CHAP TER
30-1
User Guide for Cisco Security Manager 4.4
OL-28826-01
30
Managing Remote Access VPNs on ASA and PIX 7.0+ Devices
You can configure and manage remote access IPsec on devices running Cisco ASA Software or PIX
7.0+, and SSL VPNs on ASA 8.0+ devices (but not on PIX devices). Additionally, you can use IKE
version 2 (IKEv2) negotiations in remote access IPsec VPNs on ASA 8.4(x) devices.
Tip No VPN configuration is supported on Cisco Catalyst 6500 Series ASA Service Modules and the ASA
Software Release 8.5(x) used on the module.
The configuration of these remote access VPNs are the same for these device types. IOS and PIX 6.3+
devices use different configurations for remote access VPNs (as explained in Chapter 32, “Managing
Remote Access VPNs on IOS and PIX 6.3 Devices”).
The topics in this chapter explain how to configure policies that are specific to ASA and PIX 7.0+
devices. Additionally, review the following topics for more information about remote access VPNs:
Understanding Remote Access VPNs, page 29-1
Understanding Devices Supported by Each Remote Access VPN Technology, page 29-8
Discovering Remote Access VPN Policies, page 29-12
Using the Remote Access VPN Configuration Wizard, page29-13
Creating IPSec VPNs Using the Remote Access VPN Configuration Wizard (ASA and PIX 7.0+
Devices), page 29-24
Creating SSL VPNs Using the Remote Access VPN Configuration Wizard (ASA Devices),
page 29-14
Chapter 31, “Managing Dynamic Access Policies for Remote Access VPNs (ASA 8.0+ Devices)”
This chapter contains the following topics:
Overview of Remote Access VPN Policies for ASA and PIX 7.0+ Devices, page 30-2
Understanding Cluster Load Balancing (ASA), page 30-4
Configuring Connection Profiles (ASA, PIX 7.0+), page 30-6
Configuring Group Policies for Remote Access VPNs, page 30-21
Understanding SSL VPN Server Verification (ASA), page 30-25
Working with IPSec VPN Policies, page30-28
Working with SSL and IKEv2 IPSec VPN Policies, page30-36