Group policy options for Secure Client
These specifications apply to the operation of the Secure Client VPN.
Navigation
. Click Add Group Policy or choose a current policy to edit., and then select the Secure Client tab.
Profile fields
Profile—Choose or create a file object containing the Secure Client Profile. See File objects for object creation details.
The Secure Client Profile is a group of configuration parameters stored in an XML file. The Secure Client software uses it to configure the connection entries that appear in the client's user interface. These parameters (XML tags) also configure settings to enable more Secure Client features.
Use the GUI-based Secure Client Profile Editor, an independent configuration tool, to create the Secure Client Profile. See the Secure Client Profile Editor chapter in the appropriate release of the Cisco Secure Client (including AnyConnect) Administrator Guide for details.
Management profile fields
Management VPN Tunnel—Provides always-on connectivity to the corporate network when the endpoint is powered up, regardless of the user's VPN connection status.
Management VPN Profile—The Management Profile file contains settings for enabling and establishing Management VPN Tunnel on endpoint.
The Standalone Management VPN Tunnel profile editor can be used to create a new profile file or modify an existing file. You can download the profile editor from Cisco Software Download Center.
For more information about adding a profile file, see File objects.
Client modules fields
Cisco Secure Client VPN Only offers enhanced security through various built-in modules. These modules provide services such as web security, network visibility into endpoint flows, and off-network roaming protection. Each module includes a custom client profile.
The following Secure Client modules are optional and you can configure these modules to be downloaded when a VPN user downloads Secure Client:
-
AMP Enabler—Deploys advanced malware protection (AMP) for endpoints.
-
DART—Captures a snapshot of system logs and other diagnostic information, which can be sent to the Cisco TAC for troubleshooting.
-
ISE Posture—Uses the OPSWAT library to perform posture checks to assess an endpoint's compliance.
-
Network Access Manager—Provides 802.1X (Layer 2) and device authentication for access to both wired and wireless networks.
-
Network Visibility—Enhances the enterprise administrator's ability to do capacity and service planning, auditing, compliance, and security analytics.
-
Start Before Login—Forces the user to connect to the enterprise infrastructure over a VPN connection before logging on to Windows by starting Secure Client before the Windows login dialog box appears.
-
Umbrella Roaming Security—Provides DNS-layer security when no VPN is active.
-
Web Security—Enforces web security policies and blocks malicious content.
Click Add and select the following for each client module:
-
Client Module—Select the Secure Client module from the list.
-
Profile to download—Choose or create a file object containing the Secure Client Profile. See File objects for object creation details.
-
Enable module download—Select to enable endpoints to download the client module along with the profile. If not selected, the endpoints can download only the client profile.
Use the GUI-based Secure Client Profile Editor, an independent configuration tool to create a client profile for each module. Download the Secure Client Profile Editor from Cisco Software Download Center. See the Secure Client Profile Editor chapter in the appropriate release of the Cisco Secure Client (including AnyConnect) for details.
SSL settings fields
-
SSL Compression—Determines if data compression is enabled, and specifies the method to use (Deflate or LZS). SSL Compression is disabled by default.
Data compression speeds up transmission rates, but also increases the memory requirement and CPU usage for each user session. Thereby, decreasing the overall throughput of the security appliance.
-
DTLS Compression—Specifies whether to compress Datagram Transport Layer Security (DTLS) connections for this group using LZS. DTLS Compression is disabled by default.
-
MTU Size—TSpecifies the maximum transmission unit (MTU) size for SSL VPN connections established by Cisco Secure Client VPN Only. The default is 1406 bytes; the valid range is 576 to 1462 bytes.
-
Ignore DF Bit—Whether to ignore the Don't Fragment (DF) bit in packets that need fragmentation. Allows the forced fragmentation of packets that have the DF bit set, allowing them to pass through the tunnel.
-
Connection settings fields
-
Enable Keepalive Messages between Secure Client and VPN gateway and its Interval setting.—Determines whether peers exchange keepalive messages to demonstrate availability for sending and receiving data in the tunnel. By default, this feature is enabled. Keepalive messages are transmitted at set intervals. If enabled, enter the time interval (in seconds) that the remote client waits between sending IKE keepalive packets. The default interval is 20 seconds, the valid range is 15 to 600 seconds.
-
Enable Dead Peer Detection and its Interval settings.—Dead Peer Detection (DPD) ensures that the VPN secure gateway or client quickly detects when the peer is no longer responding and the connection has failed. Default is enabled for both the gateway and the client. DPD messages transmit at set intervals. If enabled, enter the time interval (in seconds) that the remote client waits between sending DPD messages. The default interval is 30 seconds, the valid range is 5 to 3600 seconds.
-
Enable Client Bypass Protocol—Allows you to configure how the secure gateway manages IPv4 traffic (when it is expecting only IPv6 traffic), or how it manages IPv6 traffic (when it is expecting only IPv4 traffic).
After the Secure Clientconnects to the headend, the headend assigns the VPN connection an IPv4 address, an IPv6 address, or both. If the headend assigns only one type of address, you can configure the Client Bypass Protocol to either drop network traffic for which an IP address was not assigned (default, disabled, not checked), or allow that traffic to bypass the headend and be sent from the client unencrypted (“in the clear”; enabled, checked).
For example, if the secure gateway assigns only an IPv4 address to the Secure Client connection and the endpoint is dual-stacked. When the endpoint attempts to reach an IPv6 address, if Client Bypass Protocol is disabled, the IPv6 traffic is dropped; however, if Client Bypass Protocol is enabled, the IPv6 traffic is sent from the client in the clear.
-
SSL rekey—Enables the client to rekey the connection, renegotiating the crypto keys and initialization vectors, increasing the security of the connection. This is disabled by default. When enabled, the renegotiation can be done at a specified interval and rekey the existing tunnel or create a new tunnel by setting the following fields:
-
Method—Available when SSL rekey is enabled. Create a New Tunnel (default), or renegotiate, the Existing Tunnel's specifications.
-
Interval—Available when SSL rekey is enabled. Set to a default of 4 minutes with a range of 4-10080 minutes (1 week).
-
-
Client Firewall Rules—Use the Client Firewall Rules to configure firewall settings for the VPN client's platform. Rules are based on criteria such as source address, destination address, and protocol. Extended Access Control List building block objects are used to define the traffic filter criteria. Choose or create an Extended ACL for this group policy. Define a Private Network Rule to control data flowing to the private network, a Public Network Rule to control data flowing "in the clear", outside of the established VPN tunnel, or both.
NoteEnsure that the ACL contains only TCP/UDP/ICMP/IP ports and source network as any, any-ipv4 or any-ipv6.
Only VPN clients running Microsoft Windows can use these firewall settings.
Custom attributes fields
Custom attributes are used by the Secure Client to configure features such as Per App VPN, Allow or defer upgrade, and Dynamic split tunneling. Click Add to add custom attributes to the group policy.
-
Select the Secure Client Attrinute: Per App VPN, Allow Defer Update, or Dynamic Split Tunneling.
-
Select a Custom Attribute Object from the list.
NoteClick Add (+) to create a new custom attribute object for the selected Secure Client attribute. You can also create a custom attribute object at . See Configure custom attributes for Secure Client.
-
Click Add to save the attributes to the group policy, and then click Save to save the changes to the group policy.