Chapter9 Easy VPN Remote
Edit Easy VPN Remote
9-100
Cisco Router and Security Device Manager Version 2.2 Users Guide
OL-4015-08
The information is saved in the router configuration file and used each time
the tunnel is established.
Caution Storing the XAuth username and password in router memory c reates a security
risk because anyone who has access to the router configuration can obtain this
information. If you do not want this information stored on the router, do not enter
it here. The Easy VPN server will simply challenge the router for the username
and password each time the connection is established. Also, SDM cannot itself
determine whether the server allows passwords to be saved. You must determine
whether the server allows this option. If the server does not allow passwords to be
saved, you should not create a security risk by entering the information here.
Add or Edit Easy VPN Remote: Interfaces and Connections
In this window you can set the inside and outside interfaces, and specify how the
tunnel is brought up.
Inside Interfaces
Choose the inside (LAN) interface to associate with this Easy VPN configuration.
You can choose multiple inside interfaces, with the following restrictions:
If you choose interfaces that are already used in another Easy VPN
configuration, you are notified that an interface cannot be part of two Easy
VPN configurations.
If you choose interfaces that are already used in a standard VPN
configuration, you are notified that the Easy VPN configuration you are
creating cannot coexist with the existing VPN configuration. SDM will ask if
you want to remove the existing VPN tunnels from those interfaces and apply
the Easy VPN configuration to them.
An existing interface does not appear in the list of interfaces if it cannot be
used in an Easy VPN configuration. For example, loopback interfaces
configured on the router do not appear in this list.
An interface cannot be designated as both an inside and an out side interface.
Up to three inside interfaces are supported on Cisco 800 and Cisco 1700 seri es
routers. You can remove interfaces from an Easy VPN configuration in the Edit
Easy VPN Remote window.