72-128
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter72 Configuring Clientless SSL VPN
Configuring Remote Systems to Use Clientless SSL VPN Features
Using Port Forwarding
Note Users should always close the Application Access window when they finish using applications by
clicking the Close icon. Failure to quit the window properly can cause Application Access or the
applications themselves to be disabled. See Recovering from hosts File Errors When Using Application
Access for details.
Prerequisites
On Macintosh OS X, only the Safari browser supports this feature.
You must have client applications installed.
You must have Cookies enabled on the browser.
You must have administrator access on the PC if you use DNS names to specify servers, because
modifying the hosts file requires it.
You must have Sun Microsystems Java Runtime Environment (JRE) version 1.4.x and 1.5.x
installed.
If JRE is not installed, a pop-up window displays, directing users to a site where it is available. On
rare occasions, the port forwarding applet fails with JAVA exception errors. If this happens, do the
following:
a. Clear the browser cache and close the browser.
b. Verify that no JAVA icons are in the computer task bar.
c. Close all instances of JAVA.
d. Establish a clientless SSL VPN session and launch the port forwarding JAVA applet.
You must have Javascript enabled on the browser. By default, it is enabled.
If necessary, you must configure client applications.
Note The Microsoft Outlook client does not require this configuration step. All non-Windows
client applications require configuration. To determine if configuration is necessary for a
Windows application, check the value of the Remote Server field. If the Remote Server field
contains the server hostname, you do not need to configure the client application. If the
Remote Server field contains an IP address, you must configure the client application.
Restrictions
Because this feature requires installing Sun Microsystems Java™ Runtime Environment and configuring
the local clients, and because doing so requires administrator permissions on the local system or full
control of C:\windows\System32\drivers\etc, it is unlikely that users will be able to use applications
when they connect from public remote systems.
Detailed Steps
.To configure the client application, use the server’s locally mapped IP address and port number. To find
this information:
1. Start a clientless SSL VPN session and click the Application Access link on the Home page. The
Application Access window appears.