Page 73
Appendix B Site-to-Site VPN User Interface Reference
Site to Site VPN Policies
User Group Policy Page
Use the User Group Policy page to create or edit a user group policy on your Easy VPN server. For more information about user group policies in Easy VPN, see Configuring a User Group Policy for Easy VPN, page 9-106.
| | Note | You can also configure user group policies in remote access VPNs. For more |
| | | | information, see Understanding User Group Policies in Remote Access VPNs, |
| | | | page 10-4. |
| | | | | |
| | | | |
| | | | Open the Site-to-Site VPN Manager Window, page B-2, select a topology in the |
| | | | VPNs selector, then select User Group Policy in the Policies selector. |
| | | | | |
| | Note | You can also open the User Group Policy page from Policy view. For more |
| | | | information, see Managing Shared Site-to-Site VPN Policies in Policy View, |
| | | | page 9-56. |
| | | | | |
| | | | Related Topics |
| | | | | • Understanding Easy VPN, page 9-100 |
| | | | | • Working with User Group Objects, page 8-237 |
| | | | Field Reference |
Table B-24 | Easy VPN Server > User Group Policy Page |
| | | | | | |
| Element | | | | | Description |
| | | |
| Available User Groups | | Lists the predefined user groups available for selection. |
| | | | | | Select the required user group if you want to replace the default one |
| | | | | | in the Selected field. |
| | | | | | User groups are predefined objects. If the required user group is not |
| | | | | | included in the list, click Create to open the User Groups Editor |
| | | | | | dialog box that enables you to create or edit a user group object. |
| | | | | | For more information, see Editing User Group Objects, page 8-245. |
| | | | | | | | |
| | | | | | User Guide for Cisco Security Manager 3.0.1 | | |
| | | | | |
| OL-8214-02 | | | | | | | B-73 |
| | | | | | |
Contents
Site-to-Site VPN User Interface Reference
Working with VPN Topologies,
Understanding VPN Topologies,
B-3 and Peers Page, page B-7
VPN Summary
B-37
Configuring VRF-Aware IPSec Settings,
Configuring High Availability in Your VPN Topology,
Configuring an IKE Proposal,
Configuring IPSec Proposals,
Topology. See IKE Proposal Page, page B-37
Understanding IPSec Technologies and Policies,
See IPSec Proposal Page, page B-39
B-53
High Availability Page, page B-34
See GRE Modes Page, page B-59
IPSec Tab, page B-28
Managing VPN Devices in Device View,
Peers
Topology. See Device Selection Page, page B-10
Create VPN Wizard
Name and Technology
Editing a VPN Topology,
Device Selection
Defining a Name and IPSec Technology,
B-10
Navigation Path
Page, page B-9
Endpoints
See VPN Interface Tab, page B-17
See Edit Endpoints Dialog Box, page B-16
Tab, page B-24
B-34
Edit Endpoints Dialog Box
VPN Interface Tab
Information, see Interface Roles Page, page C-126
Procedure for Configuring a Vpnsm or VPN SPA Blade,
More information, see Interface Roles Page, page C-126
IP Address for IPSec Termination -To enter manually the IP
Cisco IOS Routers,
More information, see Configuring Dialer Interfaces on
Box, page B-32
Defining VPN Services Module Vpnsm or VPN SPA Settings
VPN SPA Blade,
For more information, see Adding VPN SPA Slot Locations
IP Address for IPSec Termination-To enter manually the IP
Protected Networks Tab
Table B-9 Edit Endpoints Dialog Box Protected Networks Tab
Fwsm Tab
More information, see Editing Access Control List Objects
More information, see Editing Interface Role Objects,
Information, see Editing Network/Host Objects,
Table B-10 Edit Endpoints Dialog Box Fwsm Tab
For more information, see Interface Roles Page, page C-126
VRF Aware IPSec Tab
Table B-11 Edit Endpoints Dialog Box VRF Aware IPSec Tab
IPSec Two-Box Solution,
Solution,
Routers
C-126
Summary page. See VPN Summary Page, page B-3
Dial Backup Settings Dialog Box
Table B-12 Dial Backup Settings Dialog Box
High Availability
Table B-13 Create VPN wizard High Availability
For more information, see Enabling Stateful Failover,
Policy configured. See VPN Summary Page, page B-3
IKE Proposal
Site to Site VPN Policies
Understanding Preshared Key Policies,
Site-to-Site VPN Policies in Policy View,
More information, see IKE Proposal Dialog Box, page C-123
IKE,
IPSec Proposal
C-123
For more information, see About Crypto Maps,
Shared Site-to-Site VPN Policies in Policy View,
For more information, see About Transform Sets,
IPSec Transform Sets Page, page C-130
To Use,
Element Description
ISAKMP/IPSec Settings Tab
VPN Global Settings
For more information, see About IKE Keepalive,
Configuring VPN Global Settings,
See Understanding IKE,
Appendix B Site-to-Site VPN User Interface Reference
VPN Global Settings Page, page B-44 Understanding NAT,
NAT Settings Tab
NAT,
For more information, see About NAT Traversal,
General Settings Tab
For more information, see Understanding Fragmentation
Select the required setting for the DF bit
Preshared Key
Table B-19 Preshared Key
Element Description
Negotiation Method
Public Key Infrastructure
C-140
Working with PKI Enrollment Objects,
Attributes,
GRE Modes
FlexConfig see Working with FlexConfigs,
Table B-21 GRE Modes Page GRE or GRE Dynamic IP Policy
GRE?,
OL-8214-02
Configuring Cisco IOS Router Interfaces,
OL-8214-02
For more information, see Prerequisites for Successful
Configuration of GRE,
Element Description
Preshared Key Policies,
Interfaces,
For more information, see Configuring Cisco IOS Router
Easy VPN IPSec Proposal
Understanding Easy VPN,
For more information, see Understanding NAT,
Group Objects,
Device Access Policies,
More information, see Working with AAA Server Group Objects
Working with User Group Objects,
User Group Policy
For more information, see Editing User Group Objects,
Tunnel Group Policy PIX 7.0/ASA
Tunnel Group Policy General Tab
For more information, see Working with ASA User Groups
Client Address Assignment
Network/Host Objects,
Tunnel Group Policy IPSec Tab
For more information, see Supported AAA Server Types
Tunnel Group Policy Advanced Tab
More information, see Working with Interface Role Objects
Tunnel Group Policy PIX 7.0/ASA
Tunnel Group Policy Client VPN Software Update Tab
Client Connection Characteristics
Table B-29 Easy VPN Remote Client Connection Characteristics
Working with Site-to-Site VPN Policies,
About Locking in Site-to-Site VPN Topologies,
For more information, see About Editing a VPN Topology
See Site to Site VPN Policies, page B-37
For more information, see Deleting a VPN Topology,
OL-8214-02
OL-8214-02