Cisco Systems OL-16647-01 Network Router User Manual


  Open as PDF
of 1230
 
2-13
Cisco ASDM User Guide
OL-16647-01
Chapter 2 Introduction to the Security Appliance
New Features by Platform Release
Platform
Enhancements
VLAN support for
remote access VPN
connections
Provides support for mapping (tagging) of client traffic at the group or user
level. This feature is compatible with clientless as well as IPsec and SSL
tunnel-based connections.
VPN load balancing for
the ASA 5510
Extends load balancing support to ASA 5510 adaptive security appliances
that have a Security Plus license.
Crypto conditional debug Lets users debug an IPsec tunnel on the basis of predefined crypto conditions
such as the peer IP address, connection-ID of a crypto engine, and security
parameter index (SPI). By limiting debug messages to specific IPSec
operations and reducing the amount of debug output, you can better
troubleshoot the security appliance with a large number of tunnels.
Browser-based
SSL VPN Features
Enhanced portal design Version 8.0(2) includes an enhanced end user interface that is more cleanly
organized and visually appealing.
Customization Supports administrator-defined customization of all user-visible content.
Support for FTP You can provide file access via FTP in additional to CIFS (Windows-based).
Plugin applets Version 8.0(2) adds a framework for supporting TCP-based applications
without requiring a pre-installed client application. Java applets let users
access these applications from the browser-enabled SSL VPN portal. Initial
support is for TELNET, SSH, RDP, and VNC.
Smart tunnels A smart tunnel is a connection between an application and a remote site,
using a browser-based SSL VPN session with the security appliance as the
pathway. Version 8.0(2) lets you identify the applications to which you want
to grant smart tunnel access, and lets you specify the path to the application
and the SHA-1 hash of its checksum to check before granting it access. Lotus
SameTime and Microsoft Outlook Express are examples of applications to
which you might want to grant smart tunnel access.
The remote host originating the smart tunnel connection must be running
Microsoft Windows Vista, Windows XP, or Windows 2000, and the browser
must be enabled with Java, Microsoft ActiveX, or both.
RSS newsfeed Administrators can populate the clientless portal with RSS newsfeed
information, which lets company news or other information display on a user
screen.
Table 2-5 New Features for ASA and PIX Version 8.0(2) (continued)
ASA Feature Type Feature Description