38-32
Cisco ASDM User Guide
OL-16647-01
Chapter 38 Clientless SSL VPN
Clientless SSL VPN Access
Step 2 Using your Cisco.com login, download the file cisco_vpn_auth.jar from
http://www.cisco.com/cgi-bin/tablebuild.pl/asa and copy it to the default library directory for the
SiteMinder server. This .jar file is also available on the Cisco security appliance CD.

Add/Edit SSO Servers

This SSO method uses CA SiteMinder and SAML Browser Post Profile. You can also set up SSO using
the HTTP Form protocol, or Basic HTML and NTLM authentication. To use the HTTP Form protocol,
see Configuring Session Settings. To set use basic HTML or NTLM authentication, use the auto-signon
command at the command line interface.
Fields
Server Name—If adding a server, enter the name of the new SSO server. If editing a server, this field
is display only; it displays the name of the selected SSO server.
Authentication Type—Display only. Displays the type of SSO server. The types currently supported
by the security appliance are SiteMinder and SAML Browser Post Profile.
URL—Enter the SSO server URL to which the security appliance makes SSO authentication
requests.
Secret Key—Enter a secret key used to encrypt authentication requests to the SSO server. Key
characters can be any regular or shifted alphanumeric characters. There is no minimum or maximum
number of characters. The secret key is similar to a password: you create it, save it, and configure
it. It is configured on the security appliance, the SSO server, and the SiteMinder Policy Server using
the Cisco Java plug-in authentication scheme.
Maximum Retries—Enter the number of times the security appliance retries a failed SSO
authentication attempt before the authentication times-out. The range is from 1 to 5 retries inclusive,
and the default is 3 retries.
Request Timeout—Enter the number of seconds before a failed SSO authentication attempt times
out. The range is from1 to 30 seconds inclusive, and the default is 5 seconds.
Modes
The following table shows the modes in which this feature is available:
Clientless SSL VPN Access
The Clientless SSL VPN Access panel lets you accomplish the following tasks:
Enable or disable security appliance interfaces for Clientless SSL VPN sessions.
Choose a port for Clientless SSL VPN connections.
Set a global timeout value for Clientless SSL VPN sessions.
Set a maximum number of simultaneous Clientless SSL VPN sessions.
Firewall Mode Security Context
Routed Transparent Single
Multiple
Context System
——