9-81
Cisco Router and Security Device Manager Version 2.2 Users Guide
OL-4015-08
Chapter9 Easy VPN Remote
Create Easy VPN Remote
Inside Interfaces
Choose the inside (LAN) interface to associate with this Easy VPN configuration.
You can choose multiple inside interfaces, with the following restrictions:
If you choose an interface that is already used in another Easy VPN
configuration, you are told that an interface cannot be part of two Easy VPN
configurations.
If you choose interfaces that are already used in a VPN configura tion, you are
informed that the Easy VPN configuration you are creating cannot coexist
with the existing VPN configuration. You will be asked if you want to remove
the existing VPN tunnels from those interfaces and apply the Easy VPN
configuration to them.
An existing interface does not appear in the list of interfaces if it cannot be
used in an Easy VPN configuration. For example, loopback interfaces
configured on the router do not appear in this list.
An interface cannot be designated as both an inside and an out side interface.
Up to three inside interfaces are supported on Cisco 800 and Cisco 1700 seri es
routers. You can remove interfaces from an Easy VPN configuration in the Edit
Easy VPN Remote window.
Outside Interface
Choose the outside interface that connects to the Easy VPN server or concentrator.
Note Cisco 800 routers do not support the use of interface E 0 as the outside interface
Connection Control
Choose automatic, manual, or traffic-based VPN tunnel activation.
With the manual setting, you must click the Connect or Disconnect button in the
Edit Easy VPN Remote window to establish or take down the tunnel, but you will
have full manual control over the tunnel in the Edit Easy VPN Remote window.
Additionally, if a security association (SA) timeout is set for the router, you will
have to manually reestablish the VPN tunnel whenever a timeout occurs. You can
change SA timeout settings in the VPN Components VPN Global Settings
window.