Cisco Systems OL-5532-02 Defining VPN 3000-Specific Parameters, Idle Timeout, Max Connect Time

Page 18

Chapter 4 Remote Access VPN Services

Creating Remote Access VPN Policies

Figure 4-18 The Remote Access VPN Policy – PIX Firewall Editor Page

Step 2

Use the instructions in Table 4-7to enter values for the PIX Firewall-specific parameters.

 

Table 4-7 PIX Firewall Editor Fields

 

 

 

 

 

Field Name

 

Type

Instructions

 

 

 

 

 

Idle Timeout

 

text box

Enter the inactivity timeout for the VPN client. The default is 1800 seconds.

 

 

 

 

 

Max Connect Time

 

text box

Enter maximum connection time between the VPN client and server. The default is

(in seconds)

 

 

1800 seconds.

 

 

 

 

 

Sysopt Connection

 

checkbox

Check to implicitly permit IPsec traffic. The default setting is checked.

Permit IPsec

 

 

This option issues a PIX Firewall sysopt permit-ipsec-connectioncommand to

 

 

 

 

 

 

permit IPsec traffic to pass through PIX Firewalls without checking the traffic against

 

 

 

conduit or access-list command statements in the firewall configuration.

 

 

 

 

 

Step 3

Click Next to continue to the Remote Access VPN Policy – VPN 3000 Editor page as described in the

 

“Defining VPN 3000-Specific Parameters” section on page 4-18.

 

 

 

 

 

Defining VPN 3000-Specific Parameters

Perform the following steps if you are provisioning remote access on VPN 3000 devices in your network:

Step 1 The Remote Access VPN Policy – VPN 3000 Editor page appears as shown in Figure 4-19.

Cisco IP Solution Center Integrated VPN Management Suite Security User Guide, 3.2

4-18

OL-5532-02

 

 

Image 18
Contents Remote Access VPN Services Adding AAA Server Devices to Your Repository AAA Servers Owner Select button TimeoutName IP AddressCreating Encryption Policies Click Remote Access VPN Policy PoliciesRemote Access VPN Policy General Editor XAuth Timeout Group PasswordConfirm Password Use ModeNAT Traversal AuthenticationDefault Domain IKE NAT KeepaliveRemote Access VPN Policy Address Pools Defining Address PoolsStarting Address Ending AddressNet Mask 11 Remote Access VPN Policy Split Tunneling Network List Defining Split Tunneling Networks OptionalGenerate Split TunnelingPolicy CreateDefining the Remote Access User List Optional 14 The Everything Option for Split TunnelingPassword User IDSA Idle Timeout Enabled SA Idle TimeoutDefining Cisco IOS Software-Specific Parameters Injection Defining PIX Firewall-Specific ParametersReverse Route Group LockMax Connect Time Idle TimeoutDefining VPN 3000-Specific Parameters Sysopt ConnectionAuthentication on Logins Min PasswordOnly Passwords SimultaneousDefining the VPN 3000 Access Hours Start Time Defining the VPN 3000 L2TP ParametersControl End TimeRequired Use Client AddressL2TP Compression Require StatelessSummary MSCHAPv1MSCHAPv2 23 The Policies Page with Policy Status Displayed Creating Remote Access VPN Service Requests Network-based IPsecDescription AAA Servers Remote AccessPolicies CPEs29 CPEs Associated with Remote Access Service Dialog Box 31 Add/Remove Templates Dialog Box 32 The Template DataFile Chooser Action ActiveOL-5532-02