What is the "preferred" way to configure the SSL VPN? Prior to 7 i was told to use "resource policies", but now all the documentation says to use "resource profiles". I remember some conceptual problems that "resource policies" act as ACL's and if used with the merge roles can give confusiing results.
Is this still the case?
Solved! Go to Solution.
Resource profiles is really almost always the preferred method. Regardless of how you configure you always need ACL's.
Profiles are more of a "one step" method in that when using them the bookmark, the role mapping and ACL are created in one set of screens. Using policies you must create your bookmarks seperately.
what muttbarker said.
and they are two very different things: a resource policy is your ACL; a resource profile is the bookmark [that you can add some ACLs to from the same location]
in addition, it really is a matter of preference and your use case. in all events, there are items that can't be configured in resource profiles (or standard bookmarks) that have to be done via resource policies; but the resource profile gives you access to the main ones and you can always get more granular if you want/need on the ACL list directly.
I prefer to use Resource Profiles as it creates any requisite policies. These policies are linked to the Profile. If I need to remove the profile, all the policies are removed. If I need to make a change to the settings, I can do so in one place. As long as all necessary elements are accessible in a Resource Profile I can't thing of a reason to create each element by hand. I do create broad resource policies as my fallback access. That way if a user doesn't match a profile to role mapping they will have limitations on their access or specific required resources.
Resource profiles is really almost always the preferred method. Regardless of how you configure you always need ACL's.
Profiles are more of a "one step" method in that when using them the bookmark, the role mapping and ACL are created in one set of screens. Using policies you must create your bookmarks seperately.