Cisco PIX 525 Spezifikationen Seite 412

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 604
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 411
24-2
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 24 Setting General VPN Parameters
Permitting Intra-Interface Traffic
Permitting Intra-Interface Traffic
The security appliance includes a feature that lets users on the same subnet send IPSec-protected traffic
to each other. It does so by allowing such traffic in and out of the same interface. This is called
hairpinning.
To configure this feature, use the same-security-traffic command in global configuration mode with its
intra-interface argument.
The command syntax is same-security-traffic permit {inter-interface | intra-interface}.
The following example shows how to enable intra-interface traffic:
hostname(config)# same-security-traffic permit intra-interface
hostname(config)#
Note You use the same-security-traffic command, but with the inter-interface argument, to permit
communication between interfaces that have the same security level. This feature is not specific to IPSec
connections. For more information, see the “Configuring Interface Parameters” chapter of this guide.
Setting Maximum Active IPSec VPN Sessions
To limit VPN sessions to a lower value than the security appliance allows, enter the vpn-sessiondb
max-session-limit command in global configuration mode.
This command applies to all types of VPN sessions.
The syntax is vpn-sessiondb max-session-limit {session-limit}.
The following example shows how to set a maximum VPN session limit of 450:
hostname (config)# vpn-sessiondb max-session-limit 450
hostname (config)#
Configuring Client Update
The client update feature lets administrators at a central location automatically notify VPN client users
when it is time to update the VPN client software and the VPN 3002 hardware client image.
To configure client update, enter the client-update command in tunnel-group ipsec-attributes
configuration mode. If the client is already running a software version on the list of revision numbers, it
does not need to update its software. If the client is not running a software version on the list, it should
update. You can specify up to 4 client update entries.
Seitenansicht 411
1 2 ... 407 408 409 410 411 412 413 414 415 416 417 ... 603 604

Kommentare zu diesen Handbüchern

Keine Kommentare