Cisco Systems OL-5532-02 manual Defining the VPN 3000 Access Hours

Models: OL-5532-02

1 32
Download 32 pages 17.82 Kb
Page 20
Image 20

Chapter 4 Remote Access VPN Services

Creating Remote Access VPN Policies

Table 4-8 VPN 300 Editor Fields (continued)

Field Name

Type

Instructions

 

 

 

Allow IPsec

checkbox

The Allow IPsec through NAT option lets you use the Cisco VPN Client to connect

Through NAT

 

to the VPN Concentrator via UDP through a firewall or router that is running NAT.

 

 

Enabling this feature creates runtime filter rules that forward UDP traffic for the

 

 

configured port even if other filter rules on the interface drop UDP traffic. These

 

 

runtime rules exist only while there is an active IPsec through NAT session. The

 

 

system passes inbound traffic to IPsec for decryption and unencapsulation, and then

 

 

passes it on to the destination. The system passes outbound traffic to IPsec for

 

 

encryption and encapsulation, applies a UDP header, and forwards it.

 

 

Check to enable the IPsec client to operate through a firewall using NAT via UDP.

 

 

Uncheck (disable) this option to prevent to IPsec clients from operating through a

 

 

firewall that is using NAT.

 

 

 

IPsec Through NAT

text box

If you selected Allow IPsec Through NAT, enter the UDP port to be used for IPsec

Port

 

traffic, using any port from 4001 to 49151. The default is 10000.

 

 

 

Allow Password

checkbox

Check to allow the IPsec client to store its password locally.

Storage on Client

 

 

 

 

 

Banner

text box

Enter the banner text to display for this group. The banner cannot exceed 512

 

 

characters.

 

 

 

Step 3 Click Next to continue to the VPN 3000 Access Hours page as shown Figure 4-20in the “Defining the VPN 3000 Access Hours” section on page 4-20.

Defining the VPN 3000 Access Hours

For connections made through VPN 3000 devices in your network, you can control when a user has access to your private network through the remote access VPN.

Perform the following steps to restrict user access to specific hours during the day or night:

Step 1 The Remote Access VPN Policy – Access Hours page appears as shown in Figure 4-20.

Figure 4-20 The Remote Access VPN Policy – Access Hours Page

Cisco IP Solution Center Integrated VPN Management Suite Security User Guide, 3.2

4-20

OL-5532-02

 

 

Page 20
Image 20
Cisco Systems OL-5532-02 manual Defining the VPN 3000 Access Hours