1-4
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter1 Introduction to the Cisco ASA 5500 Series
New Features
Compression for DTLS and
TLS
To improve throughput, Cisco now supports compression for DTLS and TLS on AnyConnect
3.0 or later. Each tunneling method configures compression separately, and the preferred
configuration is to have both SSL and DTLS compression as LZS. This feature enhances
migration from legacy VPN clients.
Note Using data compression on high speed remote access connections passing highly
compressible data requires significant processing power on the ASA. With other
activity and traffic on the ASA, the number of sessions that can be supported on the
platform is reduced.
We modified the following screen: Configuration > Remote Access VPN > Clientless SSL
VPN Access > Group Policies > Edit > Edit Internal Group Policy > Advanced > AnyConnect
Client > SSL Compression.
Also available in Version 8.4(3).
Clientless SSL VPN Session
Timeout Alerts
Allows you to create custom messages to alert users that their VPN session is about to end
because of inactivity or a session timeout.
We introduced the following screens:
Remote Access VPN > Configuration > Clientless SSL VPN Access > Portal > Customizations
> Add/Edit > Timeout Alerts
Remote Access VPN > Configuration > Clientless SSL VPN Access > Group Policies >
Add/Edit General
Also available in Version 8.4(3).
Multiple Context Mode Features
Automatic generation of a
MAC address prefix
In multiple context mode, the ASA now converts the automatic MAC address generation
configuration to use a default prefix. The ASA auto-generates the prefix based on the last two
bytes of the interface MAC address. This conversion happens automatically when you reload,
or if you reenable MAC address generation. The prefix method of generation provides many
benefits, including a better guarantee of unique MAC addresses on a segment. If you want to
change the prefix, you can reconfigure the feature with a custom prefix. The legacy method of
MAC address generation is no longer available.
Note To maintain hitless upgrade for failover pairs, the ASA does not convert the MAC
address method in an existing configuration upon a reload if failover is enabled.
However, we strongly recommend that you manually change to the prefix method of
generation. After upgrading, to use the prefix method of MAC address generation,
reenable MAC address generation to use the default prefix.
We modified the following screen: Configuration > Context Management > Security Contexts
AAA Features
Table1-2 New Features forASA Version 8.6(1)/ASDM Version 6.6(1) (continued)
Feature Description