天天看點

Cisco SSLVPN Client Profile anyconnect secure mobility client

<?xml version="1.0" encoding="UTF-8"?>

<AnyConnectProfile xmlns="http://schemas.xmlsoap.org/encoding/">

  <ServerList>

    <HostEntry>

      <HostName>ABC CN SSL×××</HostName>

      <HostAddress>210.13.*3.112</HostAddress>

      </HostEntry>

  </ServerList>

</AnyConnectProfile>

  1. 上傳 上面的這個檔案到 ASA的flash中:
  2. 執行下面的指令 在Tunnel Group中指定的

    group-policy GroupPolicy_Anyconnect_××× attributes

     wins-server value 192.168.20.24 192.168.20.23

     dns-server value 192.168.20.24 192.168.20.23

     vpn-simultaneous-logins 10

     vpn-idle-timeout 240

     vpn-tunnel-protocol ssl-client ssl-clientless

     password-storage enable

     split-tunnel-policy tunnelspecified

     split-tunnel-network-list value split

     default-domain value ABC.CN

     webvpn

      anyconnect profiles value Anyconnect_×××_client_profile type user

  3. 檢視

        webvpn

        enable outside

        anyconnect p_w_picpath disk0:/anyconnect-win-2.5.2014-k9.pkg 1

         anyconnect profiles Anyconnect_×××_client_profile disk0:/Cisco_AnyConnect_Profiles.xml

        anyconnect enable

         tunnel-group-list enable