Secure Client custom attributes objects
Custom attributes objects enable Secure Client (formerly AnyConnect) to configure features such as Per App VPN, allow or defer upgrade, and dynamic split tunneling. You define the attribute type, then assign one or more named values for this type. In Secure Firewall Management Center, you create custom attributes objects, add them to a group policy, and associate the policy with a remote access VPN to enable features for VPN clients.
Supported features using custom attributes objects
Firewall Threat Defense supports these features using custom attribute objects:
-
Per App VPN—You can specify which applications may use the VPN tunnel. The system identifies these apps and tunnels only the allowed applications.
-
Allow or defer upgrade—You can delay downloading Secure Client updates. When a client update becomes available, you can prompt users to upgrade or defer the update.
-
Dynamic Split Tunneling—You can configure policies to selectively include or exclude IP addresses or networks from the VPN tunnel. Create a custom attribute and add it to a group policy to achieve this.
For step-by-step instructions to configure Secure Client custom attributes, see Configure custom attributes for Secure Client.
For details about the specific custom attributes to configure for a feature, see the Cisco Secure Client (including AnyConnect) Administrator Guide for the Secure Client release you are using.