Cisco Systems PIX IOS 7.0(2) manual Partner Authentication Agent Configuration, VPN Policy

Page 5

Partner Authentication Agent Configuration

Before You Begin

This section provides instructions for integrating the partners’ product with RSA SecurID Authentication. This document is not intended to suggest optimum installations or configurations.

It is assumed that the reader has both working knowledge of all products involved, and the ability to perform the tasks outlined in this section. Administrators should have access to the product documentation for all products in order to install the required components.

All vendor products/components must be installed and working prior to the integration. Perform the necessary tests to confirm that this is true before proceeding.

Cisco PIX Security Appliance

Log onto the Cisco PIX Security Appliance and enter enable mode, by typing the word “enable” and giving the enable password. Then enter configuration mode by typing “config t”. You are now able to enter the commands below to turn on authentication.

VPN Configuration

Please refer to the following Implementation Guide for instructions on setting up the Cisco VPN client to use with the VPN configuration section.

http://rsasecurity.agora.com/rsasecured/guides/imp_pdfs/Cisco_VPN_Client_AuthMan61.pdf

RSA Native SecurID authentication configuration:

Note: The PIX Security appliance obtains the Authentication Manager’s server list when the first user authenticates, which can be either the primary or a replica. Defining replica servers is not necessary when configuring Native Support.

RSA Authentication Manager:

aaa-server AuthMan6 protocol sdi reactivation-mode timed aaa-server AuthMan6 host 10.100.50.37 retry-interval 3

timeout 13

VPN Policy:

ip local pool test 173.16.16.1-173.16.16.254

crypto ipsec transform-set myset esp-des esp-md5-hmac crypto dynamic-map dynmap 10 set transform-set myset crypto map mymap 10 ipsec-isakmp dynamic dynmap crypto map mymap interface outside

isakmp enable outside

isakmp policy 10

authentication pre-share

isakmp policy 10

encryption des

isakmp

policy

10

hash md5

isakmp

policy

10

group 2

tunnel-group AuthMan6Group type ipsec-ra tunnel-group AuthMan6Group general-attributes

5

Image 5
Contents Product Information Partner InformationPartner Integration Overview Solution SummaryAdditional Software Requirements Product RequirementsPartner Product Requirements Cisco PIX Security Appliance Agent Host Configuration VPN Policy Partner Authentication Agent ConfigurationRSA Authentication Manager Page Radius Server Radius authentication configurationRSA Software Token Certification Checklist FirewallCisco Pix Security Appliance Mandatory Functionality RSA Native Protocol Radius ProtocolCisco VPN Client Certification Checklist VPNMandatory Functionality RSA Native Protocol Radius ProtocolAppendix Known Issues