Cisco 3005 - VPN Concentrator - Gateway Technical Information

Stöbern Sie online oder laden Sie Technical Information nach Prozessoren Cisco 3005 - VPN Concentrator - Gateway herunter. Cisco 3005 - VPN Concentrator - Gateway System information Benutzerhandbuch

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 90
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 0
Exam Topics Discussed in This Chapter
This chapter covers the following topics, which you need to master in your pursuit of
certification as a Cisco Certified Security Professional:
9
Overview of remote access using preshared keys
10
Initial configuration of the Cisco VPN 3000 Concentrator Series for
remote access
11
Browser configuration of the Cisco VPN 3000 Concentrator Series
12
Configuring users and groups
13
Advanced configuration of the Cisco VPN 3000 Concentrator Series
14
Configuring the IPSec Windows Client
chpt_04.fm Page 124 Friday, April 4, 2003 9:19 AM
Seitenansicht 0
1 2 3 4 5 6 ... 89 90

Inhaltsverzeichnis

Seite 1

Exam Topics Discussed in This Chapter This chapter covers the following topics, which you need to master in your pursuit of certification as a Cisco C

Seite 2 - Preshared Keys

Using VPNs for Remote Access with Preshared Keys 133 While this type of preshared key is the most secure of the three types, it is not practical

Seite 3

134 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys VPN Concentrator Configuration Three major categories of activi

Seite 4

VPN Concentrator Configuration 135 Cisco VPN 3000 Concentrator Configuration Requirements Figure 4-2 shows a typical VPN concentrator configuration

Seite 5

136 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys following is a list of the data values you need to obtain to c

Seite 6

VPN Concentrator Configuration 137The Quick Configuration can be accomplished from the CLI, but the HTML version of the concentrator manager provide

Seite 7

138 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysOnce you have entered the correct login name and password, the co

Seite 8

VPN Concentrator Configuration 139Configuring the Private LAN InterfaceThe next phase of the CLI Quick Configuration steps is to configure the Private

Seite 9 - Foundation Topics

140 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysIn Example 4-3, the administrator wanted to use a 24-bit subnet m

Seite 10 - Wildcard Preshared Keys

VPN Concentrator Configuration 141The concentrator only presents the Quick Configuration process upon initial bootup using the default configuration.

Seite 11 - VPN Concentrator Configuration

142 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysFigure 4-3 HTTP Addressing for VPN 3000 Concentrator Series Manag

Seite 12

C H A P T E R 4 Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys From a procedural perspective, it is easier to configure t

Seite 13 - 136

VPN Concentrator Configuration 143Clicking the Install SSL Certificate hotlink takes you to the browser’s certificate installation wizard. Netscape a

Seite 14 - Password:

144 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysThe top portion of the screen is the application toolbar, and it

Seite 15

VPN Concentrator Configuration 145Figure 4-6 3005 Concentrator—Configuration | Quick | IP InterfacesFigure 4-7 shows the IP Interfaces screen for th

Seite 16

146 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysFigure 4-8 Configuration | Quick | IP Interfaces | Ethernet 1NOTE

Seite 17

VPN Concentrator Configuration 147Figure 4-9 Configuration | Quick | System InfoConfiguring the Tunneling ProtocolClicking the Continue button takes

Seite 18

148 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysFigure 4-11 Configuration | Quick | Address AssignmentConfiguring U

Seite 19

VPN Concentrator Configuration 149Figure 4-13 Configuration | Quick | User DatabaseThere is a maximum combined number of groups and users that you c

Seite 20

150 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysFigure 4-14 Configuration | Quick | IPSec GroupConfiguring the Admi

Seite 21

VPN Concentrator Configuration 151Figure 4-16 Configuration | Quick | DoneNotice the Save Needed icon in the upper-right corner of the main screen.

Seite 22

152 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keysthe plus sign indicates that the indicated function has subfuncti

Seite 23 - Configuring System Information

126 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys Figure 4-1 How to Use This Chapter “Do I Know This Already?” Q

Seite 24

VPN Concentrator Configuration 153Figure 4-18 IPSec ConfigurationThe interfaces have already been configured using the Quick Configuration option. If

Seite 25

154 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysBecause the Base Group had not been modified before Quick Configura

Seite 26

VPN Concentrator Configuration 155Modify Groups—Identity TabTo modify the group, click the group to highlight it, and then click the Modify Group b

Seite 27 - Saving Configuration Settings

156 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys• Maximum Connect Time—0 disables maximum connect time. The range

Seite 28

VPN Concentrator Configuration 157Modify Groups—IPSec TabClicking the IPSec tab brings up the screen shown in Figure 4-22. The attributes on this s

Seite 29 - Concentrator Series Manager

158 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys• IKE Keepalives—Monitors the continued presence of a remote peer

Seite 30

VPN Concentrator Configuration 159Figure 4-22 Configuration | User Management | Groups | Modify > IPSecModify Groups—Client Config TabThe Client C

Seite 31

160 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys• IPSec Backup Servers—This attribute is used on Cisco VPN 3002 H

Seite 32 - Modify Groups—General Tab

VPN Concentrator Configuration 161Figure 4-23 Configuration | User Management | Groups | Modify > Client Configchpt_04.fm Page 161 Friday, April

Seite 33

162 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysThat is all that you need to configure on the VPN concentrator. Cl

Seite 34 - Modify Groups—IPSec Tab

“Do I Know This Already?” Quiz 1271 What methods can you use for user authentication on the Cisco VPN 3000 Series Concentrators? 2 What methods

Seite 35

VPN Concentrator Configuration 163• Firewall—Select the firewall that members of the group are to use. The available options are as follows:— Cisco

Seite 36

164 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys• Firewall Policy—You can select from three different methods for

Seite 37

VPN Concentrator Configuration 165Figure 4-24 Configuration | User Management | Groups | Modify > Client FWWhen you configure the VPN 3002 Hardwar

Seite 38

166 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys• Require Individual User Authentication—You can also require all

Seite 39 - Modify Groups—Client FW Tab

VPN Concentrator Configuration 167enabling this capability. The default mode for this attribute is disabled, forcing the VPN concentrator to supply

Seite 40

168 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys— 40-bit—Clients can use the RSA RC4 encryption algorithm using a

Seite 41 - Modify Groups—HW Client Tab

VPN Concentrator Configuration 169Advanced Configuration of the VPN ConcentratorThe previous sections of this chapter looked at a small part of the

Seite 42

170 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys• NTP Servers—Network Time Protocol to ensure that all systems us

Seite 43 - Modify Groups—PPTP/L2TP Tab

VPN Concentrator Configuration 171• Redundancy—Virtual Router Redundancy Protocol parameters• Reverse Route Injection—Reverse Route Injection globa

Seite 44

172 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysConfiguration | System | GeneralThe General section of the VPN Man

Seite 45

128 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys 5 When you boot up a Cisco VPN 3000 Concentrator with the defa

Seite 46 - Configuration

VPN Concentrator Configuration 173Configuration | User ManagementConfiguration | User Management is the section that you used in the “Configuring IPSe

Seite 47

174 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysInstalling and Configuring the VPN ClientThe Cisco VPN Client is p

Seite 48

Installing and Configuring the VPN Client 175• Uninstall VPN Client—Uninstall the application. You can choose to retain connection and certificate i

Seite 49

176 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys• IKE keepalives• Split tunneling• LZS data compressionAuthentica

Seite 50

Installing and Configuring the VPN Client 177• Encryption algorithms:— 56-bit DES— 168-bit Triple-DES• Extended Authentication (XAUTH)• Mode Configu

Seite 51 - Overview of the VPN Client

178 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysThe Welcome screen appears, as shown in Figure 4-29. Click Next t

Seite 52 - VPN Client Features

Installing and Configuring the VPN Client 179The file location screen is displayed, as shown in Figure 4-31. To accept the default location, click N

Seite 53

180 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysThe installation wizard then copies the files from the CD to your

Seite 54 - • Tunnel Encapsulation Mode

Installing and Configuring the VPN Client 181Figure 4-35 VPN Client Installation CompleteVPN Client ConfigurationThe configuration process is almost

Seite 55

182 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysFigure 4-37 Connection Entry ScreenThe first screen of the creatio

Seite 56

“Do I Know This Already?” Quiz 12911 What are the three major sections of the VPN Manager system? 12 What hot keys are available in the standard

Seite 57

Installing and Configuring the VPN Client 183VPN 3000 Concentrator Series Manager” section of this chapter. Enter either the IP address of the devi

Seite 58 - VPN Client Configuration

184 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysThe group name that you established earlier was vpngroup02. Enter

Seite 59

Installing and Configuring the VPN Client 185Figure 4-42 Using the New VPN ConnectionTo connect to the VPN 3000 Concentrator, simply click the Conn

Seite 60

186 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysFoundation SummaryThe Foundation Summary is a collection of table

Seite 61

VPN Client Installation Steps 187VPN 3000 Concentrator Browser-Based Manager Quick Configuration StepsThe steps to the VPN 3000 Concentrator browse

Seite 62

188 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysStep 4Click Ye s to permit disabling IPSec Policy Agent (if asked

Seite 63 - Foundation Summary

Complete Configuration Table of Contents 189Limits for Number of Groups and UsersTable 4-4 shows the maximum number of groups and users.Complete Co

Seite 64 - VPN Client Installation Steps

190 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysConfiguration (Continued)>System (Continued)>Tunneling Proto

Seite 65 - VPN Client Program Options

Complete Configuration Table of Contents 191Configuration (Continued)>System (Continued)>Events>General>FTP Backup>Classes>Trap De

Seite 66

192 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysComplete Administration Table of ContentsTable 4-6 shows the comp

Seite 67

130 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys 18 Where would you configure information for Network Time Proto

Seite 68

Complete Monitoring Table of Contents 193Complete Monitoring Table of ContentsTable 4-7 shows the complete monitoring table of contents (TOC).Admi

Seite 69

194 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysMonitoring (Continued)>Statistics (Continued)>VRRP>SSL&g

Seite 70

Chapter Glossary 195Chapter GlossaryThe following terms were introduced in this chapter or have special significance to the topics within this chap

Seite 71

196 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysQ&AAs mentioned in Chapter 1, “All About the Cisco Certified S

Seite 72 - Chapter Glossary

Q&A 1975What options are available for addressing an IP interface on the IP Interfaces screen?6 What is the maximum number of combined groups

Seite 73

198 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys11Where does the VPN concentrator store system events?12 What are

Seite 74

Q&A 19917What would you do if you needed to re-enter the Quick Configuration mode after you have completed the initial configuration of the VPN

Seite 75

200 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys23You would like to be able to pass DNS and WINS information from

Seite 76

Q&A 20129When you boot up a Cisco VPN 3000 Concentrator with the default factory configuration, what happens?30 If you supply an address of 144

Seite 77

202 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys35What is the default number of simultaneous logins available to

Seite 78

“Do I Know This Already?” Quiz 131 The answers to this quiz are listed in Appendix A, “Answers to the “Do I Know This Already?” Quizzes and Q&am

Seite 79

Q&A 20342What type of cable does the console port require on VPN concentrators?43 What is the default administrator name and password for VPN

Seite 80

204 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys48When reviewing the list of attributes for a group, what does it

Seite 81

Q&A 20554What methods can be used for device authentication between VPN peers?55 What is a wildcard preshared key?56 What information do you n

Seite 82

206 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys60When you select IPSec as the tunneling protocol, what screen do

Seite 83

Scenario 4-1 207ScenariosThe following scenarios and questions are designed to draw together the content of the chapter and exercise your understa

Seite 84 - Scenarios

208 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysScenario 4-2Your company sells donuts and has 60 shops located in

Seite 85 - Scenario 4-2

Scenario 4-2 209• Reauthentication on Rekey• Tunnel Type• Group Lock• Authentication• IPComp• Mode Configurationchpt_04.fm Page 209 Friday, April

Seite 86 - Scenario 4-2 209

210 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysScenario AnswersThe answers provided in this section are not nece

Seite 87 - Scenario Answers

Scenario 4-2 Answers 2119Unlimited access? This would be a group-by-group decision. Does the R&D team work around the clock or just during bus

Seite 88 - Scenario 4-2 Answers

212 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys• Tunnel Type—Remote access• Group Lock—Disabled• Authentication—

Seite 89 - • Mode Configuration—Enabled

132 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys Foundation Topics Using VPNs for Remote Access with Preshared

Seite 90

chpt_04.fm Page 213 Friday, April 4, 2003 9:19 AM

Kommentare zu diesen Handbüchern

Keine Kommentare