1-78
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring Connection Profiles, Group Policies, and Users
Supporting a Zone Labs Integrity Server
Setting Client Firewall Parameters
Enter the following commands to set the appropriate client firewall parameters. You can configure only
one instance of each command. For more information, see the “Configuring VPN Client Firewall
Policies” section on page 70-74.
Cisco Integrated Firewall
hostname(config-group-policy)# client-firewall {opt | req} cisco-integrated acl-in ACL
acl-out ACL
Cisco Security Agent
hostname(config-group-policy)# client-firewall {opt | req} cisco-security-agent
No Firewall
hostname(config-group-policy)# client-firewall none
Custom Firewall
hostname(config-group-policy)# client-firewall {opt | req} custom vendor-id num product-id
num
policy {AYT | CPP acl-in ACL acl-out ACL} [description string]
Zone Labs Firewalls
hostname(config-group-policy)# client-firewall {opt | req} zonelabs-integrity
Note When the firewall type is zonelabs-integrity, do not include arguments. The Zone Labs Integrity Server
determines the policies.
hostname(config-group-policy)# client-firewall {opt | req} zonelabs-zonealarm policy {AYT
| CPP acl-in ACL
acl-out ACL}
hostname(config-group-policy)# client-firewall {opt | req} zonelabs-zonealarmorpro policy
{AYT | CPP acl-in ACL
acl-out ACL}
client-firewall {opt | req} zonelabs-zonealarmpro policy {AYT | CPP acl-in ACL
acl-out
ACL}
Sygate Personal Firewalls
hostname(config-group-policy)# client-firewall {opt | req} sygate-personal
hostname(config-group-policy)# client-firewall {opt | req} sygate-personal-pro
hostname(config-group-policy)# client-firewall {opt | req} sygate-security-agent
Network Ice, Black Ice Firewall:
hostname(config-group-policy)# client-firewall {opt | req} networkice-blackice