72-49
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter72 Configuring Clientless SSL VPN
Configuring Application Access
Assigning a Smart Tunnel List
For each group policy and username, you can configure clientless SSL VPN to do one of the following:
Start smart tunnel access automatically upon user login.
Enable smart tunnel access upon user login, but require the user to start it manually, using the
Application Access > Start Smart Tunnels button on the clientless SSL VPN Portal Page.
Restrictions
These options are mutually exclusive for each group policy and username. Use only one.
The following smart tunnel commands are available to each group policy and username. The
configuration of each group policy and username supports only one of these commands at a time, so
when you enter one, the ASA replaces the one present in the configuration of the group policy or
username in question with the new one, or in the case of the last command, simply removes the
smart-tunnel command already present in the group policy or username.
Configuring and Applying Smart Tunnel Policy
The smart tunnel policy requires a per group policy/username configuration. Each group
policy/username references a globally configured list of networks. When the smart tunnel is turned on,
you can allow traffic outside of the tunnel with the use of 2 CLIs: one configures the network (a set of
hosts), and the other uses the specified smart-tunnel network to enforce a policy on a user. The following
commands create a list of hosts to use for configuring smart tunnel policies:
Specifying Servers for Smart Tunnel Auto Sign-on
The Add Smart Tunnel Auto Sign-on Server List dialog box lets you add one or more lists of servers for
which to automate the submission of login credentials during smart tunnel setup. The Edit Smart Tunnel
Auto-signon Server List dialog box lets you modify the contents of these lists. This feature is available
for Internet Explorer and Firefox.
To create a list of servers for which to automate the submission of credentials in smart tunnel
connections, enter the following commands:
Open a new Terminal window on a Mac. (Any
subsequent application launched from within
the same Terminal window fails because of the
one-time-password implementation.)
terminal Terminal Mac
Start smart tunnel for a new window new-terminal Terminal open -a MacTelnet Mac
Start application from a Mac Terminal window. curl Terminal curl www.example.com Mac
Table72-6 Example Smart Tunnel Entries
Smart Tunnel Support
Application ID
(Any unique string
is OK.) Process Name OS