33-10
User Guide for Cisco Security Manager 4.4
OL-28826-01
Chapter 33 Configuring Policy Objects for Remote Access VPNs
ASA Group Policies Dialog Box

Add or Edit Client Access Rules Dialog Box

Use the Client Access Rules dialog box to create or edit the priority, action, VPN client type and VPN
client version for a client access rule.
Navigation Path
From ASA Group Policies IPSec Settings, page 33-8, click the Add Row button beneath the Client
Access Rules table, or select a rule and click the Edit Row button.
Field Reference
ASA Group Policies SSL VPN Clientless Settings
Use the Clientless settings to configure the clientless mode of access to the corporate network in a remote
access SSL VPN for the ASA group policy object.
When a user connects to the SSL VPN in clientless mode, the user logs into the SSL VPN portal page.
From the portal page, the user can access all available HTTP sites, access web e-mail, and browse
Common Internet File System (CIFS) file servers, depending on how you configure the portal.
Table33-6 Add or Edit Client Access Rules Dialog Box
Element Description
Priority The relative priority of the rule.
The rule with the lowest integer has the highest priority. Therefore, the
rule with the lowest integer that matches a client type or version is the
rule that applies. If a lower priority rule contradicts, the security
appliance ignores it. Values are 1-65535.
Action Whether this rule permits or denies traffic access to the client.
VPN Client Type
VPN Client Version
The type or version of VPN client to which this rule applies. Spaces are
allowed.
You can use * as a wildcard to match zero or more characters. You can
use n/a for clients that do not send their type or version. The strings you
enter in these fields must match the strings displayed using the show
vpn-sessiondb remote command on the ASA device.
Following are some examples, where priority, permit/deny, type, and
version are shown in order:
3 Deny * version 3.* is a priority 3 rule that denies all client types
with software version 3.x.
5 Permit VPN3002 * is a priority 5 rule that allows VPN3002
clients of all software versions.
255 Permit * * is a priority 255 rule that allows all types and
versions of clients. This is useful if you are only trying to deny
specific types of clients without wanting to create permit rules fo r
all the other types.