify that DPD is performed by the
client. Enter the interval, from 30 to 3600 seconds, with which the client performs DPD.
Modes
The following table shows the modes in which this feature is available:
Customization
Fields
Portal Customization—Selects the customization to apply to the AnyConnect Client/SSL VPN
portal page. The default is DfltCustomization.
Manage—Opens the Configure GUI Customization objects dialog box, in which you can specify
that you want to add, edit, delete, import, or export a customization object.
Firewall Mode Security Context
Routed Transparent Single
Multiple
Context System
——
Firewall Mode Security Context
Routed Transparent Single
Multiple
Context System
——