Cisco ASA - Enable Cisco Secure Desktop or Cache Cleaner Per Profile, Not Globally

Posted on 2010-11-09
Last Modified: 2012-05-10
I'm running a Cisco ASA 5520 8.2(1) for secure VPN access.  We use both AnyConnect and WebVPN.  I am trying to enable either Cisco Secure Desktop or Cache Cleaner for a certain AnyConnect profile, while not applying it to the other profiles.  Is this possible?  Seems to me like it's just a checkbox on or off, and I can't find anything in the group policies to enable or disable for a given policy.  I'm using the ASDM for this (easier for me on things like this than CLI) so if this is possible please describe how to get to it in the ASDM.

Question by:hachemp
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2

Accepted Solution

kellemann earned 500 total points
ID: 34100926
Short answer, yes you can. It's a relatively new command called without-csd

Expert Comment

ID: 34100967
Sorry, forgot about the ASDM part. I am not a big user of ASDM, but I can't find the ASDM equivalent to the the without-csd command.

Author Comment

ID: 34105864
Thanks for the response kellemann.  The only problem I see with this is that it seems to apply specifically to webVPN and then specifically to certain URLs.  I tried using the 'without-csd' command on one of my AnyConnect tunnel-groups and it didn't stop it from using CSD.  Unfortunately, according to the link you sent, 'the group-url command is required for the without-csd command to have an effect.'

Is there another way I should be using this?  I'm not averse to using CLI to do this, just need to know if what I need can be accomplished with this command, and if I'm using it correctly.  

Expert Comment

ID: 34110257
Sorry, that's the only way to create differentiate CSD. See this FAQ:

Author Comment

ID: 34112007
Thanks a lot for the info.  It's unfortunate that they don't provide this yet but you answered my questions accurately.

Featured Post

Connect further...control easier

With the ATEN CE624, you can now enjoy a high-quality visual experience powered by HDBaseT technology and the convenience of a single Cat6 cable to transmit uncompressed video with zero latency and multi-streaming for dual-view applications where remote access is required.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
cisco asa proxy arp 2 27
Port# 500 and 4500 not open by ISP 10 44
TZ400 VPN Clients 5 27
SonicPoint N2 will not provision on SonicWall NSA220 4 18
For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
When speed and performance are vital to revenue, companies must have complete confidence in their cloud environment.
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question