Page 39
Appendix B Site-to-Site VPN User Interface Reference
| | Site to Site VPN Policies | |
Table B-14 | IKE Proposal Page (continued) |
| | |
Element | | Description |
| |
Selected IKE Proposal | The selected IKE proposal with its predefined default values. |
| | For more information about security parameters, see Understanding |
| | IKE, page 9-58. |
| | Note You cannot edit the selected IKE proposal because it is a |
| | predefined object. You can only edit the properties of an |
| | IKE proposal object you create. |
| | To remove the IKE proposal from this field, select a different one. |
| | |
Create button | | Opens the IKE Editor dialog box for creating an IKE proposal |
| | object. For more information, see IKE Proposal Dialog Box, |
| | page C-123. |
| | |
Edit button | | Opens the IKE Editor dialog box for editing the selected IKE |
| | proposal. For more information, see IKE Proposal Dialog Box, |
| | page C-123. |
| | |
Save button | | Saves your changes to the server but keeps them private. |
| | Note To publish your changes, click the Submit button on the |
| | toolbar. |
| | |
Close button | | Closes the Site-to-Site VPN window. |
| | |
Help button | | Opens help for this page. |
| | | |
IPSec Proposal Page
Use the IPSec Proposal page to edit the IPSec policy definitions for your VPN topology.
For more information about IPSec Proposals, see Understanding IPSec Tunnel Policies, page 9-63.
Note When configuring IPSec policy definitions on an Easy VPN server, the IPSec Proposal page contains different elements. See Easy VPN IPSec Proposal Page, page B-69.
| | User Guide for Cisco Security Manager 3.0.1 | | |
| | |
| OL-8214-02 | | | B-39 |
| | |
Contents
Site-to-Site VPN User Interface Reference
Working with VPN Topologies,
Understanding VPN Topologies,
VPN Summary
B-3 and Peers Page, page B-7
B-37
Configuring IPSec Proposals,
Configuring High Availability in Your VPN Topology,
Configuring VRF-Aware IPSec Settings,
Configuring an IKE Proposal,
B-53
Understanding IPSec Technologies and Policies,
Topology. See IKE Proposal Page, page B-37
See IPSec Proposal Page, page B-39
See GRE Modes Page, page B-59
High Availability Page, page B-34
IPSec Tab, page B-28
Managing VPN Devices in Device View,
Peers
Topology. See Device Selection Page, page B-10
Create VPN Wizard
Name and Technology
B-10
Device Selection
Editing a VPN Topology,
Defining a Name and IPSec Technology,
Navigation Path
Page, page B-9
Endpoints
See VPN Interface Tab, page B-17
Tab, page B-24
See Edit Endpoints Dialog Box, page B-16
B-34
Edit Endpoints Dialog Box
VPN Interface Tab
Information, see Interface Roles Page, page C-126
Procedure for Configuring a Vpnsm or VPN SPA Blade,
More information, see Interface Roles Page, page C-126
IP Address for IPSec Termination -To enter manually the IP
Cisco IOS Routers,
More information, see Configuring Dialer Interfaces on
Box, page B-32
Defining VPN Services Module Vpnsm or VPN SPA Settings
VPN SPA Blade,
For more information, see Adding VPN SPA Slot Locations
IP Address for IPSec Termination-To enter manually the IP
Protected Networks Tab
Table B-9 Edit Endpoints Dialog Box Protected Networks Tab
Information, see Editing Network/Host Objects,
More information, see Editing Access Control List Objects
Fwsm Tab
More information, see Editing Interface Role Objects,
Table B-10 Edit Endpoints Dialog Box Fwsm Tab
For more information, see Interface Roles Page, page C-126
VRF Aware IPSec Tab
Table B-11 Edit Endpoints Dialog Box VRF Aware IPSec Tab
IPSec Two-Box Solution,
Solution,
Routers
C-126
Summary page. See VPN Summary Page, page B-3
Dial Backup Settings Dialog Box
Table B-12 Dial Backup Settings Dialog Box
High Availability
Table B-13 Create VPN wizard High Availability
For more information, see Enabling Stateful Failover,
Policy configured. See VPN Summary Page, page B-3
IKE Proposal
Site to Site VPN Policies
Site-to-Site VPN Policies in Policy View,
Understanding Preshared Key Policies,
More information, see IKE Proposal Dialog Box, page C-123
IPSec Proposal
IKE,
C-123
For more information, see About Crypto Maps,
Shared Site-to-Site VPN Policies in Policy View,
For more information, see About Transform Sets,
IPSec Transform Sets Page, page C-130
To Use,
Element Description
ISAKMP/IPSec Settings Tab
VPN Global Settings
For more information, see About IKE Keepalive,
Configuring VPN Global Settings,
See Understanding IKE,
Appendix B Site-to-Site VPN User Interface Reference
VPN Global Settings Page, page B-44 Understanding NAT,
NAT Settings Tab
NAT,
For more information, see About NAT Traversal,
General Settings Tab
For more information, see Understanding Fragmentation
Select the required setting for the DF bit
Preshared Key
Table B-19 Preshared Key
Element Description
Negotiation Method
Public Key Infrastructure
Working with PKI Enrollment Objects,
C-140
Attributes,
GRE Modes
FlexConfig see Working with FlexConfigs,
Table B-21 GRE Modes Page GRE or GRE Dynamic IP Policy
GRE?,
OL-8214-02
Configuring Cisco IOS Router Interfaces,
OL-8214-02
For more information, see Prerequisites for Successful
Configuration of GRE,
Element Description
Preshared Key Policies,
Interfaces,
For more information, see Configuring Cisco IOS Router
Easy VPN IPSec Proposal
Understanding Easy VPN,
For more information, see Understanding NAT,
Device Access Policies,
Group Objects,
More information, see Working with AAA Server Group Objects
User Group Policy
Working with User Group Objects,
For more information, see Editing User Group Objects,
Tunnel Group Policy PIX 7.0/ASA
Tunnel Group Policy General Tab
For more information, see Working with ASA User Groups
Client Address Assignment
Network/Host Objects,
Tunnel Group Policy IPSec Tab
For more information, see Supported AAA Server Types
Tunnel Group Policy Advanced Tab
More information, see Working with Interface Role Objects
Tunnel Group Policy PIX 7.0/ASA
Tunnel Group Policy Client VPN Software Update Tab
Client Connection Characteristics
Table B-29 Easy VPN Remote Client Connection Characteristics
Working with Site-to-Site VPN Policies,
About Locking in Site-to-Site VPN Topologies,
See Site to Site VPN Policies, page B-37
For more information, see About Editing a VPN Topology
For more information, see Deleting a VPN Topology,
OL-8214-02
OL-8214-02