Cisco PIX 525 Specifiche Pagina 289

  • Scaricare
  • Aggiungi ai miei manuali
  • Stampa
  • Pagina
    / 466
  • Indice
  • SEGNALIBRI
  • Valutato. / 5. Basato su recensioni clienti
Vedere la pagina 288
8-9
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 8 Managing VPN Remote Access
Using an Easy VPN Remote Device with Pre-Shared Keys
Pool of local addresses to be assigned to the VPN group.
(Optional) IP address of a DNS server to download to the Cisco Easy VPN Remote device.
(Optional) IP address of a WINS server to download to the Cisco Easy VPN Remote device.
(Optional) Default domain name to download to the Cisco Easy VPN Remote device.
(Optional) Split tunneling enabled on the PIX Firewall allowing both encrypted and clear traffic
between the Cisco Easy VPN Remote device and the PIX
Firewall.
Note If split tunneling is not enabled, all traffic between the Cisco Easy VPN Remote device and
the PIX Firewall will be encrypted.
(Optional) Inactivity timeout setting for the Cisco Easy VPN Remote device. The default is 30
minutes.
On the Cisco Easy VPN Remote device, you would configure the vpngroup name and group password
to match that which you configured on the PIX
Firewall.
When the Cisco Easy VPN Remote device initiates ISAKMP with the PIX Firewall, the VPN group
name and pre-shared key are sent to the PIX
Firewall. The PIX Firewall then uses the group name to look
up the configured client policy attributes for the given Cisco Easy VPN Remote device and downloads
the matching policy attributes to the client during the IKE negotiation.
Figure 8-2 illustrates the example network.
Figure 8-2 Cisco Easy VPN Remote Device Access
VPN Client user
(10.1.1.0/24 local address
when terminated on the PIX)
192.168.101.1
209.165.200.227
209.165.200.229
Router
PIX
Firewall
10.0.0.1
192.168.101.2
AAA Server
partnerauth
10.0.0.15
DNS/WINS Server
10.0.0.14
44311
San Jose Office
Internet
Vedere la pagina 288
1 2 ... 284 285 286 287 288 289 290 291 292 293 294 ... 465 466

Commenti su questo manuale

Nessun commento