72-28
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter72 Configuring Clientless SSL VPN
Configuring Browser Access to Plug-ins
Restrictions
The plug-ins do not work if the security appliance configures the clientless session to use a proxy
server.
Note The remote desktop protocol plug-in does not support load balancing with a session broker.
Because of the way the protocol handles the redirect from the session broker, the connection
fails. If a session broker is not used, the plug-in works.
The plug-ins support single sign-on (SSO). They use the same credentials entered to open the
clientless SSL VPN session. Because the plug-ins do not support macro substitution, you do not
have the options to perform SSO on different fields such as the internal domain password or on an
attribute on a RADIUS or LDAP server.
A stateful failover does not retain sessions established using plug-ins. Users must reconnect
following a failover.
If you use stateless failover instead of stateful failover, clientless features such as bookmarks,
customization, and dynamic access-policies are not synchronized between the failover ASA pairs.
In the event of a failover, these features do not work.
Adding a New Environment Variable
To set up and use an RDP plug-in, you must add a new environment variable. For the process of adding
a new environment variable, use the following steps:
Detailed Steps
Step1 Right click on My Computer to access the System Properties and choose the Advanced tab.
Step2 On the Advanced tab, choose the environment variables button.
Step3 In the new user variable dialog box, enter the RF_DEBUG variable.
Step4 Verify the new Environment Variable in the user variables section.
Step5 If you used the client computer with versions of WebVPN before version 8.3, you must remove the old
Cisco Portforwarder Control. Go to the C:/WINDOWS/Downloaded Program Files directory, right click
on the portforwarder control, and choose Remove.
Step6 Clear all of the Internet Explorer browser cache.
Step7 Launch your WebVPN session and establish an RDP session with the RDP ActiveX Plug-in.
You can now observe events in the Windows Application Event viewer.
Preparing the Security Appliance for a Plug-in
Before installing a plug-in, prepare the ASA as follows: