Configuring WebVPN Tunnel Group WebVPN Attributes

To configure the parameters specific to a WebVPN tunnel group, follow the steps in this section.

Step 1 To specify the attributes of a WebVPN tunnel-group, enter tunnel-group webvpn-attributes mode by entering the following command. The prompt changes to indicate the mode change:

hostname(config)# tunnel-group tunnel-group-name webvpn-attributes hostname(config-tunnel-ipsec)#

For example, to specify the webvpn-attributes for the WebVPN tunnel-group named sales, enter the following command:

hostname(config)# tunnel-group sales webvpn-attributes hostname(config-tunnel-webvpn)#

Step 2 To specify the authentication method to use: AAA, digital certificates, or both, enter the authentication command. You can specify either aaa or certificate or both, in any order.

hostname(config-tunnel-webvpn)# authentication authentication_method hostname(config-tunnel-webvpn)#

For example, The following command allows both AAA and certificate authentication:

hostname(config-tunnel-webvpn)# authentication aaa certificate hostname(config-tunnel-webvpn)#

Applying Customization

Customizations determine the appearance of the windows that the user sees upon login. You configure the customization parameters as part of configuring WebVPN.

To apply a previously defined web-page customization to change the look-and-feel of the web page that the user sees at login, enter the customization command in username webvpn configuration mode:

hostname(config-username-webvpn)# customization {none | value customization_name} hostname(config-username-webvpn)#

For example, to use the customization named blueborder, enter the following command:

hostname(config-username-webvpn)# customization value blueborder hostname(config-username-webvpn)#

You configure the customization itself by entering the customization command in WebVPN mode.

The following example shows a command sequence that first establishes a WebVPN customization named "123" that defines a password prompt. The example then defines a WebVPN tunnel-group named "test" and uses the customization command to specifies the use of the WebVPN customization named "123":

hostname(config)# webvpn hostname(config-webvpn)# customization 123

hostname(config-webvpn-custom)# password-prompt Enter password hostname(config-webvpn)# exit hostname(config)# tunnel-group test type webvpn hostname(config)# tunnel-group test webvpn-attributes hostname(config-tunnel-webvpn)# customization value 123 hostname(config-tunnel-webvpn)#

Step 3 The security appliance queries NetBIOS name servers to map NetBIOS names to IP addresses. WebVPN requires NetBIOS to access or share files on remote systems. WebVPN uses NetBIOS and the CIFS protocol to access or share files on remote systems. When you attempt a file-sharing connection to a Windows computer by using its computer name, the file server you specify corresponds to a specific NetBIOS name that identifies a resource on the network.

To make the NBNS function operational, you must configure at least one NetBIOS server (host). You can configure up to three NBNS servers for redundancy. The security appliance uses the first server on the list for NetBIOS/CIFS name resolution. If the query fails, it uses the next server.

To specify the name of the NBNS (NetBIOS Name Service) server to use for CIFS name resolution, use the nbns-server command. You can enter up to three server entries. The first server you configure is the primary server, and the others are backups, for redundancy. You can also specify whether this is a master browser (rather than just a WINS server), the timeout interval, and the number of retries. A WINS server or a master browser is typically on the same network as the security appliance, or reachable from that network. You must specify the timeout interval before the number of retries:

hostname(config-tunnel-webvpn)# nbns-server {host-name | IP_address} [master] [timeout seconds] [retry number] hostname(config-tunnel-webvpn)#

For example, to configure the server named nbnsprimary as the primary server and the server 192.168.2.2 as the secondary server, each allowing three retries and having a 5-second timeout, enter the following command:

hostname(config)# name 192.168.2.1 nbnsprimary hostname(config-tunnel-webvpn)# nbns-server nbnsprimary master timeout 5 retry 3 hostname(config-tunnel-webvpn)# nbns-server 192.168.2.2 timeout 5 retry 3

hostname(config-tunnel-webvpn)#

The timeout interval can range from 1 through 30 seconds (default 2), and the number of retries can be in the range 0 through 10 (default 2).

The nbns-server command in tunnel-group webvpn-attributes configuration mode replaces the deprecated nbns-server command in webvpn configuration mode.

Step 4 To specify alternative names for the group, use the group-alias command. Specifying the group alias creates one or more alternate names by which the user can refer to a tunnel-group. The group alias that you specify here appears in the drop-down list on the user's login page. Each group can have multiple aliases or no alias, each specified in separate commands. This feature is useful when the same group is known by several common names, such as "Devtest" and "QA".

For each group alias, enter a group-alias command. Each alias is enabled by default. You can optionally explicitly enable or disable each alias:

hostname(config-tunnel-webvpn)# group-alias alias [enable | disable] hostname(config-tunnel-webvpn)#

For example, to enable the aliases QA and Devtest for a tunnel-group named QA, enter the following commands:

hostname(config-tunnel-webvpn)# group-alias QA enable hostname(config-tunnel-webvpn)# group-alias Devtest enable hostname(config-tunnel-webvpn)#

Note The WebVPN tunnel-group-list must be enabled for the (dropdown) group list to appear.

Step 5 To specify incoming URLs or IP addresses for the group, use the group-url command. Specifying a group URL or IP address eliminates the need for the user to select a group at login. When a user logs in, the security appliance looks for the user's incoming URL or address in the tunnel-group-policy table. If it finds the URL or address and if group-url is enabled in the tunnel group, then the security appliance automatically selects the associated tunnel group and presents the user with only the username and password fields in the login window. This simplifies the user interface and has the added advantage of never exposing the list of groups to the user. The login window that the user sees uses the customizations configured for that tunnel group.

If the URL or address is disabled and group-alias is configured, then the dropdown list of groups is also displayed, and the user must make a selection.

You can configure multiple URLs or addresses (or none) for a group. Each URL or address can be enabled or disabled individually. You must use a separate group-url command for each URL or address specified. You must specify the entire URL or address, including either the http or https protocol.

You cannot associate the same URL or address with multiple groups. The security appliance verifies the uniqueness of the URL or address before accepting the URL or address for a tunnel group.

For each group URL or address, enter a group-URL command. You can optionally explicitly enable (the default) or disable each URL or alias:

hostname(config-tunnel-webvpn)# group-url url [enable | disable] hostname(config-tunnel-webvpn)#

For example, to enable the group URLs http://www.cisco.com and http://192.168.10.10 for the tunnel-group named RadiusServer, enter the following commands:

hostname(config)# tunnel-group RadiusServer type webvpn hostname(config)# tunnel-group RadiusServer general-attributes hostname(config-tunnel-general)# authentication server-group RADIUS hostname(config-tunnel-general)# accounting-server-group RADIUS hostname(config-tunnel-general)# tunnel-group RadiusServer webvpn-attributes hostname(config-tunnel-webvpn)# group-alias "Cisco Remote Access" enable hostname(config-tunnel-webvpn)# group-url http://www.cisco.com enable hostname(config-tunnel-webvpn)# group-url http://192.168.10.10 enable hostname(config-tunnel-webvpn)#

For a more extensive example, see Customizing Login Windows for WebVPN Users, page 30-23.

Step 6 To specify the DNS server to use for a WebVPN tunnel group, enter the dns-group command. The default value is DefaultDNS:

hostname(config-tunnel-webvpn)# dns-group {hostname | ip_address} hostname(config-tunnel-webvpn)#

The dns-group command resolves the hostname to the appropriate DNS server for the tunnel group. For example, to specify the use of the DNS server named server1, enter the following command:

hostname(config)# name 10.10.10.1 server1

hostname(config-tunnel-webvpn)# dns-group server1 hostname(config-tunnel-webvpn)#

Step 7 (Optional) To specify a VPN feature policy if you use the Cisco Secure Desktop Manager to set the

Group-Based Policy attribute to "Use Failure Group-Policy" or "Use Success Group-Policy, if criteria match," use the hic-fail-group-policy command. The default value is DfltGrpPolicy.

hostname(config-tunnel-webvpn)# hic-fail-group-policy name

hostname(config-tunnel-webvpn)#

Name is the name of a group policy created for a WebVPN tunnel group.

This policy is an alternative group policy to differentiate access rights for the following CSD clients:

• Clients that match a CSD location entry set to "Use Failure Group-Policy."

• Clients that match a CSD location entry set to "Use Success Group-Policy, if criteria match," and

then fail to match the configured Group-Based Policy criteria. For more information, see the Cisco

Secure Desktop Configuration Guide for Cisco ASA 5500 Series Administrators.

The following example specifies an alternative group policy named group2:

hostname(config-tunnel-webvpn)# hic-fail-group-policy group2

hostname(config-tunnel-webvpn)#

Note The security appliance does not use this attribute if you set the VPN feature policy to "Always

use Success Group-Policy."

For more information, see the Cisco Secure Desktop Configuration Guide for Cisco ASA 5500 Series

Administration Guide.

Customizing

Login Windows for WebVPN Users

You can set up different login windows for different groups by using a combination of customization

profiles and tunnel groups. For example, assuming that you had created a customization profile called

salesgui, you can create a WebVPN tunnel group called sales that uses that customization profile, as the

following example shows:

Step 1

In webvpn mode, define a WebVPN customization, in this case named salesgui and change the default

logo to mycompanylogo.gif. You must have previously loaded mycompanylogo.gif onto the flash

memory of the security appliance and saved the configuration. See the WebVPN chapter for details.

hostname# webvpn

hostname (config-webvpn)# customization value salesgui

hostname(config-webvpn-custom)# logo file disk0:\mycompanylogo.gif

hostname(config-webvpn-custom)#

Step 2

In global configuration mode, set up a username and associate with it the WebVPN customization you've

just defined:

hostname# username seller attributes

hostname(config-username)# webvpn

hostname(config-username-webvpn)# customization value salesgui

hostname(config-username-webvpn)# exit

hostname(config-username)# exit

hostname#

Step 3

In global configuration mode, create a WebVPN tunnel-group named sales:

hostname# tunnel-group sales type webvpn

hostname(config-tunnel-webvpn)#

Step 4

Specify that you want to use the salesgui customization for this tunnel group:

hostname# tunnel-group sales webvpn-attributes

hostname(config-tunnel-webvpn)# customization salesgui

Step 5 Set the group URL to the address that the user enters into the browser to log in to the security appliance; for example, if the security appliance has the IP address 192.168.3.3, set the group URL to https://192.168.3.3:

hostname(config-tunnel-webvpn)# group-url https://192.168.3.3. hostname(config-tunnel-webvpn)#

If a port number is required for a successful login, include the port number, preceded by a colon. The security appliance maps this URL to the sales tunnel group and applies the salesgui customization profile to the login screen that the user sees upon logging in to https://192.168.3.3.

Continue reading here: Using Active Directory to Force the User to Change Password at Next Logon

Was this article helpful?

+1 0