Disabling compression for WebVPN client (Portal users) using APCF?

Unanswered Question
Sep 24th, 2010
User Badges:
  • Cisco Employee,

Hi All,


We are trying to disable compression for WebVPN users by the following command:


no compression http-comp all


But we are still seeing gzip/deflate in the PCAP captures.


At this time, I do not have the information related to ASA code but the device is ASA 5540.


My main concern or question is if we can disable compression for WebVPN clients using APCF or not.


Any suggestion would be really appreciated.


Regards,

Nick.AP

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Jennifer Halim Fri, 09/24/2010 - 17:06
User Badges:
  • Cisco Employee,

Hi Nikhil,


Where are you seeing the gzip in the packet capture? How are you actually seeing the gzip because it should be SSL encrypted?

The compression would be between your WebVPN towards the ASA firewall, and once it has been decrypted on the ASA towards the internal host, the traffic will be clear text as normal. The encryption is only between client on the outside towards the ASA external interface.


Hope that helps.

Nikhil Thakur Fri, 09/24/2010 - 17:26
User Badges:
  • Cisco Employee,

Hi Jennifer,


Thank you very much for the quick response.


Sorry...It was my bad!


Actually, we are seeing gzip/deflate in the HTTP watch captures and not in PCAP.


Please let me know if that makes more sense to you.


Warm Regards,

Nick

Nikhil Thakur Mon, 09/27/2010 - 17:10
User Badges:
  • Cisco Employee,

Hi All,


Do you guys have any idea about what I am talking?


Please suggest.


Regards,

Nikhil Thakur.

Actions

This Discussion

Related Content