cancel
Showing results for 
Search instead for 
Did you mean: 

What is the "preferred" way to configure the SSL VPN?

SOLVED
pkramer_
New Contributor

What is the "preferred" way to configure the SSL VPN?

What is the "preferred" way to configure the SSL VPN? Prior to 7 i was told to use "resource policies", but now all the documentation says to use "resource profiles". I remember some conceptual problems that "resource policies" act as ACL's and if used with the merge roles can give confusiing results.

 

Is this still the case?

1 ACCEPTED SOLUTION

Accepted Solutions
muttbarker_
Valued Contributor

Re: What is the "preferred" way to configure the SSL VPN?

Resource profiles is really almost always the preferred method. Regardless of how you configure you always need ACL's. 

 

Profiles are more of a "one step" method in that when using them the bookmark, the role mapping and ACL are created in one set of screens. Using policies you must create your bookmarks seperately. 

View solution in original post

3 REPLIES 3
zanyterp_
Respected Contributor

Re: What is the "preferred" way to configure the SSL VPN?

what muttbarker said. Smiley Very Happy

and they are two very different things: a resource policy is your ACL; a resource profile is the bookmark [that you can add some ACLs to from the same location]

in addition, it really is a matter of preference and your use case. in all events, there are items that can't be configured in resource profiles (or standard bookmarks) that have to be done via resource policies; but the resource profile gives you access to the main ones and you can always get more granular if you want/need on the ACL list directly.

mattspierce_
Frequent Contributor

Re: What is the "preferred" way to configure the SSL VPN?

I prefer to use Resource Profiles as it creates any requisite policies.  These policies are linked to the Profile.  If I need to remove the profile, all the policies are removed.  If I need to make a change to the settings, I can do so in one place.  As long as all necessary elements are accessible in a Resource Profile I can't thing of a reason to create each element by hand.  I do create broad resource policies as my fallback access.  That way if a user doesn't match a profile to role mapping they will have limitations on their access or specific required resources.

muttbarker_
Valued Contributor

Re: What is the "preferred" way to configure the SSL VPN?

Resource profiles is really almost always the preferred method. Regardless of how you configure you always need ACL's. 

 

Profiles are more of a "one step" method in that when using them the bookmark, the role mapping and ACL are created in one set of screens. Using policies you must create your bookmarks seperately.