
B-8
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Appendix B Configuration Examples for Other Remote Access Clients
L2TP with IPSec in Transport Mode
Next Tokencode Mode
If the user enters an incorrect passcode, then the token status is changed to the Next Tokencode mode.
In this case, when the user tries to connect the next time, and enters a correct password in the first
Software Token dialog box, another Software Token dialog box appears, prompting the user to enter
the next tokencode.
New PIN Mode
This mode is seen when the user is first assigned a token and needs to connect before a PIN can be
assigned or created by the user (Case 1), or if for some reason the administrator puts the token in the
New PIN Mode (Case 2).
Case 1: User has no PINs previously assigned, or the PIN has been cleared.
In this case, enter the value that is currently being displayed in the Software Token dialog box that
requests a username and password.
Case 2: User has an existing PIN and needs to change it.
In this case, enter the PIN in the Software Token dialog box or on the Pinpad, and use the value thus
obtained as the password.
The next prompt, in either case, is for the new PIN. If the user is configured for user-created PIN allowed,
enter
y if the user wants the system to generate the PIN. The system sends the PIN in the next prompt to
the client. If
n is entered, the user is prompted to select the PIN. If the user is configured for user-created
PIN required, then the prompt requests the user to select the PIN.
The next prompt requires the user to enter the password using the new PIN. Enter the newly created PIN
in the Software Token dialog box or on the Pinpad, and use the value thus obtained.
1. For the system generated PIN:
When a y is entered, the system sends the PIN and requires the user to use the PIN to enter the next
tokencode.
2. The user creates the PIN, or a user-created PIN is required. When n is entered in the Generate PIN
dialog box, or if the user is required to generate the PIN, the User Authentication for New
Connection dialog box appears.
Once the user enters the PIN and it is accepted by the server, the following Software Token dialog box
appears. Enter the next tokencode using the new PIN.
L2TP with IPSec in Transport Mode
This section describes how to use IPSec in transport mode to enable L2TP. It includes the following
topics:
• L2TP Overview, page B-9
• IPSec Transport and Tunnel Modes, page B-9
• Configuring L2TP with IPSec in Transport Mode, page B-10
For an L2TP configuration example, see “Xauth with RSA Ace/Server and RSA SecurID.”
Kommentare zu diesen Handbüchern