69-119
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter69 General VPN Setup
DTLS Settings
AnyConnect Essentials mode cannot be enabled when active clientless sessions exist to the device. To
view SSL VPN session details click the Monitoring> VPN > VPN Sessions link in the SSL VPN
Sessions section. This opens the Monitoring > VPN > VPN > VPN Statistics > Sessions pane. To see
session details, choose Filter By: Clientless SSL VPN and click Filter. This displays session details.
To see how many clientless SSL VPN sessions are currently active, without showing session details,
click Check Number of Clientless SSL Sessions. If the SSL VPN session count is zero, you can enable
AnyConnect Essentials.
Note Secure Desktop does not work when AnyConnect Essentials is enabled. You can, however, disable
AnyConnect Essentials when you enable Secure Desktop.
Modes
The following table shows the modes in which this feature is available:
DTLS Settings
Enabling Datagram Transport Layer Security (DTLS) allows the AnyConnect VPN client establishing
an SSL VPN connection to use two simultaneous tunnels—an SSL tunnel and a DTLS tunnel. Using
DTLS avoids latency and bandwidth problems associated with some SSL connections and improves the
performance of real-time applications that are sensitive to packet delays.
If you do not enable DTLS, AnyConnect client users establishing SSL VPN connections connect with
an SSL VPN tunnel only.
Fields
Interface—Displays a list of interfaces on the ASA.
DTLS Enabled—Click to enable DTLS connections with the AnyConnect client on the interfaces.
UDP Port (default 443)—(Optional) Specify a separate UDP port for DTLS connections.
Modes
The following table shows the modes in which this feature is available:
Firewall Mode Security Context
Routed Transparent Single
Multiple
Context System
——
Firewall Mode Security Context
Routed Transparent Single
Multiple
Context System
——