Friday, August 1, 2014

Clientless SSL VPN - Smart tunnel 1 (all applications)

Smart tunnel make internet users to use a variety of application locally with Clientless ssl vpn which is similar to plug-ins. However, there is a big difference that when you use smart tunnel function, you can use applications outside of web site.

1. Apply Smart Tunnel to Group Policy: This will open all application through Clientless vpn.

Uncheck Web acls for test purpose.


Clientless ssl VPN - plug-ins

Cisco plug-ins give more options to outside users to access inside devices such as Remote Desktop Access, VNC and SSH.

I'm going to add RDP, VNC and SSH plug-ins to ASA.
So that, people in internet with clientless ssl vpn can access inside network with more options.

First, add plug-ins to ASA. you have to copy the plug-ins from tftp to Flash.


ASA_VPN Clientless SSL VPN with Certifiate.

Topology ( Firewall is pre-configured )

ASA_VPN Network

VPN Test Network
Inside Network: 192.168.0.0/24
Management Network: 172.16.0.0/24
Internet Test PC: 192.168.1.151/24
Publick IP address: 192.168.1.141/24

Scenario: outside user(192.168.1.151 / Windows 7) connects inside network through VPNs to use inside  services such as Web, RDP (Remote Desktop Protocol), VNC, SSH and ftp services.

    Type of VPNs
               1. Web VPN (Clientless SSL VPN)
               2. Anyconnect SSL VPN
               3. IPsec Remote Access VPN
               4. Site to Site IPsec VPN