30-38
User Guide for Cisco Security Manager 4.4
OL-28826-01
Chapter 30 Managing Remote Access VPNs on ASA and PIX 7.0+ Devices
Working with SSL and IKEv2 IPSec VPN Policies
Field Reference
Table30-16 SSL VPN Access Policy Page
Element Description
Access Interface Table The Access Interface table lists the interfaces that are configured for
remote access SSL or IKEv2 IPSec VPN connections. The table
displays the access settings for each interface: whether the interface is
enabled to allow VPN access, whether DTLS is enabled, whether client
certificates are required, and the trustpoints used by the interface.
To configure access on an interface, click the Add row (+) button
(see Access Interface Configuration Dialog Box, page 30-40).
To edit access settings for an interface, select the interface and
click the Edit Row (pencil) button (see Access Interface
Configuration Dialog Box, page 30-40).
To delete access settings for an interface, select the interface and
click the Delete Row (trash can) button.
Port Number The port to use for VPN sessions. The default port is 443, for HTTPS
traffic. If HTTP port redirection is enabled, the default HTTP port
number is 80. To specify a non-default port, the range is 1024 through
65535.
Enter the port number or the name of a port list object, or click Select
to select a port list object or to create a new object.
Note If you change the port number, all current SSL VPN
connections terminate (upon configuration deployment), and
current users must reconnect.
DTLS Port Number The UDP port to use for DTLS connections. The default port is 443. For
details about DTLS, see Understanding SSL VPN Access Policies
(ASA), page 30-36.
Enter the port number or the name of a port list object, or click Select
to select a port list object or to create a new object.
Fallback Trustpoint The trustpoint (Certificate Authority, or CA server) to use for interfaces
that do not have an assigned trustpoint. Enter the name of a PKI
enrollment object, or click Select to select the object from a list or to
create a new object.