
4-12
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 4 Using PIX Firewall in SOHO Networks
Using the PIX Firewall PPPoE Client
To establish a VPN tunnel with this server, enter the following command on the PIX Firewall used as an
Easy VPN Remote device:
ca verifycertdn cn*myvpn, ou=myou, o=myorg, st=ca, c=US
This command causes the receiving PIX Firewall to accept certificates with any DN having the following
attributes:
• Common Name (CN) containing the string myvpn
• Organizational Unit (OU) equal to myou
• Organization (O) equal to myorg
• State (ST) equal to CA
• Country (C) equal to US
You could be more restrictive by identifying a specific common name, or less restrictive by omitting the
CN attribute altogether.
You can use an asterisk (*) to match an attribute containing the string following the asterisk. Use an
exclamation mark (!) to match an attribute that does not contain the characters following the exclamation
mark.
Using the PIX Firewall PPPoE Client
This section describes how to use the PPPoE client provided with PIX Firewall Version 6.2 and higher.
It includes the following topics:
• Overview, page 4-12
• Configuring the PPPoE Client Username and Password, page 4-13
• Enabling PPPoE on the PIX Firewall, page 4-14
• Using PPPoE with a Fixed IP Address, page 4-14
• Monitoring and Debugging the PPPoE Client, page 4-15
• Using Related Commands, page 4-16
Overview
Point-to-Point Protocol over Ethernet (PPPoE) combines two widely accepted standards, Ethernet and
PPP, to provide an authenticated method of assigning IP addresses to client systems. PPPoE clients are
typically personal computers connected to an ISP over a remote broadband connection, such as DSL or
cable service. ISPs deploy PPPoE because it supports high-speed broadband access using their existing
remote access infrastructure and because it is easier for customers to use.
PIX Firewall Version 6.2 introduces PPPoE client functionality. This allows small office, home office
(SOHO) users of the PIX
Firewall to connect to ISPs using DSL modems.
Note The PIX Firewall PPPoE client can only be enabled on the outside interface.
Kommentare zu diesen Handbüchern