Introduction to Clientless SSL VPN
Clientless SSL VPN enables end users to securely access resources on the corporate network from anywhere using an SSL-enabled Web browser. The user first authenticates with a Clientless SSL VPN gateway, which then allows the user to access pre-configured network resources.
Note |
Security contexts (also called firewall multimode) and Active/Active stateful failover are not supported when Clientless SSL VPN is enabled. |
Clientless SSL VPN creates a secure, remote-access VPN tunnel to an ASA using a web browser without requiring a software or hardware client. It provides secure and easy access to a broad range of web resources and both web-enabled and legacy applications from almost any device that can connect to the Internet via HTTP. They include:
-
Internal websites.
-
Web-enabled applications.
-
NT/Active Directory file shares.
-
email proxies, including POP3S, IMAP4S, and SMTPS.
-
Microsoft Outlook Web Access Exchange Server 2000, 2003, and 2007.
-
Microsoft Web App to Exchange Server 2010 in 8.4(2) and later.
-
Application Access (smart tunnel or port forwarding access to other TCP-based applications).
Clientless SSL VPN uses Secure Sockets Layer Protocol and its successor, Transport Layer Security (SSL/TLS1) to provide the secure connection between remote users and specific, supported internal resources that you configure as an internal server. The ASA recognizes connections that must be proxied, and the HTTP server interacts with the authentication subsystem to authenticate users.
The network administrator provides access to resources by users of Clientless SSL VPN sessions on a group basis. Users have no direct access to resources on the internal network.