Cisco Systems OL-24124-01 manual 17-8

Page 8

Chapter 17 Configuring Virtual Private Networks

Sample IOS configuration summary

ip address 10.89.79.140 port 443

!ssl configuration

ssl encryption aes128-sha1

ssl trustpoint iosrcdnvpn-cert inservice

!

!webvpn context for User and Password authentication webvpn context UserPasswordContext

title "User-Password authentication" ssl authenticate verify all

!

!

policy group UserPasswordGroup functions svc-enabled hide-url-bar

timeout idle 3600

svc address-pool "webvpn-pool"

svc default-domain "nw048b.cisco.com"

svc split include 10.89.75.0 255.255.255.0 svc dns-server primary 64.101.128.56

svc dtls

default-group-policy UserPasswordGroup gateway VPN_RCDN_IOS domain UserPasswordVPN inservice

!

!

!webvpn context for Certificate (username pre-filled) and Password authentication webvpn context CertPasswordContext

title "certificate plus password" ssl authenticate verify all

!

!

policy group CertPasswordGroup functions svc-enabled hide-url-bar

timeout idle 3600

svc address-pool "webvpn-pool"

svc default-domain "nw048b.cisco.com" svc dns-server primary 64.101.128.56 svc dtls

default-group-policy CertPasswordGroup gateway VPN_RCDN_IOS domain CertPasswordVPN authentication certificate aaa username-prefill

ca trustpoint CiscoMfgCert inservice

!

!

!webvpn context for certificate only authentication

webvpn context CertOnlyContext

title "Certificate only authentication" ssl authenticate verify all

!

!

policy group CertOnlyGroup

 

 

 

functions svc-enabled

 

 

 

hide-url-bar

 

 

 

timeout idle 3600

 

 

 

svc address-pool "webvpn-pool"

 

 

 

svc default-domain "nw048b.cisco.com"

 

 

 

svc dns-server primary 64.101.128.56

 

 

 

svc dtls

 

 

 

default-group-policy CertOnlyGroup

 

 

 

gateway VPN_RCDN_IOS domain CertOnlyVPN

 

 

 

Cisco Unified Communications Manager Security Guide

 

 

 

 

 

 

 

 

 

17-8

 

OL-24124-01

 

 

 

 

Image 8
Contents 17-1 Configuring the VPN FeatureSupported Devices Configuration Steps 17-217-3 IOS configuration requirementsConfiguring IOS for VPN client on IP phone Routerconfig# ip route destip mask gatewayip 17-4Sample IOS configuration summary 17-517-6 Aaa new-model17-7 Hidekeys17-8 17-9 ASA configuration requirementsConfiguring ASA for VPN client on IP phone 17-10 Sample ASA configuration summary 17-1117-12 Same-security-traffic permit inter-interface17-13 17-14 Svc rekey time17-15 17-16