1-15
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring AnyConnect VPN Client Connections
Configuring AnyConnect Connections
asa1(config-webvpn)# anyconnect profiles sales disk0:/sales_hosts.xml
asa1(config-webvpn)# anyconnect profiles engineering disk0:/engineering_hosts.xml
The profiles are now available to group policies.
You can view the profiles loaded in cache memory using the dir cache:stc/profiles command:
hostname(config-webvpn)# dir cache:/stc/profiles
Directory of cache:stc/profiles/
0 ---- 774 11:54:41 Nov 22 2006 engineering.xml
0 ---- 774 11:54:29 Nov 22 2006 sales.xml
2428928 bytes total (18219008 bytes free)
hostname(config-webvpn)#
Step 4 Enter group policy webvpn configuration mode and specify a client profile for a group policy with the
anyconnect profiles command:
You can enter the anyconnect profiles value command followed by a question mark (?) to view the
available profiles. For example:
asa1(config-group-webvpn)# anyconnect profiles value ?
config-group-webvpn mode commands/options:
Available configured profile packages:
engineering
sales
The next example configures the group policy to use the profile sales with the client profile type vpn:
asa1(config-group-webvpn)# anyconnect profiles value sales type vpn
asa1(config-group-webvpn)#
Enabling AnyConnect Client Deferred Upgrade
Deferred Upgrade allows the AnyConnect user to delay download of a client upgrade. When a client
update is available, AnyConnect opens a dialog asking the user if they would like to update, or to defer
the upgrade.
Deferred Upgrade is enabled by adding custom attributes to the ASA, and then referencing and
configuring those attributes in a group policy.
The following custom attributes support Deferred Upgrade: