Cisco Systems OL-5532-02 manual Defining Split Tunneling Networks Optional

Page 12

Chapter 4 Remote Access VPN Services

Creating Remote Access VPN Policies

Step 6 Click Next to continue to the Split Tunneling Network page as shown in Figure 4-11in the “Defining Split Tunneling Networks (Optional)” section on page 4-12.

Defining Split Tunneling Networks (Optional)

You can enable or disable split tunneling for remote users. To set the split tunneling parameters, perform the following steps:

Step 1 The Remote Access VPN Policy – Split Tunneling Network List page appears as shown in Figure 4-11.

Note From the ISC home page, you can navigate to the Split Tunneling Network page by clicking Service Design > Policies > Create > IPsec Policy > Remote Access VPN Policy, entering values for the General Editor and Address Pools pages, and then clicking Split Tunneling.

Figure 4-11 Remote Access VPN Policy – Split Tunneling Network List Page

Step 2 Follow the instructions in Table 4-4to choose your split tunneling options. For example, click Create to add IP addresses to the split tunneling network list.

Note Once the list is populated using Create, Generate, or both options, you can edit the list until it contains the desired networks from which traffic must travel through the IPsec tunnel.

Cisco IP Solution Center Integrated VPN Management Suite Security User Guide, 3.2

4-12

OL-5532-02

 

 

Image 12
Contents Remote Access VPN Services Adding AAA Server Devices to Your Repository AAA Servers Timeout NameOwner Select button IP AddressCreating Encryption Policies Click Remote Access VPN Policy PoliciesRemote Access VPN Policy General Editor Group Password Confirm PasswordXAuth Timeout Use Mode Authentication Default Domain NAT Traversal IKE NAT KeepaliveRemote Access VPN Policy Address Pools Defining Address PoolsStarting Address Ending AddressNet Mask 11 Remote Access VPN Policy Split Tunneling Network List Defining Split Tunneling Networks OptionalSplit Tunneling PolicyGenerate CreateDefining the Remote Access User List Optional 14 The Everything Option for Split TunnelingPassword User IDSA Idle Timeout Enabled SA Idle TimeoutDefining Cisco IOS Software-Specific Parameters Defining PIX Firewall-Specific Parameters Reverse RouteInjection Group LockIdle Timeout Defining VPN 3000-Specific ParametersMax Connect Time Sysopt ConnectionLogins Min Password Only PasswordsAuthentication on SimultaneousDefining the VPN 3000 Access Hours Defining the VPN 3000 L2TP Parameters ControlStart Time End TimeUse Client Address L2TP CompressionRequired Require StatelessSummary MSCHAPv1MSCHAPv2 23 The Policies Page with Policy Status Displayed Creating Remote Access VPN Service Requests Network-based IPsecDescription Remote Access PoliciesAAA Servers CPEs29 CPEs Associated with Remote Access Service Dialog Box 31 Add/Remove Templates Dialog Box 32 The Template DataFile Chooser Action ActiveOL-5532-02