Appendix B Site-to-Site VPN User Interface Reference

Create VPN Wizard

Table B-10

Edit Endpoints Dialog Box > FWSM Tab (continued)

 

 

 

Element

 

Description

 

 

FWSM Inside VLAN

The VLAN which serves as the inside interface to the Firewall

 

 

Services Module (FWSM).

 

 

If required, click Select to open a dialog box that lists all available

 

 

interfaces, and sets of interfaces defined by interface roles, and in

 

 

which you can make your selection, or create interface role objects.

 

 

For more information, see Interface Roles Page, page C-126.

 

 

 

FWSM Blade

 

From the list of available blades, select the blade number to which

 

 

the selected FWSM inside VLAN interface is connected.

 

 

Security Context

If the selected FWSM inside VLAN is part of a security context,

 

 

specify its name in this field. The name is case-sensitive.

 

 

You can partition an FWSM into multiple virtual firewalls, known

 

 

as security contexts. A security context is an independent virtual

 

 

firewall that has its own security policy, interfaces, and

 

 

administrators. You can define security contexts when you import a

 

 

Catalyst 6500/7600 device into the Security Manager inventory.

 

 

For more information, see Security Contexts Page, page C-475.

 

 

 

OK button

 

Saves your changes locally on the client and closes the dialog box.

 

 

 

Cancel button

 

Closes the dialog box without saving your changes.

 

 

 

Help button

 

Opens help for this tab.

 

 

 

VRF Aware IPSec Tab

Use the VRF-Aware IPSec tab on the Edit Endpoints dialog box to configure a VRF-Aware IPSec policy on a hub in your hub-and-spoke VPN topology. When you select the row in the Endpoints table that contains the required hub device (the IPSec Aggregator), and click Edit, the VRF Aware IPSec tab opens. You can configure VRF-Aware IPSec as a one-box or two-box solution.

 

 

Note

In a VPN topology with two hubs, you must configure VRF-Aware IPSec on

 

 

 

both devices.

 

 

 

You cannot configure VRF-Aware IPSec on a device that belongs to another

 

 

 

VPN topology in which VRF-Aware IPSec is not configured.

 

 

User Guide for Cisco Security Manager 3.0.1

 

 

B-28

 

 

 

OL-8214-02

 

 

 

 

 

 

 

 

 

 

Page 28
Image 28
3D Innovations 3.0.1 appendix VRF Aware IPSec Tab, For more information, see Interface Roles Page, page C-126