Cisco Systems OL-16647-01 Network Router User Manual


  Open as PDF
of 1230
 
38-21
Cisco ASDM User Guide
OL-16647-01
Chapter 38 Clientless SSL VPN
Port Forwarding
Neither port forwarding nor the ASDM Java applet work with user authentication using digital
certificates. Java does not have the ability to access the web browser keystore. Therefore Java cannot
use certificates that the browser uses to authenticate users, and the application cannot start.
Add/Edit Port Forwarding List
The Add/Edit Port Forwarding List dialog boxes let you add or edit a named list of TCP applications to
associate with users or group policies for access over clientless SSL VPN connections.
Fields
List Name—Alpha-numeric name for the list. Maximum 64 characters.
Local TCP Port—Local port that listens for traffic for the application.
Remote Server—IP address or DNS name of the remote server.
Remote TCP Port—Remote port that listens for traffic for the application.
Description—Text that describes the TCP application.
Modes
The following table shows the modes in which this feature is available:
Add/Edit Port Forwarding Entry
The Add/Edit Port Forwarding Entry dialog boxes let you specify TCP applications to associate with
users or group policies for access over clientless SSL VPN connections. Assign values to the attributes
in these windows as follows:
Local TCP Port—Type a TCP port number for the application to use. You can use a local port
number only once for a listname. To avoid conflicts with local TCP services, use port numbers in
the range 1024 to 65535.
Remote Server—Type either the DNS name or IP address of the remote server. We recommend using
hostnames so that you do not have to configure the client applications for specific IP addresses.
Remote TCP Port—Type the well-know port number for the application.
Description—Type a description of the application. Maximum 64 characters.
Modes
The following table shows the modes in which this feature is available:
Firewall Mode Security Context
Routed Transparent Single
Multiple
Context System
——