
8-8
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 8 Managing VPN Remote Access
Using an Easy VPN Remote Device with Pre-Shared Keys
When the Cisco Easy VPN Remote device initiates ISAKMP with the PIX Firewall, the VPN group
name and pre-shared key (or certificate) are sent to the PIX
Firewall. The PIX Firewall then uses the
group name to look up the configured client policy attributes for the given Cisco Easy VPN Remote
device and downloads the matching policy attributes to the client during the IKE negotiation.
If you are using a remote client other than a Cisco Easy VPN Remote device, you can still assign IP
addresses dynamically, as long as the remote client supports the IKE Mode Config protocol within
IPSec. For configuration examples for clients other than Easy VPN Remote devices, refer to
Appendix B, “Configuration Examples for Other Remote Access Clients”
Using an Easy VPN Remote Device with Pre-Shared Keys
This example shows use of the following supported features:
• Extended Authentication (Xauth) for user authentication
• RADIUS authorization for user services authorization
• IKE Mode Config for VPN IP address assignment
• Wildcard pre-shared key for IKE authentication
This section shows use of eXtended Authentication (Xauth), RADIUS authorization, IKE Mode Config,
and a wildcard, pre-shared key for IKE authentication between a PIX
Firewall and an Easy VPN Remote
software client.
Note The PIX Firewall configuration provided in the first section applies to any Easy VPN Remote device.
However the last section describes the configuration required for software clients. For configuration
instructions when using a PIX
Firewall as an Easy VPN Remote device, refer to “Using PIX Firewall as
an Easy VPN Remote Device” in Chapter 4, “Using PIX Firewall in SOHO Networks.”
This section includes the following topics:
• Scenario Description, page 8-8
• Configuring the PIX Firewall, page 8-10
• Configuring the Easy VPN Remote Software Client, page 8-12
Scenario Description
With the vpngroup command set, you configure the PIX Firewall for a specified group of Cisco Easy
VPN Remote devices, using the following parameters:
• Group name for a given group of Cisco Easy VPN Remote devices.
• Pre-shared key or group password used to authenticate your VPN access to the remote server
(PIX Firewall).
Note This pre-shared key is equivalent to the password entered in the Group Password box of
Cisco Easy VPN Remote software clients while configuring the group access information
for a connection entry.
Comentarios a estos manuales