<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WebVPN Clientless SSL VPN to intranet website - links to external sites are not working in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/webvpn-clientless-ssl-vpn-to-intranet-website-links-to-external/m-p/3830245#M925102</link>
    <description>&lt;P&gt;Yes this is setup on a Cisco ASA 5550 ASA version 9.1.7.32&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Connection Profile= RemoteUsers&amp;nbsp; GroupPolicy_RemoteUsers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Running Config&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;FONT&gt;=~=~=~=~=~=~=~=~=~=~=~= PuTTY log 2019.04.01 16:16:39 =~=~=~=~=~=~=~=~=~=~=~=&lt;BR /&gt;show run&lt;BR /&gt;: Saved&lt;BR /&gt;:&lt;BR /&gt;: Serial Number:xxxxxxxxxxxxxxxx&lt;BR /&gt;: Hardware:&amp;nbsp;&amp;nbsp; ASA5550, 4096 MB RAM, CPU Pentium 4 3000 MHz&lt;BR /&gt;:&lt;BR /&gt;ASA Version 9.1(7)32&lt;BR /&gt;!&lt;BR /&gt;hostname tconnect&lt;BR /&gt;domain-name tc.inet&lt;BR /&gt;enable password xxxxxxxxxx encrypted&lt;BR /&gt;names&lt;BR /&gt;ip local pool VPN_Pool1 172.25.224.1-172.25.225.254 mask 255.255.254.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/0&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt;&amp;nbsp;nameif inside&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 172..xx.xx.xx 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/2&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/3&lt;BR /&gt;&amp;nbsp;nameif outside&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address 10.254.xx.xx 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Management0/0&lt;BR /&gt;&amp;nbsp;management-only&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/0&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/2&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/3&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;boot system disk0:/asa917-32-k8.bin&lt;BR /&gt;boot system disk0:/asa917-23-k8.bin&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone CST -6&lt;BR /&gt;clock summer-time CDT recurring&lt;BR /&gt;dns domain-lookup inside&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;name-server 172.xx.xx.xx&lt;BR /&gt;&amp;nbsp;name-server 172.xx.xx.xx&lt;BR /&gt;&amp;nbsp;domain-name tc.inet&lt;BR /&gt;object network NETWORK_OBJ_172.25.224.0_23&lt;BR /&gt;&amp;nbsp;subnet 172.25.224.0 255.255.254.0&lt;BR /&gt;object-group network DM_INLINE_NETWORK_1&lt;BR /&gt;&amp;nbsp;network-object 172.xx.xx.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object object NETWORK_OBJ_172.25.224.0_23&lt;BR /&gt;object-group service DM_INLINE_TCP_1 tcp&lt;BR /&gt;&amp;nbsp;port-object eq www&lt;BR /&gt;&amp;nbsp;port-object eq https&lt;BR /&gt;access-list inside_access_in extended permit ip object-group DM_INLINE_NETWORK_1 any&lt;BR /&gt;access-list inside_access_in extended permit tcp any any object-group DM_INLINE_TCP_1&lt;BR /&gt;access-list outside_access_in extended deny ip any any&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended deny ip any4 any4&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended permit tcp any4 any4 eq lpd&lt;BR /&gt;access-list AnyConnect_Client_Local_Print remark IPP: Internet Printing Protocol&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended permit tcp any4 any4 eq 631&lt;BR /&gt;access-list AnyConnect_Client_Local_Print remark Windows' printing port&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended permit tcp any4 any4 eq 9100&lt;BR /&gt;access-list AnyConnect_Client_Local_Print remark mDNS: multicast DNS protocol&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended permit udp any4 host 224.0.0.251 eq 5353&lt;BR /&gt;access-list AnyConnect_Client_Local_Print remark LLMNR: Link Local Multicast Name Resolution protocol&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended permit udp any4 host 224.0.0.252 eq 5355&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;access-list AnyConnect_Client_Local_Print remark TCP/NetBIOS protocol&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended permit tcp any4 any4 eq 137&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended permit udp any4 any4 eq netbios-ns&lt;BR /&gt;access-list Allowed_External webtype permit url http://* log debugging interval 300&lt;BR /&gt;access-list Allowed_External webtype permit url https://* log debugging interval 300&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;logging list VPN-USER-DISCONNECT message 746012&lt;BR /&gt;logging list VPN-USER-DISCONNECT message 722051&lt;BR /&gt;logging list VPN-USER-DISCONNECT message 746013&lt;BR /&gt;logging list VPN-USER-DISCONNECT message 113019&lt;BR /&gt;logging list VPN-USER-DISCONNECT message 716038&lt;BR /&gt;logging list VPN-USER-DISCONNECT message 716001&lt;BR /&gt;logging list VPN-USER-DISCONNECT message 611101&lt;BR /&gt;logging list VPN-USER-DISCONNECT message 716039&lt;BR /&gt;logging list VPN-USER-DISCONNECT message 716052&lt;BR /&gt;logging list VPN-USER-DISCONNECT message 716023&lt;BR /&gt;logging list VPN-USER-DISCONNECT message 716002&lt;BR /&gt;logging list VPN-USER-DISCONNECT message 716058&lt;BR /&gt;logging list VPN-USER-DISCONNECT message 716059&lt;BR /&gt;logging list VPN-USER-DISCONNECT message 716060&lt;BR /&gt;logging console critical&lt;BR /&gt;logging trap VPN-USER-DISCONNECT&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;logging asdm VPN-USER-DISCONNECT&lt;BR /&gt;logging host inside 172.xx.xx.xx&lt;BR /&gt;logging permit-hostdown&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;no failover&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-7121.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;no arp permit-nonconnected&lt;BR /&gt;nat (inside,outside) source static any any destination static NETWORK_OBJ_172.25.224.0_23 NETWORK_OBJ_172.25.224.0_23 no-proxy-arp route-lookup&lt;BR /&gt;access-group inside_access_in in interface inside&lt;BR /&gt;access-group outside_access_in in interface outside&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 10.254.254.1 1&lt;BR /&gt;route inside 10.0.0.0 255.0.0.0 172.xx.xxx.1 1&lt;BR /&gt;route inside 172.16.0.0 255.240.0.0 172.xx.xxx.1 1&lt;BR /&gt;route inside 172.xx.xxx.0 255.255.255.0 172.xx.xxx.1 1&lt;BR /&gt;route inside 192.168.0.0 255.255.0.0 172.xx.xxx.1 1&lt;BR /&gt;route inside 0.0.0.0 0.0.0.0 172.xx.xxx.1 tunneled&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout pat-xlate 0:00:30&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;&amp;nbsp;webvpn&lt;BR /&gt;&amp;nbsp; appl-acl Allowed_External&lt;BR /&gt;&amp;nbsp; url-list value CompassOnly&lt;BR /&gt;&amp;nbsp; file-browsing disable&lt;BR /&gt;&amp;nbsp; file-entry disable&lt;BR /&gt;&amp;nbsp; url-entry disable&lt;BR /&gt;&amp;nbsp; svc ask none default webvpn&lt;BR /&gt;aaa-server TC_Radius protocol radius&lt;BR /&gt;&amp;nbsp;reactivation-mode timed&lt;BR /&gt;aaa-server TC_Radius (inside) host 172.xx.x.128&lt;BR /&gt;&amp;nbsp;key xxxx&lt;BR /&gt;&amp;nbsp;authentication-port 1812&lt;BR /&gt;&amp;nbsp;accounting-port 1813&lt;BR /&gt;&amp;nbsp;radius-common-pw xxxx&lt;BR /&gt;&amp;nbsp;no mschapv2-capable&lt;BR /&gt;aaa-server TC_Radius (inside) host 172.xx.x.129&lt;BR /&gt;&amp;nbsp;key xxxx&lt;BR /&gt;&amp;nbsp;authentication-port 1812&lt;BR /&gt;&amp;nbsp;accounting-port 1813&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;radius-common-pw xxxx&lt;BR /&gt;aaa-server SecureAuth_Radiu protocol radius&lt;BR /&gt;aaa-server SecureAuth_Radiu (inside) host 172.xx.x.163&lt;BR /&gt;&amp;nbsp;timeout 60&lt;BR /&gt;&amp;nbsp;key xxxx&lt;BR /&gt;&amp;nbsp;authentication-port 1812&lt;BR /&gt;&amp;nbsp;accounting-port 1813&lt;BR /&gt;&amp;nbsp;radius-common-pw xxxx&lt;BR /&gt;&amp;nbsp;no mschapv2-capable&lt;BR /&gt;aaa-server SA_OATH protocol radius&lt;BR /&gt;aaa-server SA_OATH (inside) host 172.xx.x.164&lt;BR /&gt;&amp;nbsp;timeout 60&lt;BR /&gt;&amp;nbsp;key xxxx&lt;BR /&gt;&amp;nbsp;authentication-port 1812&lt;BR /&gt;&amp;nbsp;accounting-port 1813&lt;BR /&gt;&amp;nbsp;radius-common-pw xxxx&lt;BR /&gt;&amp;nbsp;no mschapv2-capable&lt;BR /&gt;aaa-server SecureAuth_New protocol radius&lt;BR /&gt;aaa-server SecureAuth_New (inside) host 172.xx.x.54&lt;BR /&gt;&amp;nbsp;timeout 60&lt;BR /&gt;&amp;nbsp;key xxxx&lt;BR /&gt;&amp;nbsp;authentication-port 1812&lt;BR /&gt;&amp;nbsp;accounting-port 1813&lt;BR /&gt;&amp;nbsp;radius-common-pw xxxx&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;no mschapv2-capable&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;eou allow none&lt;BR /&gt;aaa authentication enable console LOCAL&lt;BR /&gt;aaa authentication http console LOCAL&lt;BR /&gt;aaa authentication ssh console LOCAL&lt;BR /&gt;http server enable&lt;BR /&gt;http 172.xx.xxx.0 255.255.255.0 inside&lt;BR /&gt;http redirect outside 80&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal DES&lt;BR /&gt;&amp;nbsp;protocol esp encryption des&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal 3DES&lt;BR /&gt;&amp;nbsp;protocol esp encryption 3des&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES&lt;BR /&gt;&amp;nbsp;protocol esp encryption aes&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES192&lt;BR /&gt;&amp;nbsp;protocol esp encryption aes-192&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES256&lt;BR /&gt;&amp;nbsp;protocol esp encryption aes-256&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec security-association pmtu-aging infinite&lt;BR /&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set ikev2 ipsec-proposal AES256 AES192 AES 3DES DES&lt;BR /&gt;crypto map outside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;BR /&gt;crypto map outside_map interface outside&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint0&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint1&lt;BR /&gt;&amp;nbsp;enrollment terminal&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint2&lt;BR /&gt;&amp;nbsp;keypair ASDM_TrustPoint2&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint3&lt;BR /&gt;&amp;nbsp;enrollment terminal&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint4&lt;BR /&gt;&amp;nbsp;enrollment terminal&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint5&lt;BR /&gt;&amp;nbsp;enrollment terminal&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint6&lt;BR /&gt;&amp;nbsp;enrollment terminal&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint7&lt;BR /&gt;&amp;nbsp;keypair ASDM_TrustPoint7&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint8&lt;BR /&gt;&amp;nbsp;enrollment terminal&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint9&lt;BR /&gt;&amp;nbsp;enrollment terminal&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;crypto ca trustpool policy&lt;BR /&gt;crypto ca certificate chain ASDM_TrustPoint2&lt;BR /&gt;&amp;nbsp;certificate 2f&lt;BR /&gt;&amp;nbsp; quit&lt;BR /&gt;crypto ca certificate chain ASDM_TrustPoint3&lt;BR /&gt;&amp;nbsp;certificate ca 15a&lt;BR /&gt;&amp;nbsp; quit&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;crypto ca certificate chain ASDM_TrustPoint4&lt;BR /&gt;&amp;nbsp;certificate ca 02&lt;BR /&gt;&amp;nbsp; quit&lt;BR /&gt;crypto ca certificate chain ASDM_TrustPoint5&lt;BR /&gt;&amp;nbsp;certificate ca 1f3&lt;BR /&gt;&amp;nbsp; quit&lt;BR /&gt;crypto ca certificate chain ASDM_TrustPoint6&lt;BR /&gt;&amp;nbsp;certificate ca 4b&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp; quit&lt;BR /&gt;crypto ca certificate chain ASDM_TrustPoint7&lt;BR /&gt;&amp;nbsp;certificate 0e&lt;BR /&gt;&amp;nbsp; quit&lt;BR /&gt;crypto ca certificate chain ASDM_TrustPoint8&lt;BR /&gt;&amp;nbsp;certificate ca 03&lt;BR /&gt;&amp;nbsp; quit&lt;BR /&gt;crypto ca certificate chain ASDM_TrustPoint9&lt;BR /&gt;&amp;nbsp;certificate ca 0d&lt;BR /&gt;&amp;nbsp; quit&lt;BR /&gt;crypto ikev2 policy 1&lt;BR /&gt;&amp;nbsp;encryption aes-256&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;crypto ikev2 policy 10&lt;BR /&gt;&amp;nbsp;encryption aes-192&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 20&lt;BR /&gt;&amp;nbsp;encryption aes&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 30&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 40&lt;BR /&gt;&amp;nbsp;encryption des&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;crypto ikev2 enable outside client-services port 443&lt;BR /&gt;crypto ikev2 remote-access trustpoint ASDM_TrustPoint2&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh stricthostkeycheck&lt;BR /&gt;ssh 172.xx.xxx.0 255.255.255.0 inside&lt;BR /&gt;ssh timeout 10&lt;BR /&gt;ssh version 2&lt;BR /&gt;ssh key-exchange group dh-group1-sha1&lt;BR /&gt;console timeout 10&lt;BR /&gt;vpn-sessiondb max-other-vpn-limit 5000&lt;BR /&gt;vpn-sessiondb max-anyconnect-premium-or-essentials-limit 5000&lt;BR /&gt;!&lt;BR /&gt;tls-proxy maximum-session 1000&lt;BR /&gt;!&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;ntp server 10.xx.xxx.xx source inside&lt;BR /&gt;ssl encryption dhe-aes128-sha1 dhe-aes256-sha1 aes128-sha1 aes256-sha1 3des-sha1&lt;BR /&gt;ssl trust-point ASDM_TrustPoint7 outside&lt;BR /&gt;webvpn&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;enable outside&lt;BR /&gt;&amp;nbsp;csd image disk0:/csd_3.5.2008-k9.pkg&lt;BR /&gt;&amp;nbsp;csd hostscan image disk0:/hostscan_4.2.02075-k9.pkg&lt;BR /&gt;&amp;nbsp;anyconnect image disk0:/anyconnect-win-4.2.02075-k9.pkg 1&lt;BR /&gt;&amp;nbsp;anyconnect image disk0:/anyconnect-macosx-i386-4.2.02075-k9.pkg 2&lt;BR /&gt;&amp;nbsp;anyconnect profiles RemoteUsers_client_profile disk0:/RemoteUsers_client_profile.xml&lt;BR /&gt;&amp;nbsp;anyconnect enable&lt;BR /&gt;&amp;nbsp;tunnel-group-list enable&lt;BR /&gt;&amp;nbsp;smart-tunnel list Taylor_Tubes RDP mstsc.exe platform windows&lt;BR /&gt;&amp;nbsp;smart-tunnel list Taylor_Tubes IE iexplore.exe platform windows&lt;BR /&gt;&amp;nbsp;smart-tunnel list Taylor_Tubes Firefox Firefox.exe platform windows&lt;BR /&gt;&amp;nbsp;smart-tunnel list Taylor_Tubes Chrome_browser chrome.exe platform windows&lt;BR /&gt;&amp;nbsp;smart-tunnel list Taylor_Tubes Safari /Applications/Safari platform mac&lt;BR /&gt;&amp;nbsp;smart-tunnel list Taylor_Tubes Outlook outlook.exe platform windows&lt;BR /&gt;&amp;nbsp;cache&lt;BR /&gt;&amp;nbsp; disable&lt;BR /&gt;&amp;nbsp;error-recovery disable&lt;BR /&gt;group-policy DfltGrpPolicy attributes&lt;BR /&gt;&amp;nbsp;wins-server value 172.xx.xxx.xx&lt;BR /&gt;&amp;nbsp;dns-server value 172.xx.xxx.xx&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1 ikev2 l2tp-ipsec ssl-client ssl-clientless&lt;BR /&gt;&amp;nbsp;default-domain value xxx.xxx.inet&lt;BR /&gt;&amp;nbsp;webvpn&lt;BR /&gt;&amp;nbsp; anyconnect ask enable default webvpn timeout 10&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp; auto-signon allow uri * auth-type ntlm&lt;BR /&gt;group-policy GroupPolicy_RemoteUsers internal&lt;BR /&gt;group-policy GroupPolicy_RemoteUsers attributes&lt;BR /&gt;&amp;nbsp;wins-server value 172.xx.xxx.xx&lt;BR /&gt;&amp;nbsp;dns-server value 172.xx.xxx.xx&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ssl-client ssl-clientless&lt;BR /&gt;&amp;nbsp;default-domain value corp.tcc.inet&lt;BR /&gt;&amp;nbsp;webvpn&lt;BR /&gt;&amp;nbsp; url-list value Applications&amp;amp;Links&lt;BR /&gt;&amp;nbsp; filter value Allowed_External&lt;BR /&gt;&amp;nbsp; anyconnect profiles value RemoteUsers_client_profile type user&lt;BR /&gt;&amp;nbsp; smart-tunnel enable Taylor_Tubes&lt;BR /&gt;username gnsadmin password xxxxxxxxxx encrypted privilege 15&lt;BR /&gt;username gnsadmin attributes&lt;BR /&gt;&amp;nbsp;password-storage disable&lt;BR /&gt;tunnel-group RemoteUsers type remote-access&lt;BR /&gt;tunnel-group RemoteUsers general-attributes&lt;BR /&gt;&amp;nbsp;address-pool VPN_Pool1&lt;BR /&gt;&amp;nbsp;authentication-server-group TC_Radius&lt;BR /&gt;&amp;nbsp;authorization-server-group TC_Radius&lt;BR /&gt;&amp;nbsp;default-group-policy GroupPolicy_RemoteUsers&lt;BR /&gt;tunnel-group RemoteUsers webvpn-attributes&lt;BR /&gt;&amp;nbsp;group-alias Compass enable&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;group-alias RemoteUsers disable&lt;BR /&gt;&amp;nbsp;group-url &lt;A href="http://newcompass.tc.inet" target="_blank" rel="noopener"&gt;http://newcompass.tc.inet&lt;/A&gt; enable&lt;BR /&gt;&amp;nbsp;without-csd&lt;BR /&gt;tunnel-group RemoteUsers ipsec-attributes&lt;BR /&gt;&amp;nbsp;ikev1 trust-point ASDM_TrustPoint2&lt;BR /&gt;tunnel-group WebVPN_Prof type remote-access&lt;BR /&gt;tunnel-group WebVPN_Prof general-attributes&lt;BR /&gt;&amp;nbsp;authentication-server-group TC_Radius&lt;BR /&gt;&amp;nbsp;default-group-policy GroupPolicy_RemoteUsers&lt;BR /&gt;!&lt;BR /&gt;class-map global-class&lt;BR /&gt;&amp;nbsp;match default-inspection-traffic&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;&amp;nbsp;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp;parameters&lt;BR /&gt;&amp;nbsp; message-length maximum client auto&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp; inspect ftp&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect h323 h225&lt;BR /&gt;&amp;nbsp; inspect h323 ras&lt;BR /&gt;&amp;nbsp; inspect rsh&lt;BR /&gt;&amp;nbsp; inspect rtsp&lt;BR /&gt;&amp;nbsp; inspect esmtp&lt;BR /&gt;&amp;nbsp; inspect sqlnet&lt;BR /&gt;&amp;nbsp; inspect skinny&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sunrpc&lt;BR /&gt;&amp;nbsp; inspect xdmcp&lt;BR /&gt;&amp;nbsp; inspect sip&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect netbios&lt;BR /&gt;&amp;nbsp; inspect tftp&lt;BR /&gt;&amp;nbsp; inspect ip-options&lt;BR /&gt;policy-map global-policy&lt;BR /&gt;&amp;nbsp;class global-class&lt;BR /&gt;&amp;nbsp; inspect icmp&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context&lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;call-home&lt;BR /&gt;&amp;nbsp;profile CiscoTAC-1&lt;BR /&gt;&amp;nbsp; no active&lt;BR /&gt;&amp;nbsp; destination address http &lt;A href="https://tools.cisco.com/its/service/oddce/services/DDCEService" target="_blank" rel="noopener"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp; destination address email callhome@cisco.com&lt;BR /&gt;&amp;nbsp; destination transport-method http&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group diagnostic&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group environment&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group inventory periodic monthly 22&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group configuration periodic monthly 22&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group telemetry periodic daily&lt;BR /&gt;Cryptochecksum:32387d8764fbfd06733995ce6a6dab98&lt;BR /&gt;: end&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT&gt;tconnect# show version&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT&gt;Cisco Adaptive Security Appliance Software Version 9.1(7)32&lt;BR /&gt;Device Manager Version 7.12(1)&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Mon, 01 Apr 2019 21:42:32 GMT</pubDate>
    <dc:creator>srbrandt40</dc:creator>
    <dc:date>2019-04-01T21:42:32Z</dc:date>
    <item>
      <title>WebVPN Clientless SSL VPN to intranet website - links to external sites are not working</title>
      <link>https://community.cisco.com/t5/network-security/webvpn-clientless-ssl-vpn-to-intranet-website-links-to-external/m-p/3830179#M925078</link>
      <description>&lt;P&gt;I have setup WebVPN clientless SSL VPN so our users that are external login and there is a link to our company intranet website. Any of the links that exist on the website or are internal on our LAN/WAN work correctly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My problem is this website has quite a few links that are external such as company videos hosted on YouTube and websites hosted outside by third parties.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I click on one of these links I get : Connection Failed Server "url" unavailable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried different settings and so far none have fixed this issue.&lt;/P&gt;&lt;P&gt;Group Policy : General - Web ACL - Allowed_External &amp;nbsp; Permit any url&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What am I missing to make this work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:59:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/webvpn-clientless-ssl-vpn-to-intranet-website-links-to-external/m-p/3830179#M925078</guid>
      <dc:creator>srbrandt40</dc:creator>
      <dc:date>2020-02-21T16:59:52Z</dc:date>
    </item>
    <item>
      <title>Re: WebVPN Clientless SSL VPN to intranet website - links to external sites are not working</title>
      <link>https://community.cisco.com/t5/network-security/webvpn-clientless-ssl-vpn-to-intranet-website-links-to-external/m-p/3830213#M925092</link>
      <description>&lt;P&gt;Not sure what device you have configured for Web VPN, ( i was assuming you configured ASA)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;please refer below reference guide(and post the running config to have look)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security-vpn/webvpn-ssl-vpn/119417-config-asa-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security-vpn/webvpn-ssl-vpn/119417-config-asa-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2019 20:32:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/webvpn-clientless-ssl-vpn-to-intranet-website-links-to-external/m-p/3830213#M925092</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-04-01T20:32:51Z</dc:date>
    </item>
    <item>
      <title>Re: WebVPN Clientless SSL VPN to intranet website - links to external sites are not working</title>
      <link>https://community.cisco.com/t5/network-security/webvpn-clientless-ssl-vpn-to-intranet-website-links-to-external/m-p/3830245#M925102</link>
      <description>&lt;P&gt;Yes this is setup on a Cisco ASA 5550 ASA version 9.1.7.32&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Connection Profile= RemoteUsers&amp;nbsp; GroupPolicy_RemoteUsers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Running Config&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;FONT&gt;=~=~=~=~=~=~=~=~=~=~=~= PuTTY log 2019.04.01 16:16:39 =~=~=~=~=~=~=~=~=~=~=~=&lt;BR /&gt;show run&lt;BR /&gt;: Saved&lt;BR /&gt;:&lt;BR /&gt;: Serial Number:xxxxxxxxxxxxxxxx&lt;BR /&gt;: Hardware:&amp;nbsp;&amp;nbsp; ASA5550, 4096 MB RAM, CPU Pentium 4 3000 MHz&lt;BR /&gt;:&lt;BR /&gt;ASA Version 9.1(7)32&lt;BR /&gt;!&lt;BR /&gt;hostname tconnect&lt;BR /&gt;domain-name tc.inet&lt;BR /&gt;enable password xxxxxxxxxx encrypted&lt;BR /&gt;names&lt;BR /&gt;ip local pool VPN_Pool1 172.25.224.1-172.25.225.254 mask 255.255.254.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/0&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt;&amp;nbsp;nameif inside&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 172..xx.xx.xx 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/2&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/3&lt;BR /&gt;&amp;nbsp;nameif outside&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address 10.254.xx.xx 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Management0/0&lt;BR /&gt;&amp;nbsp;management-only&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/0&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/2&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/3&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;boot system disk0:/asa917-32-k8.bin&lt;BR /&gt;boot system disk0:/asa917-23-k8.bin&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone CST -6&lt;BR /&gt;clock summer-time CDT recurring&lt;BR /&gt;dns domain-lookup inside&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;name-server 172.xx.xx.xx&lt;BR /&gt;&amp;nbsp;name-server 172.xx.xx.xx&lt;BR /&gt;&amp;nbsp;domain-name tc.inet&lt;BR /&gt;object network NETWORK_OBJ_172.25.224.0_23&lt;BR /&gt;&amp;nbsp;subnet 172.25.224.0 255.255.254.0&lt;BR /&gt;object-group network DM_INLINE_NETWORK_1&lt;BR /&gt;&amp;nbsp;network-object 172.xx.xx.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object object NETWORK_OBJ_172.25.224.0_23&lt;BR /&gt;object-group service DM_INLINE_TCP_1 tcp&lt;BR /&gt;&amp;nbsp;port-object eq www&lt;BR /&gt;&amp;nbsp;port-object eq https&lt;BR /&gt;access-list inside_access_in extended permit ip object-group DM_INLINE_NETWORK_1 any&lt;BR /&gt;access-list inside_access_in extended permit tcp any any object-group DM_INLINE_TCP_1&lt;BR /&gt;access-list outside_access_in extended deny ip any any&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended deny ip any4 any4&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended permit tcp any4 any4 eq lpd&lt;BR /&gt;access-list AnyConnect_Client_Local_Print remark IPP: Internet Printing Protocol&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended permit tcp any4 any4 eq 631&lt;BR /&gt;access-list AnyConnect_Client_Local_Print remark Windows' printing port&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended permit tcp any4 any4 eq 9100&lt;BR /&gt;access-list AnyConnect_Client_Local_Print remark mDNS: multicast DNS protocol&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended permit udp any4 host 224.0.0.251 eq 5353&lt;BR /&gt;access-list AnyConnect_Client_Local_Print remark LLMNR: Link Local Multicast Name Resolution protocol&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended permit udp any4 host 224.0.0.252 eq 5355&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;access-list AnyConnect_Client_Local_Print remark TCP/NetBIOS protocol&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended permit tcp any4 any4 eq 137&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended permit udp any4 any4 eq netbios-ns&lt;BR /&gt;access-list Allowed_External webtype permit url http://* log debugging interval 300&lt;BR /&gt;access-list Allowed_External webtype permit url https://* log debugging interval 300&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;logging list VPN-USER-DISCONNECT message 746012&lt;BR /&gt;logging list VPN-USER-DISCONNECT message 722051&lt;BR /&gt;logging list VPN-USER-DISCONNECT message 746013&lt;BR /&gt;logging list VPN-USER-DISCONNECT message 113019&lt;BR /&gt;logging list VPN-USER-DISCONNECT message 716038&lt;BR /&gt;logging list VPN-USER-DISCONNECT message 716001&lt;BR /&gt;logging list VPN-USER-DISCONNECT message 611101&lt;BR /&gt;logging list VPN-USER-DISCONNECT message 716039&lt;BR /&gt;logging list VPN-USER-DISCONNECT message 716052&lt;BR /&gt;logging list VPN-USER-DISCONNECT message 716023&lt;BR /&gt;logging list VPN-USER-DISCONNECT message 716002&lt;BR /&gt;logging list VPN-USER-DISCONNECT message 716058&lt;BR /&gt;logging list VPN-USER-DISCONNECT message 716059&lt;BR /&gt;logging list VPN-USER-DISCONNECT message 716060&lt;BR /&gt;logging console critical&lt;BR /&gt;logging trap VPN-USER-DISCONNECT&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;logging asdm VPN-USER-DISCONNECT&lt;BR /&gt;logging host inside 172.xx.xx.xx&lt;BR /&gt;logging permit-hostdown&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;no failover&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-7121.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;no arp permit-nonconnected&lt;BR /&gt;nat (inside,outside) source static any any destination static NETWORK_OBJ_172.25.224.0_23 NETWORK_OBJ_172.25.224.0_23 no-proxy-arp route-lookup&lt;BR /&gt;access-group inside_access_in in interface inside&lt;BR /&gt;access-group outside_access_in in interface outside&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 10.254.254.1 1&lt;BR /&gt;route inside 10.0.0.0 255.0.0.0 172.xx.xxx.1 1&lt;BR /&gt;route inside 172.16.0.0 255.240.0.0 172.xx.xxx.1 1&lt;BR /&gt;route inside 172.xx.xxx.0 255.255.255.0 172.xx.xxx.1 1&lt;BR /&gt;route inside 192.168.0.0 255.255.0.0 172.xx.xxx.1 1&lt;BR /&gt;route inside 0.0.0.0 0.0.0.0 172.xx.xxx.1 tunneled&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout pat-xlate 0:00:30&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;&amp;nbsp;webvpn&lt;BR /&gt;&amp;nbsp; appl-acl Allowed_External&lt;BR /&gt;&amp;nbsp; url-list value CompassOnly&lt;BR /&gt;&amp;nbsp; file-browsing disable&lt;BR /&gt;&amp;nbsp; file-entry disable&lt;BR /&gt;&amp;nbsp; url-entry disable&lt;BR /&gt;&amp;nbsp; svc ask none default webvpn&lt;BR /&gt;aaa-server TC_Radius protocol radius&lt;BR /&gt;&amp;nbsp;reactivation-mode timed&lt;BR /&gt;aaa-server TC_Radius (inside) host 172.xx.x.128&lt;BR /&gt;&amp;nbsp;key xxxx&lt;BR /&gt;&amp;nbsp;authentication-port 1812&lt;BR /&gt;&amp;nbsp;accounting-port 1813&lt;BR /&gt;&amp;nbsp;radius-common-pw xxxx&lt;BR /&gt;&amp;nbsp;no mschapv2-capable&lt;BR /&gt;aaa-server TC_Radius (inside) host 172.xx.x.129&lt;BR /&gt;&amp;nbsp;key xxxx&lt;BR /&gt;&amp;nbsp;authentication-port 1812&lt;BR /&gt;&amp;nbsp;accounting-port 1813&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;radius-common-pw xxxx&lt;BR /&gt;aaa-server SecureAuth_Radiu protocol radius&lt;BR /&gt;aaa-server SecureAuth_Radiu (inside) host 172.xx.x.163&lt;BR /&gt;&amp;nbsp;timeout 60&lt;BR /&gt;&amp;nbsp;key xxxx&lt;BR /&gt;&amp;nbsp;authentication-port 1812&lt;BR /&gt;&amp;nbsp;accounting-port 1813&lt;BR /&gt;&amp;nbsp;radius-common-pw xxxx&lt;BR /&gt;&amp;nbsp;no mschapv2-capable&lt;BR /&gt;aaa-server SA_OATH protocol radius&lt;BR /&gt;aaa-server SA_OATH (inside) host 172.xx.x.164&lt;BR /&gt;&amp;nbsp;timeout 60&lt;BR /&gt;&amp;nbsp;key xxxx&lt;BR /&gt;&amp;nbsp;authentication-port 1812&lt;BR /&gt;&amp;nbsp;accounting-port 1813&lt;BR /&gt;&amp;nbsp;radius-common-pw xxxx&lt;BR /&gt;&amp;nbsp;no mschapv2-capable&lt;BR /&gt;aaa-server SecureAuth_New protocol radius&lt;BR /&gt;aaa-server SecureAuth_New (inside) host 172.xx.x.54&lt;BR /&gt;&amp;nbsp;timeout 60&lt;BR /&gt;&amp;nbsp;key xxxx&lt;BR /&gt;&amp;nbsp;authentication-port 1812&lt;BR /&gt;&amp;nbsp;accounting-port 1813&lt;BR /&gt;&amp;nbsp;radius-common-pw xxxx&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;no mschapv2-capable&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;eou allow none&lt;BR /&gt;aaa authentication enable console LOCAL&lt;BR /&gt;aaa authentication http console LOCAL&lt;BR /&gt;aaa authentication ssh console LOCAL&lt;BR /&gt;http server enable&lt;BR /&gt;http 172.xx.xxx.0 255.255.255.0 inside&lt;BR /&gt;http redirect outside 80&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal DES&lt;BR /&gt;&amp;nbsp;protocol esp encryption des&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal 3DES&lt;BR /&gt;&amp;nbsp;protocol esp encryption 3des&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES&lt;BR /&gt;&amp;nbsp;protocol esp encryption aes&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES192&lt;BR /&gt;&amp;nbsp;protocol esp encryption aes-192&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES256&lt;BR /&gt;&amp;nbsp;protocol esp encryption aes-256&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec security-association pmtu-aging infinite&lt;BR /&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set ikev2 ipsec-proposal AES256 AES192 AES 3DES DES&lt;BR /&gt;crypto map outside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;BR /&gt;crypto map outside_map interface outside&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint0&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint1&lt;BR /&gt;&amp;nbsp;enrollment terminal&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint2&lt;BR /&gt;&amp;nbsp;keypair ASDM_TrustPoint2&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint3&lt;BR /&gt;&amp;nbsp;enrollment terminal&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint4&lt;BR /&gt;&amp;nbsp;enrollment terminal&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint5&lt;BR /&gt;&amp;nbsp;enrollment terminal&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint6&lt;BR /&gt;&amp;nbsp;enrollment terminal&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint7&lt;BR /&gt;&amp;nbsp;keypair ASDM_TrustPoint7&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint8&lt;BR /&gt;&amp;nbsp;enrollment terminal&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint9&lt;BR /&gt;&amp;nbsp;enrollment terminal&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;crypto ca trustpool policy&lt;BR /&gt;crypto ca certificate chain ASDM_TrustPoint2&lt;BR /&gt;&amp;nbsp;certificate 2f&lt;BR /&gt;&amp;nbsp; quit&lt;BR /&gt;crypto ca certificate chain ASDM_TrustPoint3&lt;BR /&gt;&amp;nbsp;certificate ca 15a&lt;BR /&gt;&amp;nbsp; quit&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;crypto ca certificate chain ASDM_TrustPoint4&lt;BR /&gt;&amp;nbsp;certificate ca 02&lt;BR /&gt;&amp;nbsp; quit&lt;BR /&gt;crypto ca certificate chain ASDM_TrustPoint5&lt;BR /&gt;&amp;nbsp;certificate ca 1f3&lt;BR /&gt;&amp;nbsp; quit&lt;BR /&gt;crypto ca certificate chain ASDM_TrustPoint6&lt;BR /&gt;&amp;nbsp;certificate ca 4b&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp; quit&lt;BR /&gt;crypto ca certificate chain ASDM_TrustPoint7&lt;BR /&gt;&amp;nbsp;certificate 0e&lt;BR /&gt;&amp;nbsp; quit&lt;BR /&gt;crypto ca certificate chain ASDM_TrustPoint8&lt;BR /&gt;&amp;nbsp;certificate ca 03&lt;BR /&gt;&amp;nbsp; quit&lt;BR /&gt;crypto ca certificate chain ASDM_TrustPoint9&lt;BR /&gt;&amp;nbsp;certificate ca 0d&lt;BR /&gt;&amp;nbsp; quit&lt;BR /&gt;crypto ikev2 policy 1&lt;BR /&gt;&amp;nbsp;encryption aes-256&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;crypto ikev2 policy 10&lt;BR /&gt;&amp;nbsp;encryption aes-192&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 20&lt;BR /&gt;&amp;nbsp;encryption aes&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 30&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 40&lt;BR /&gt;&amp;nbsp;encryption des&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;crypto ikev2 enable outside client-services port 443&lt;BR /&gt;crypto ikev2 remote-access trustpoint ASDM_TrustPoint2&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh stricthostkeycheck&lt;BR /&gt;ssh 172.xx.xxx.0 255.255.255.0 inside&lt;BR /&gt;ssh timeout 10&lt;BR /&gt;ssh version 2&lt;BR /&gt;ssh key-exchange group dh-group1-sha1&lt;BR /&gt;console timeout 10&lt;BR /&gt;vpn-sessiondb max-other-vpn-limit 5000&lt;BR /&gt;vpn-sessiondb max-anyconnect-premium-or-essentials-limit 5000&lt;BR /&gt;!&lt;BR /&gt;tls-proxy maximum-session 1000&lt;BR /&gt;!&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;ntp server 10.xx.xxx.xx source inside&lt;BR /&gt;ssl encryption dhe-aes128-sha1 dhe-aes256-sha1 aes128-sha1 aes256-sha1 3des-sha1&lt;BR /&gt;ssl trust-point ASDM_TrustPoint7 outside&lt;BR /&gt;webvpn&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;enable outside&lt;BR /&gt;&amp;nbsp;csd image disk0:/csd_3.5.2008-k9.pkg&lt;BR /&gt;&amp;nbsp;csd hostscan image disk0:/hostscan_4.2.02075-k9.pkg&lt;BR /&gt;&amp;nbsp;anyconnect image disk0:/anyconnect-win-4.2.02075-k9.pkg 1&lt;BR /&gt;&amp;nbsp;anyconnect image disk0:/anyconnect-macosx-i386-4.2.02075-k9.pkg 2&lt;BR /&gt;&amp;nbsp;anyconnect profiles RemoteUsers_client_profile disk0:/RemoteUsers_client_profile.xml&lt;BR /&gt;&amp;nbsp;anyconnect enable&lt;BR /&gt;&amp;nbsp;tunnel-group-list enable&lt;BR /&gt;&amp;nbsp;smart-tunnel list Taylor_Tubes RDP mstsc.exe platform windows&lt;BR /&gt;&amp;nbsp;smart-tunnel list Taylor_Tubes IE iexplore.exe platform windows&lt;BR /&gt;&amp;nbsp;smart-tunnel list Taylor_Tubes Firefox Firefox.exe platform windows&lt;BR /&gt;&amp;nbsp;smart-tunnel list Taylor_Tubes Chrome_browser chrome.exe platform windows&lt;BR /&gt;&amp;nbsp;smart-tunnel list Taylor_Tubes Safari /Applications/Safari platform mac&lt;BR /&gt;&amp;nbsp;smart-tunnel list Taylor_Tubes Outlook outlook.exe platform windows&lt;BR /&gt;&amp;nbsp;cache&lt;BR /&gt;&amp;nbsp; disable&lt;BR /&gt;&amp;nbsp;error-recovery disable&lt;BR /&gt;group-policy DfltGrpPolicy attributes&lt;BR /&gt;&amp;nbsp;wins-server value 172.xx.xxx.xx&lt;BR /&gt;&amp;nbsp;dns-server value 172.xx.xxx.xx&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1 ikev2 l2tp-ipsec ssl-client ssl-clientless&lt;BR /&gt;&amp;nbsp;default-domain value xxx.xxx.inet&lt;BR /&gt;&amp;nbsp;webvpn&lt;BR /&gt;&amp;nbsp; anyconnect ask enable default webvpn timeout 10&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp; auto-signon allow uri * auth-type ntlm&lt;BR /&gt;group-policy GroupPolicy_RemoteUsers internal&lt;BR /&gt;group-policy GroupPolicy_RemoteUsers attributes&lt;BR /&gt;&amp;nbsp;wins-server value 172.xx.xxx.xx&lt;BR /&gt;&amp;nbsp;dns-server value 172.xx.xxx.xx&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ssl-client ssl-clientless&lt;BR /&gt;&amp;nbsp;default-domain value corp.tcc.inet&lt;BR /&gt;&amp;nbsp;webvpn&lt;BR /&gt;&amp;nbsp; url-list value Applications&amp;amp;Links&lt;BR /&gt;&amp;nbsp; filter value Allowed_External&lt;BR /&gt;&amp;nbsp; anyconnect profiles value RemoteUsers_client_profile type user&lt;BR /&gt;&amp;nbsp; smart-tunnel enable Taylor_Tubes&lt;BR /&gt;username gnsadmin password xxxxxxxxxx encrypted privilege 15&lt;BR /&gt;username gnsadmin attributes&lt;BR /&gt;&amp;nbsp;password-storage disable&lt;BR /&gt;tunnel-group RemoteUsers type remote-access&lt;BR /&gt;tunnel-group RemoteUsers general-attributes&lt;BR /&gt;&amp;nbsp;address-pool VPN_Pool1&lt;BR /&gt;&amp;nbsp;authentication-server-group TC_Radius&lt;BR /&gt;&amp;nbsp;authorization-server-group TC_Radius&lt;BR /&gt;&amp;nbsp;default-group-policy GroupPolicy_RemoteUsers&lt;BR /&gt;tunnel-group RemoteUsers webvpn-attributes&lt;BR /&gt;&amp;nbsp;group-alias Compass enable&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;group-alias RemoteUsers disable&lt;BR /&gt;&amp;nbsp;group-url &lt;A href="http://newcompass.tc.inet" target="_blank" rel="noopener"&gt;http://newcompass.tc.inet&lt;/A&gt; enable&lt;BR /&gt;&amp;nbsp;without-csd&lt;BR /&gt;tunnel-group RemoteUsers ipsec-attributes&lt;BR /&gt;&amp;nbsp;ikev1 trust-point ASDM_TrustPoint2&lt;BR /&gt;tunnel-group WebVPN_Prof type remote-access&lt;BR /&gt;tunnel-group WebVPN_Prof general-attributes&lt;BR /&gt;&amp;nbsp;authentication-server-group TC_Radius&lt;BR /&gt;&amp;nbsp;default-group-policy GroupPolicy_RemoteUsers&lt;BR /&gt;!&lt;BR /&gt;class-map global-class&lt;BR /&gt;&amp;nbsp;match default-inspection-traffic&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;&amp;nbsp;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp;parameters&lt;BR /&gt;&amp;nbsp; message-length maximum client auto&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp; inspect ftp&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect h323 h225&lt;BR /&gt;&amp;nbsp; inspect h323 ras&lt;BR /&gt;&amp;nbsp; inspect rsh&lt;BR /&gt;&amp;nbsp; inspect rtsp&lt;BR /&gt;&amp;nbsp; inspect esmtp&lt;BR /&gt;&amp;nbsp; inspect sqlnet&lt;BR /&gt;&amp;nbsp; inspect skinny&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sunrpc&lt;BR /&gt;&amp;nbsp; inspect xdmcp&lt;BR /&gt;&amp;nbsp; inspect sip&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect netbios&lt;BR /&gt;&amp;nbsp; inspect tftp&lt;BR /&gt;&amp;nbsp; inspect ip-options&lt;BR /&gt;policy-map global-policy&lt;BR /&gt;&amp;nbsp;class global-class&lt;BR /&gt;&amp;nbsp; inspect icmp&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context&lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;call-home&lt;BR /&gt;&amp;nbsp;profile CiscoTAC-1&lt;BR /&gt;&amp;nbsp; no active&lt;BR /&gt;&amp;nbsp; destination address http &lt;A href="https://tools.cisco.com/its/service/oddce/services/DDCEService" target="_blank" rel="noopener"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp; destination address email callhome@cisco.com&lt;BR /&gt;&amp;nbsp; destination transport-method http&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group diagnostic&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group environment&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group inventory periodic monthly 22&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group configuration periodic monthly 22&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group telemetry periodic daily&lt;BR /&gt;Cryptochecksum:32387d8764fbfd06733995ce6a6dab98&lt;BR /&gt;: end&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT&gt;tconnect# show version&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT&gt;Cisco Adaptive Security Appliance Software Version 9.1(7)32&lt;BR /&gt;Device Manager Version 7.12(1)&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 01 Apr 2019 21:42:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/webvpn-clientless-ssl-vpn-to-intranet-website-links-to-external/m-p/3830245#M925102</guid>
      <dc:creator>srbrandt40</dc:creator>
      <dc:date>2019-04-01T21:42:32Z</dc:date>
    </item>
  </channel>
</rss>

