Cisco Systems OL-5532-02 manual Starting Address, Ending Address, Net Mask

Page 11

Chapter 4 Remote Access VPN Services

Creating Remote Access VPN Policies

Figure 4-9 Address Pools Dialog Box

Step 3

Follow the instructions in Table 4-3to enter values in the address pool fields.

 

Table 4-3 Address Pools Fields

 

 

 

 

Field Name

 

Type

Instructions

 

 

 

 

Starting Address

 

text box

Enter the starting address of the IP address pool.

 

 

 

 

Ending Address

 

text box

Enter the ending address of the IP address pool. The address pool range must be

 

 

 

within a single subnet.

 

 

 

 

Net Mask

 

text box

Enter the netmask to enable autodetection of the remote access address pool during

 

 

 

creation of the service on the CPE devices, so that the remote access address pool can

 

 

 

be detected by peer devices. We recommend that you enter the netmask here in the

 

 

 

remote access policy, instead later of in the service request.

 

 

 

 

Step 4

Click OK when done to return to the Remote Access VPN Policy – Address Pools page.

Step 5

The Address Pool Name field is enabled once an Address Pool is defined, as shown in Figure 4-10. If

 

you want to use with something other than the Cisco IOS or PIX Firewall autogenerated name for this

 

address pool, enter a name here for the address pools defined on this page.

Figure 4-10 The Remote Access VPN Policy – Address Pools Page

Cisco IP Solution Center Integrated VPN Management Suite Security User Guide, 3.2

 

OL-5532-02

4-11

 

 

 

Image 11
Contents Remote Access VPN Services Adding AAA Server Devices to Your Repository AAA Servers IP Address TimeoutName Owner Select buttonCreating Encryption Policies Policies Click Remote Access VPN PolicyRemote Access VPN Policy General Editor Use Mode Group Password Confirm Password XAuth TimeoutIKE NAT Keepalive AuthenticationDefault Domain NAT TraversalDefining Address Pools Remote Access VPN Policy Address PoolsNet Mask Starting AddressEnding Address Defining Split Tunneling Networks Optional 11 Remote Access VPN Policy Split Tunneling Network ListCreate Split TunnelingPolicy Generate14 The Everything Option for Split Tunneling Defining the Remote Access User List OptionalUser ID PasswordDefining Cisco IOS Software-Specific Parameters SA Idle TimeoutEnabled SA Idle Timeout Group Lock Defining PIX Firewall-Specific ParametersReverse Route InjectionSysopt Connection Idle TimeoutDefining VPN 3000-Specific Parameters Max Connect TimeSimultaneous Logins Min PasswordOnly Passwords Authentication onDefining the VPN 3000 Access Hours End Time Defining the VPN 3000 L2TP ParametersControl Start TimeRequire Stateless Use Client AddressL2TP Compression RequiredMSCHAPv2 SummaryMSCHAPv1 23 The Policies Page with Policy Status Displayed Creating Remote Access VPN Service Requests Description Network-basedIPsec CPEs Remote AccessPolicies AAA Servers29 CPEs Associated with Remote Access Service Dialog Box 31 Add/Remove Templates Dialog Box 32 The Template DataFile Chooser Active ActionOL-5532-02