Cisco 3005 - VPN Concentrator - Gateway Información técnica

Busca en linea o descarga Información técnica para Procesadores Cisco 3005 - VPN Concentrator - Gateway. Cisco 3005 - VPN Concentrator - Gateway System information Manual de usuario

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 90
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 0
Exam Topics Discussed in This Chapter
This chapter covers the following topics, which you need to master in your pursuit of
certification as a Cisco Certified Security Professional:
9
Overview of remote access using preshared keys
10
Initial configuration of the Cisco VPN 3000 Concentrator Series for
remote access
11
Browser configuration of the Cisco VPN 3000 Concentrator Series
12
Configuring users and groups
13
Advanced configuration of the Cisco VPN 3000 Concentrator Series
14
Configuring the IPSec Windows Client
chpt_04.fm Page 124 Friday, April 4, 2003 9:19 AM
Vista de pagina 0
1 2 3 4 5 6 ... 89 90

Indice de contenidos

Pagina 1

Exam Topics Discussed in This Chapter This chapter covers the following topics, which you need to master in your pursuit of certification as a Cisco C

Pagina 2 - Preshared Keys

Using VPNs for Remote Access with Preshared Keys 133 While this type of preshared key is the most secure of the three types, it is not practical

Pagina 3

134 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys VPN Concentrator Configuration Three major categories of activi

Pagina 4

VPN Concentrator Configuration 135 Cisco VPN 3000 Concentrator Configuration Requirements Figure 4-2 shows a typical VPN concentrator configuration

Pagina 5

136 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys following is a list of the data values you need to obtain to c

Pagina 6

VPN Concentrator Configuration 137The Quick Configuration can be accomplished from the CLI, but the HTML version of the concentrator manager provide

Pagina 7

138 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysOnce you have entered the correct login name and password, the co

Pagina 8

VPN Concentrator Configuration 139Configuring the Private LAN InterfaceThe next phase of the CLI Quick Configuration steps is to configure the Private

Pagina 9 - Foundation Topics

140 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysIn Example 4-3, the administrator wanted to use a 24-bit subnet m

Pagina 10 - Wildcard Preshared Keys

VPN Concentrator Configuration 141The concentrator only presents the Quick Configuration process upon initial bootup using the default configuration.

Pagina 11 - VPN Concentrator Configuration

142 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysFigure 4-3 HTTP Addressing for VPN 3000 Concentrator Series Manag

Pagina 12

C H A P T E R 4 Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys From a procedural perspective, it is easier to configure t

Pagina 13 - 136

VPN Concentrator Configuration 143Clicking the Install SSL Certificate hotlink takes you to the browser’s certificate installation wizard. Netscape a

Pagina 14 - Password:

144 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysThe top portion of the screen is the application toolbar, and it

Pagina 15

VPN Concentrator Configuration 145Figure 4-6 3005 Concentrator—Configuration | Quick | IP InterfacesFigure 4-7 shows the IP Interfaces screen for th

Pagina 16

146 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysFigure 4-8 Configuration | Quick | IP Interfaces | Ethernet 1NOTE

Pagina 17

VPN Concentrator Configuration 147Figure 4-9 Configuration | Quick | System InfoConfiguring the Tunneling ProtocolClicking the Continue button takes

Pagina 18

148 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysFigure 4-11 Configuration | Quick | Address AssignmentConfiguring U

Pagina 19

VPN Concentrator Configuration 149Figure 4-13 Configuration | Quick | User DatabaseThere is a maximum combined number of groups and users that you c

Pagina 20

150 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysFigure 4-14 Configuration | Quick | IPSec GroupConfiguring the Admi

Pagina 21

VPN Concentrator Configuration 151Figure 4-16 Configuration | Quick | DoneNotice the Save Needed icon in the upper-right corner of the main screen.

Pagina 22

152 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keysthe plus sign indicates that the indicated function has subfuncti

Pagina 23 - Configuring System Information

126 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys Figure 4-1 How to Use This Chapter “Do I Know This Already?” Q

Pagina 24

VPN Concentrator Configuration 153Figure 4-18 IPSec ConfigurationThe interfaces have already been configured using the Quick Configuration option. If

Pagina 25

154 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysBecause the Base Group had not been modified before Quick Configura

Pagina 26

VPN Concentrator Configuration 155Modify Groups—Identity TabTo modify the group, click the group to highlight it, and then click the Modify Group b

Pagina 27 - Saving Configuration Settings

156 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys• Maximum Connect Time—0 disables maximum connect time. The range

Pagina 28

VPN Concentrator Configuration 157Modify Groups—IPSec TabClicking the IPSec tab brings up the screen shown in Figure 4-22. The attributes on this s

Pagina 29 - Concentrator Series Manager

158 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys• IKE Keepalives—Monitors the continued presence of a remote peer

Pagina 30

VPN Concentrator Configuration 159Figure 4-22 Configuration | User Management | Groups | Modify > IPSecModify Groups—Client Config TabThe Client C

Pagina 31

160 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys• IPSec Backup Servers—This attribute is used on Cisco VPN 3002 H

Pagina 32 - Modify Groups—General Tab

VPN Concentrator Configuration 161Figure 4-23 Configuration | User Management | Groups | Modify > Client Configchpt_04.fm Page 161 Friday, April

Pagina 33

162 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysThat is all that you need to configure on the VPN concentrator. Cl

Pagina 34 - Modify Groups—IPSec Tab

“Do I Know This Already?” Quiz 1271 What methods can you use for user authentication on the Cisco VPN 3000 Series Concentrators? 2 What methods

Pagina 35

VPN Concentrator Configuration 163• Firewall—Select the firewall that members of the group are to use. The available options are as follows:— Cisco

Pagina 36

164 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys• Firewall Policy—You can select from three different methods for

Pagina 37

VPN Concentrator Configuration 165Figure 4-24 Configuration | User Management | Groups | Modify > Client FWWhen you configure the VPN 3002 Hardwar

Pagina 38

166 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys• Require Individual User Authentication—You can also require all

Pagina 39 - Modify Groups—Client FW Tab

VPN Concentrator Configuration 167enabling this capability. The default mode for this attribute is disabled, forcing the VPN concentrator to supply

Pagina 40

168 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys— 40-bit—Clients can use the RSA RC4 encryption algorithm using a

Pagina 41 - Modify Groups—HW Client Tab

VPN Concentrator Configuration 169Advanced Configuration of the VPN ConcentratorThe previous sections of this chapter looked at a small part of the

Pagina 42

170 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys• NTP Servers—Network Time Protocol to ensure that all systems us

Pagina 43 - Modify Groups—PPTP/L2TP Tab

VPN Concentrator Configuration 171• Redundancy—Virtual Router Redundancy Protocol parameters• Reverse Route Injection—Reverse Route Injection globa

Pagina 44

172 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysConfiguration | System | GeneralThe General section of the VPN Man

Pagina 45

128 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys 5 When you boot up a Cisco VPN 3000 Concentrator with the defa

Pagina 46 - Configuration

VPN Concentrator Configuration 173Configuration | User ManagementConfiguration | User Management is the section that you used in the “Configuring IPSe

Pagina 47

174 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysInstalling and Configuring the VPN ClientThe Cisco VPN Client is p

Pagina 48

Installing and Configuring the VPN Client 175• Uninstall VPN Client—Uninstall the application. You can choose to retain connection and certificate i

Pagina 49

176 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys• IKE keepalives• Split tunneling• LZS data compressionAuthentica

Pagina 50

Installing and Configuring the VPN Client 177• Encryption algorithms:— 56-bit DES— 168-bit Triple-DES• Extended Authentication (XAUTH)• Mode Configu

Pagina 51 - Overview of the VPN Client

178 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysThe Welcome screen appears, as shown in Figure 4-29. Click Next t

Pagina 52 - VPN Client Features

Installing and Configuring the VPN Client 179The file location screen is displayed, as shown in Figure 4-31. To accept the default location, click N

Pagina 53

180 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysThe installation wizard then copies the files from the CD to your

Pagina 54 - • Tunnel Encapsulation Mode

Installing and Configuring the VPN Client 181Figure 4-35 VPN Client Installation CompleteVPN Client ConfigurationThe configuration process is almost

Pagina 55

182 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysFigure 4-37 Connection Entry ScreenThe first screen of the creatio

Pagina 56

“Do I Know This Already?” Quiz 12911 What are the three major sections of the VPN Manager system? 12 What hot keys are available in the standard

Pagina 57

Installing and Configuring the VPN Client 183VPN 3000 Concentrator Series Manager” section of this chapter. Enter either the IP address of the devi

Pagina 58 - VPN Client Configuration

184 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysThe group name that you established earlier was vpngroup02. Enter

Pagina 59

Installing and Configuring the VPN Client 185Figure 4-42 Using the New VPN ConnectionTo connect to the VPN 3000 Concentrator, simply click the Conn

Pagina 60

186 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysFoundation SummaryThe Foundation Summary is a collection of table

Pagina 61

VPN Client Installation Steps 187VPN 3000 Concentrator Browser-Based Manager Quick Configuration StepsThe steps to the VPN 3000 Concentrator browse

Pagina 62

188 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysStep 4Click Ye s to permit disabling IPSec Policy Agent (if asked

Pagina 63 - Foundation Summary

Complete Configuration Table of Contents 189Limits for Number of Groups and UsersTable 4-4 shows the maximum number of groups and users.Complete Co

Pagina 64 - VPN Client Installation Steps

190 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysConfiguration (Continued)>System (Continued)>Tunneling Proto

Pagina 65 - VPN Client Program Options

Complete Configuration Table of Contents 191Configuration (Continued)>System (Continued)>Events>General>FTP Backup>Classes>Trap De

Pagina 66

192 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysComplete Administration Table of ContentsTable 4-6 shows the comp

Pagina 67

130 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys 18 Where would you configure information for Network Time Proto

Pagina 68

Complete Monitoring Table of Contents 193Complete Monitoring Table of ContentsTable 4-7 shows the complete monitoring table of contents (TOC).Admi

Pagina 69

194 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysMonitoring (Continued)>Statistics (Continued)>VRRP>SSL&g

Pagina 70

Chapter Glossary 195Chapter GlossaryThe following terms were introduced in this chapter or have special significance to the topics within this chap

Pagina 71

196 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysQ&AAs mentioned in Chapter 1, “All About the Cisco Certified S

Pagina 72 - Chapter Glossary

Q&A 1975What options are available for addressing an IP interface on the IP Interfaces screen?6 What is the maximum number of combined groups

Pagina 73

198 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys11Where does the VPN concentrator store system events?12 What are

Pagina 74

Q&A 19917What would you do if you needed to re-enter the Quick Configuration mode after you have completed the initial configuration of the VPN

Pagina 75

200 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys23You would like to be able to pass DNS and WINS information from

Pagina 76

Q&A 20129When you boot up a Cisco VPN 3000 Concentrator with the default factory configuration, what happens?30 If you supply an address of 144

Pagina 77

202 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys35What is the default number of simultaneous logins available to

Pagina 78

“Do I Know This Already?” Quiz 131 The answers to this quiz are listed in Appendix A, “Answers to the “Do I Know This Already?” Quizzes and Q&am

Pagina 79

Q&A 20342What type of cable does the console port require on VPN concentrators?43 What is the default administrator name and password for VPN

Pagina 80

204 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys48When reviewing the list of attributes for a group, what does it

Pagina 81

Q&A 20554What methods can be used for device authentication between VPN peers?55 What is a wildcard preshared key?56 What information do you n

Pagina 82

206 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys60When you select IPSec as the tunneling protocol, what screen do

Pagina 83

Scenario 4-1 207ScenariosThe following scenarios and questions are designed to draw together the content of the chapter and exercise your understa

Pagina 84 - Scenarios

208 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysScenario 4-2Your company sells donuts and has 60 shops located in

Pagina 85 - Scenario 4-2

Scenario 4-2 209• Reauthentication on Rekey• Tunnel Type• Group Lock• Authentication• IPComp• Mode Configurationchpt_04.fm Page 209 Friday, April

Pagina 86 - Scenario 4-2 209

210 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared KeysScenario AnswersThe answers provided in this section are not nece

Pagina 87 - Scenario Answers

Scenario 4-2 Answers 2119Unlimited access? This would be a group-by-group decision. Does the R&D team work around the clock or just during bus

Pagina 88 - Scenario 4-2 Answers

212 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys• Tunnel Type—Remote access• Group Lock—Disabled• Authentication—

Pagina 89 - • Mode Configuration—Enabled

132 Chapter 4: Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys Foundation Topics Using VPNs for Remote Access with Preshared

Pagina 90

chpt_04.fm Page 213 Friday, April 4, 2003 9:19 AM

Comentarios a estos manuales

Sin comentarios