Cisco PIX 525 Spécifications Page 287

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 466
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 286
8-7
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 8 Managing VPN Remote Access
Configuring Easy VPN Remote Devices with IKE Mode Config
Configuring Easy VPN Remote Devices with IKE Mode Config
A PIX Firewall used as an Easy VPN Server uses the IKE Mode Configuration (Config) protocol to
download an IP address and other network level configuration to an Easy VPN Remote device as part of
the IKE negotiation. During this exchange, the PIX
Firewall gives an IP address to the Easy VPN Remote
device that is used as an “inner” IP address encapsulated under IPSec. This provides a known IP address
for the Easy VPN Remote device, which can then be matched against the IPSec policy on the Easy VPN
Server.
Note If you use IKE Mode Config on the PIX Firewall, the routers handling the IPSec traffic must also support
IKE Mode Config. Cisco IOS Release 12.0(7)T and higher supports IKE Mode Config.
To configure IKE Mode Config, use the following command:
vpngroup groupname option
Replace groupname with an identifier to be used when configuring a particular group of Easy VPN
Remote devices. The administrator of each Easy VPN Remote device enters a specific group name to
access the Easy VPN Remote server.
Replace option with the different options required in your VPN implementation. Some of these options
are required when using network extension mode, which allow central configuration of additional
parameters, such as the address of the DNS server. You also use options with the vpngroup command
to enable various Easy VPN features such as SUA, IUA, and backup servers, as described in the
“Using
the PIX Firewall as an Easy VPN Server” section on page 8-1.
Note For step-by-step procedures using the vpngroup command to implement Easy VPN Remote devices in
different scenarios, refer to the examples later in this chapter.
Table 8-1 summarizes the required and optional parameters used when configuring IKE Mode Config.
Ta b l e 8-1 Required and Optional IKE Mode Config Parameters
Option Description Usage
address-pool
poolname
Pool of local addresses to be assigned to the VPN group.
Use the ip local range command to identify a range of IP
addresses.
Required.
dns-server
address
IP address of a DNS server to download to the Cisco Easy
VPN Remote device.
Required for network
extension mode.
wins-server
address
IP address of a WINS server to download to the Cisco Easy
VPN Remote device.
Required for network
extension mode.
default-domain
domain-name
Default domain name to download to the Cisco Easy VPN
Remote device.
Required for network
extension mode.
split-tunnel
access-list
Split tunneling allows both encrypted and clear traffic
between the Cisco Easy VPN Remote device and the
PIX
Firewall.
Optional.
idle-time
seconds
Inactivity timeout setting for the Cisco Easy VPN Remote
device. The default is 30 minutes.
Optional.
Vue de la page 286
1 2 ... 282 283 284 285 286 287 288 289 290 291 292 ... 465 466

Commentaires sur ces manuels

Pas de commentaire