Cisco PIX 525 Spécifications Page 425

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 466
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 424
B-21
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Appendix B Configuration Examples for Other Remote Access Clients
Using Cisco VPN Client Version 1.1
Making an Exception to Xauth for a Site-to-Site VPN Peer
If you have both a site-to-site VPN peer and VPN client peers terminating on the same interface, and
have the Xauth feature configured, configure the PIX
Firewall to make an exception to this feature for
the site-to-site VPN peer. With this exception, the PIX
Firewall will not challenge the site-to-site peer
for a username and password. The command that you employ to make an exception to the Xauth feature
depends on the authentication method you are using within your IKE policies.
Table B-1 summarizes the guidelines to follow.
Ta b l e B-1 Configuring no-xauth
IKE Authentication Method no-xauth Related Command to Use
pre-shared key isakmp key keystring address ip-address [netmask] [no-xauth]
[no-config-mode]
See the isakmp command page within the Cisco PIX Firewall
Command Reference for more information.
rsa signatures isakmp peer fqdn fqdn [no-xauth] [no-config-mode]
See the isakmp command page within the Cisco PIX Firewall
Command Reference for more information.
Making an Exception to IKE Mode Config for Site-to-Site VPN Peers
If you have both a site-to-site VPN peer and VPN clients terminating on the same interface, and have the
IKE Mode Config feature configured, configure the PIX
Firewall to make an exception to this feature
for the site-to-site VPN peer. With this exception, the PIX
Firewall will not attempt to download an IP
address to the peer for dynamic IP address assignment. The command that you employ to bypass the IKE
Mode Config feature depends on the authentication method you are using within your IKE policies. See
Table B-2 for the guidelines to follow.
Ta b l e B-2 Configuring no-config-mode
IKE Authentication Method no-config-mode Related Command to Use
pre-shared key isakmp key keystring address ip-address [netmask] [no-xauth]
[no-config-mode]
See the isakmp command page in the Cisco PIX Firewall
Command Reference for more information.
rsa signatures isakmp peer fqdn fqdn [no-xauth] [no-config-mode]
See the isakmp command page in the Cisco PIX Firewall
Command Reference for more information.
Vue de la page 424
1 2 ... 420 421 422 423 424 425 426 427 428 429 430 ... 465 466

Commentaires sur ces manuels

Pas de commentaire