Enabling Datagram Transport Layer Security (Dtls) With Anyconnect (Ssl) Connections - Cisco 5505 - ASA Firewall Edition Bundle Administrator's Manual

Administration guide
Hide thumbs Also See for 5505 - ASA Firewall Edition Bundle:
Table of Contents

Advertisement

Configuring AnyConnect Features Using ASDM
The AnyConnect client includes the following features, which you configure on the security appliance:
Enabling Datagram Transport Layer Security (DTLS) with
AnyConnect (SSL) Connections
Datagram Transport Layer Security avoids latency and bandwidth problems associated with some
SSL-only connections, including AnyConnect connections, and improves the performance of real-time
applications that are sensitive to packet delays. DTLS is a standards-based SSL protocol that provides a
low-latency data path using UDP. For detailed information about DTLS, see RFC 4347
(http://www.ietf.org/rfc/rfc4347.txt).
Datagram Transport Layer Security (DTLS) allows the AnyConnect client establishing an SSL VPN
connection to use two simultaneous tunnels-an SSL tunnel and a DTLS tunnel. Using DTLS avoids
latency and bandwidth problems associated with some SSL connections and improves the performance
of real-time applications that are sensitive to packet delays.
If you do not enable DTLS, AnyConnect/SSL VPN connections connect with an SSL VPN tunnel only.
You cannot enable DTLS globally with ASDM. The following section describes how to enable DTLS
for any specific interface.
OL-12950-012
page 5-1
Configuring DTLS, page 5-2
Configuring the Dynamic Access Policies Feature of the Security Appliance, page 5-15
Cisco Secure Desktop Support, page 5-15
C H A P T E R
Cisco AnyConnect VPN Client Administrator Guide
5
5-1

Advertisement

Table of Contents
loading

Table of Contents