Cisco PIX 525 Spezifikationen Seite 282

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 466
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 281
8-2
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 8 Managing VPN Remote Access
Using the PIX Firewall as an Easy VPN Server
Overview
With software Version 6.2 and later releases, you can configure the PIX Firewall as an Easy VPN Server.
When used as an Easy VPN Server, the firewall can push VPN configuration to any Easy VPN Remote
device, which greatly simplifies configuration and administration.
Figure 8-1 illustrates how an Easy
VPN Server can be used in a Virtual Private Network (VPN).
Figure 8-1 Using the PIX Firewall as an Easy VPN Server
Internet
83965
PIX Firewall
Version 6.2 or higher
(Easy VPN Server)
Easy VPN Remote device
(Cisco VPN client version 3.x or
Cisco VPN 3000 client version 2.5)
Easy VPN Remote device
(PIX 501, 506, 506E
Cisco VPN 3002 Hardware Client
Cisco 800 or 1700 Series router)
Push remote
configuration
Remote LANCentral LAN
Using the PIX Firewall as an Easy VPN Server lets you configure your VPN policy in a single location
on the PIX
Firewall and then push this configuration to multiple Easy VPN Remote devices. The
following are the different types of Easy VPN Remote devices you can use with a PIX
Firewall
configured as an Easy VPN Server:
Software clients—Connect directly to the Easy VPN Server but require prior installation and
configuration of client software on each host computer. These include the following:
Cisco VPN Client Version 3.x (also known as Unity Client 3.x)
Cisco VPN 3000 Client version 2.5 (also known as the Altiga VPN Client Version 2.5)
Hardware clients—Allow multiple hosts on a remote network to access a network protected by an
Easy VPN Server without any special configuration or software installation on the remote hosts.
These include the following:
PIX 501 or PIX 506/506E
Cisco VPN 3002 Hardware Client
Cisco IOS-based Easy VPN Remote devices (for example, Cisco 800 series and Cisco 1700
series routers)
You use the vpngroup command to associate security policy attributes with a VPN group name. These
attributes are pushed to any Easy VPN Remote devices assigned to the group. The subsequent sections
and examples in this chapter describe how to use this command for implementing different options and
scenarios. See the Cisco PIX Firewall Command Reference for the complete command syntax.
The configuration instructions and examples in this chapter assume that you are using an Easy VPN
Remote device (except for the
“Using PPTP for Remote Access” section on page 8-19). For information
about using a PIX 501 or PIX 506/506E as an Easy VPN Remote device, refer to Chapter 4, “Using PIX
Firewall in SOHO Networks.
Seitenansicht 281
1 2 ... 277 278 279 280 281 282 283 284 285 286 287 ... 465 466

Kommentare zu diesen Handbüchern

Keine Kommentare