
1-18
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 1 Getting Started
Creating a Virtual Private Network
Supporting Remote Access with a Cisco Easy VPN Server
The PIX Firewall supports mixed VPN deployments, including both site-to-site and remote-access
traffic. A remote access VPN uses analog, dial, ISDN, DSL, mobile IP, and cable technologies to
securely connect mobile users, telecommuters, and other individual systems to a network protected by
the PIX
Firewall. Using the PIX Firewall as an Easy VPN Server lets you configure your VPN policy in
a single location on the PIX
Firewall and then push this configuration to multiple Easy VPN Remote
devices. You can use any PIX
Firewall unit running Version 6.2 or higher as an Easy VPN Server.
The following are the different types of Cisco Easy VPN Remote devices you can use with a
PIX
Firewall used as an Easy VPN Server:
• Software clients—Connect directly to the Easy VPN Server but require prior installation and
configuration of client software on each host computer. These include the following:
–
Cisco VPN Client Version 3.x (also known as Unity Client 3.x)
–
Cisco VPN 3000 Client Version 2.5 (also known as the Altiga VPN Client Version 2.5)
• Hardware clients—Allow multiple hosts on a remote network to access a network protected by an
Easy VPN Server without any special configuration or software installation on the remote hosts.
These include the following:
–
Cisco PIX 501 or PIX 506/506E
–
Cisco VPN 3002 Hardware Client
–
Cisco IOS software-based Easy VPN Remote devices (for example, Cisco 800 series and 1700
series routers)
PIX Firewall Version 6.3 introduces support for the following features that improve security, reliability,
and scalability of remote access VPNs:
• Individual User Authentication (IUA)—Allows authentication of users on remote access networks
protected by an Easy VPN Remote hardware client.
• Secure Unit Authentication (SUA)—Allows additional authentication of an Easy VPN Remote
hardware client.
• Configurable policy for Internet access—Provides a configurable policy for controlling access
through the Easy VPN Remote device when an IKE tunnel does not exist.
• Easy VPN Server load balancing and redundancy—Allows the Easy VPN Remote device to be
directed to a server based on load balancing or availability.
• X.509 certificate support—Allows the use of IPSec Main Mode by providing RSA-SIG support.
• Advanced Encryption Standard (AES) and Diffie-Hellman group 5—Provides additional encryption
options for use by the Easy VPN Remote device.
PIX Firewall Version 6.3 introduces support for load balancing and redundancy among a cluster of Easy
VPN Servers. It also provides additional client authentication options, such as user-level authentication.
For further information about using PIX
Firewall as an Easy VPN Server, see Chapter 8, “Managing
VPN Remote Access.” Chapter 8 also includes configuration instructions for using Point-to-Point
Protocol (PPTP).
For information about using a PIX 501 or PIX 506/506E as an Easy VPN Remote device, refer to
Chapter 4, “Using PIX Firewall in SOHO Networks.” For information about configuring remote access
for other VPN software clients, including L2TP, Windows 2000, and Cisco Secure VPN Client Version
1.1, refer to
Appendix B, “Configuration Examples for Other Remote Access Clients.”
Kommentare zu diesen Handbüchern