29-30
User Guide for Cisco Security Manager 4.4
OL-28826-01
Chapter 29 Managing Remote Access VPNs: The Basics
Using the Remote Access VPN Configuration Wizard
Remote Access VPN Configuration Wizard—Defaults Page
Use the Defaults page of the Remote Access VPN Configuration wizard to select the shared policies to
assign to the remote access IPSec VPN. Initially, the policies selected are those configured in the
Security Manager Administration VPN Defaults for remote access VPNs. For information on how to
configure these defaults, see Understanding and Configuring VPN Default Policies, page 24-12.
Required policies must always have a policy selected. If “Factory Default” is shown, then the policy
applied is not a shared policy but default policy settings supplied by Security Manager. If you can select
the empty option, the policy is optional and you need to configure it only if you want the associated
features.
When evaluating which policies to assign (if any), keep the following in mind:
The drop-down lists for each policy type list the existing shared policies that you can select. You can
select only shared policies that have been committed to the Security Manager database (and
approved, if you are using Workflow mode with an approver). You cannot create a shared policy and
use it before you submit it.
To view the content of a policy, select it and click the View Conten t button. You are presented with
a read-only view of the policy. Use this to help verify that you are selecting the desired policy.
Note If you try to select a default policy that is currently locked by another user, a message is displayed
warning you of a lock problem. To bypass the lock, select a different policy or cancel the VPN creation
until the lock is removed. For more information, see Understanding Policy Locking, page5-7.
Navigation Path
(Device view) Open the Remote Access VPN Configuration Wizard for configuring a remote access
IPsec VPN (see Using the Remote Access VPN Configuration Wizard, page 29-13) and click Next until
you reach this page.
Related Topics
Creating IPSec VPNs Using the Remote Access VPN Configuration Wizard (ASA and PIX 7.0+
Devices), page 29-24
Creating IPSec VPNs Using the Remote Access VPN Configuration Wizard (IOS and PIX 6.3
Devices), page 29-35
Overview of Remote Access VPN Policies, page 29-9
Field Reference
Table29-8 Remote Access VPN Configuration Wizard, Defaults Page
Element Description
ASA Cluster Load Balance Defines load balancing for an ASA device in your remote access VPN.
High Availability Defines a High Availability (HA) policy on a Cisco IOS router in a
remote access VPN.
Certificate to Connection
Profile Map Policy
(IKEv1 only.) Defines the certificate to connection profile map options
for an ASA device in your remote access VPN.
IKE Proposal Defines the set of algorithms that two peers use to secure the IKE
negotiation between them.