1 / 22

Network Security 2

Network Security 2. Module 6 – Configure Remote Access VPN. Module 6 – Configure Remote Access VPN. Lesson 6.2 Configure the EasyVPN Server. Easy VPN Server General Configuration Tasks. The following general tasks are used to configure Easy VPN Server on a Cisco router –

gdaniels
Download Presentation

Network Security 2

An Image/Link below is provided (as is) to download presentation Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author. Content is provided to you AS IS for your information and personal use only. Download presentation by click this link. While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server. During download, if you can't get a presentation, the file might be deleted by the publisher.

E N D

Presentation Transcript


  1. Network Security 2 Module 6 – Configure Remote Access VPN

  2. Module 6 – Configure Remote Access VPN Lesson 6.2 Configure the EasyVPN Server

  3. Easy VPN Server General Configuration Tasks • The following general tasks are used to configure Easy VPN Server on a Cisco router – • Task 1 – Create IP address pool. • Task 2 – Configure group policy lookup. • Task 3 – Create ISAKMP policy for remote VPN Client access. • Task 4 – Define group policy for mode configuration push. • Task 5 – Create a transform set. • Task 6 – Create a dynamic crypto map with RRI. • Task 7 – Apply mode configuration to the dynamic crypto map. • Task 8 – Apply the crypto map to the router interface. • Task 9 – Enable IKE DPD. • Task 10 – Configure XAUTH. • Task 11 – (Optional) Enable XAUTH save password feature.

  4. Task 1 – Create IP Address Pool

  5. Task 2 – Configure Group Policy Lookup • Creates a user group for local AAA policy lookup

  6. Task 3 – Create ISAKMP Policy for Remote VPN Client Access

  7. Task 4 – Define Group Policy for Mode Configuration Push • Task 4 contains the following steps – • Step 1 – Add the group profile to be defined. • Step 2 – Configure the ISAKMP pre-shared key. • Step 3 – Specify the DNS servers. • Step 4 – Specify the WINS servers. • Step 5 – Specify the DNS domain. • Step 6 – Specify the local IP address pool.

  8. Task 4 - Add the Group Profile to Be Defined

  9. Task 5 – Create Transform Set

  10. Task 6 – Create a Dynamic Crypto Map with RRI • Task 6 contains the following steps – • Step 1 – Create a dynamic crypto map. • Step 2 – Assign a transform set. • Step 3 – Enable RRI.

  11. Task 6 - Create a Dynamic Crypto Map

  12. Task 7 – Apply Mode Configuration to Crypto Map • Task 7 contains the following steps – • Step 1 – Configure the router to respond to mode configuration requests. • Step 2 – Enable IKE querying for a group policy. • Step 3 – Apply the dynamic crypto map to the crypto map.

  13. Task 7 – Apply Mode Configuration to Crypto Map

  14. Task 8 – Apply the Crypto Map to Router Outside Interface

  15. Task 9 – Enable ISAKMP DPD

  16. Task 10 – Configure XAUTH • Task 10 contains the following steps – • Step 1 – Enable AAA login authentication. • Step 2 – Set the XAUTH timeout value. • Step 3 – Enable ISAKMP XAUTH for the dynamic crypto map.

  17. Task 10, Step 1 – Enable AAA Login Authentication

  18. Task 10, Step 2 – Set XAUTH Timeout Value

  19. Task 10, Step 3 – Enable ISAKMP XAUTH for Crypto Map

  20. Task 11 – (Optional) Enable XAUTH Save Password

  21. Q and A

More Related