72-46
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter72 Configuring Clientless SSL VPN
Configuring Application Access
Step6 Select Windows next to OS.
Step7 Click OK.
Step8 Repeat Steps 37 for each application to add to the list.
Step9 Click OK in the Add or Edit Smart Tunnel List dialog box.
Step10 Assign the list to the group policies and local user policies to which you want to provide smart tunnel
access to the associated applications, as follows:
To assign the list to a group policy, choose Configuration > Remote Access VPN> Clientless SSL
VPN Access > Group Policies > Add or Edit > Portal and choose the smart tunnel name from the
drop-down list next to the Smart Tunnel List attribute.
To assign the list to a local user policy, choose Configuration > Remote Access VPN> AAA Setup
> Local Users > Add or Edit > VPN Policy > Clientless SSL VPN and choose the smart tunnel
name from the drop-down list next to the Smart Tunnel List attribute.
Simplifying Configuration of Which Applications to Tunnel
A smart tunnel application list is essentially a filter of what applications are granted access to the tunnel.
The default is to allow access for all processes started by the browser. With Smart Tunnel enabled
bookmark, the clientless session grants access only to processes initiated by the web browser. For
non-browser applications, an administrator can choose to tunnel all applications and thus remove the
need to know which applications an end user may invoke. Table72-5 shows in which situations
processes are granted access.
Restrictions
This configuration is applicable to Windows platforms only.
Detailed Steps
Follow these steps to configure tunnel policy.
Table72-5 Access for Smart Tunnel Applications and Enabled Bookmarks
Smart Tunnel Enabled Bookmark Smart Tunnel Application Access
Application list specified Any processes that match a
process name in the application
list are granted access.
Only processes that match a
process name in the application
list are granted access.
Smart tunnel is disabled All processes (and their child
processes) are granted access.
No process is granted access.
Smart Tunnel all
Applications check box is
checked
All processes (and their child
processes) are granted access.
Note This includes processes
initiated by non-Smart
Tunnel web pages if the
web page is served by the
same browser process.
All processes owned by the user
who started the browser are
granted access but not child
processes of those original
processes.