69-71
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter69 General VPN Setup
Configuring Clientless SSL VPN Connections
Modes
The following table shows the modes in which this feature is available:
Add or Edit SSL VPN Connections > Advanced > Authorization
This dialog box lets you configure the default authorization server group, interface-specific
authorization server groups, and user name mapping attributes. The attributes are the same for SSL VPN
and Clientless SSL VPN connections.
Fields
Default Authorization Server Group—Configures default authorization server group attributes.
Server Group—Selects the authorization server group to use for this connection. The default is
--None--.
Manage—Opens the Configure AAA Server Groups dialog box.
Users must exist in the authorization database to connect—Enables or disables this requirement.
Interface-specific Authorization Server Groups
Table—Lists each configured interface and the server group with which it is associated.
Add or Edit—Opens the Assign Authorization Server Group to Interface dialog box.
Delete—Removes the selected row from the table.
User Name Mapping—Specifies user name mapping attributes.
Username Mapping from Certificate—Lets you specify the fields in a digital certificate from which
to extract the username.
Pre-fill Username from Certificate —Enables the use of a username extracted from the specified
certificate field as the username for username/password authentication and authorization, using
the options that follow in this dialog box.
Hide username from end user—Specifies not to display the extracted username to the end user.
Use script to select username—Specify the name of a script to use to select a username from a
digital certificate. There is no default.
Add or Edit—Opens the Add or Edit Script Content dialog box, in which you can define a script
to use in mapping the username from the certificate.
Delete—Deletes the selected script. There is no confirmation or undo.
Use the entire DN as the username—Enables or disables the requirement to use the entire DN
as the username.
Specify individual DN fields as the username. You can select both the primary DN field, for
which the default is CN (Common Name) and the secondary DN field, for which the default is
OU (Organization Unit).
Primary Field—Selects the first field to use in the username.
Firewall Mode Security Context
Routed Transparent Single
Multiple
Context System
——