Cisco 3002 - VPN Hardware Client Especificaciones Pagina 142

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 318
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 141
11-4
VPN 3002 Hardware Client Reference, Release 4.0
OL-3813-01
Chapter 11 Policy Management
Configuration | Policy Management | Traffic Management
Step 3 Enter the username and password for the VPN 3002.
Alternatively, you can initiate a tunnel by clicking Connect Now on the in the Monitoring | System
Status screen.
Network Extension Mode with Split Tunneling
You always assign the VPN 3002 to a client group on the central-site VPN Concentrator. If you enable
split tunneling for that group, IPSec operates on all traffic that travels through the VPN 3002 to networks
within the network list for that group behind the central-site VPN Concentrator. PAT does not apply.
Traffic from the VPN 3002 to any other destination than those within the network list on the central-site
VPN Concentrator travels in the clear without applying IPSec. NAT translates the network addresses of
the devices on the VPN 3002 private network to the address of the VPN 3002 public interface. Thus the
network and addresses on the private side of the VPN 3002 are accessible over the tunnel, but are
protected from the Internet, that is, they cannot be accessed directly.
VPN 3000 Series Concentrator Settings Required for Network Extension Mode
For the VPN 3002 to use Network Extension mode, these are the requirements for the central-site VPN
Concentrator.
1. The VPN Concentrator at the central site must be running Software version 3.0 or later.
2. Configure a group to which you assign this VPN 3002. This includes assigning a group name and
password. See Chapter 14, User Management, in the VPN 3000 Series Concentrator Reference
Volume I.
3. Configure one or more users for the group, including usernames and passwords.
4. Configure either a default gateway or a static route to the VPN 3002 private network. See
Chapter 8, IP Routing in the VPN 3000 Series Concentrator Reference Volume I.
5. If you want the VPN 3002 to be able to reach devices on other networks that connect to this VPN
Concentrator, review your Network Lists. See Chapter 15, Policy Management in the VPN 3000
Series Concentrator Reference Volume I.
6. Enable Network Extension Mode. See the section that follows for details.
Network Extension Mode per Group
A network administrator can now restrict the use of network extension mode. VPN 3002 hardware clients
can use network extension mode only if, on the VPN Concentrator, you enable network extension mode
on a group basis for VPN 3002 hardware clients.
Note If you disallow network extension mode, which is the default setting on the VPN Concentrator, the
VPN 3002 can connect to that VPN Concentrator in PAT mode only. In this case, be careful that all
VPN 3002s in the group are configured for PAT mode. If a VPN 3002 is configured to use network
extension mode and the VPN Concentrator to which it connects disallows network extension mode,
the VPN 3002 will attempt to connect every 4 seconds, and every attempt will be rejected; this is the
equivalent of denial of service attack.
Vista de pagina 141
1 2 ... 137 138 139 140 141 142 143 144 145 146 147 ... 317 318

Comentarios a estos manuales

Sin comentarios