
8-3
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 8 Managing VPN Remote Access
Using the PIX Firewall as an Easy VPN Server
Note PIX Firewall Version 6.3 introduces a feature that lets you establish a management connection to the
inside interface of a PIX
Firewall over a VPN tunnel. This feature is designed for remote management
of a PIX
Firewall used as an Easy VPN Remote device, which typically has an IP address dynamically
assigned to its outside interface. For further information, refer to “
Connecting to PIX Firewall Over a
VPN Tunnel” in Chapter 9, “Accessing and Monitoring PIX Firewall.”
For information about configuring remote access for other VPN software clients, including L2TP,
Windows 2000, and Cisco Secure VPN Client Version 1.1, refer to
Appendix B, “Configuration
Examples for Other Remote Access Clients.”
Note Before you install the Cisco VPN 3000 Client Version 2.5 or the Cisco VPN Client Version 3.x on a
remote host computer, uninstall any Cisco Secure VPN Client Version 1.1 software and clear the
associated directories.
The configuration of the PIX Firewall as an Easy VPN Server is similar regardless of the type of Easy
VPN Remote device that you are using. However, certain Easy VPN Server features and options only
apply when using an Easy VPN Remote hardware client.
For instance, when using a hardware client, two different modes of operation can be enabled on the Easy
VPN Remote device:
• Client mode
• Network extension mode
Client mode causes VPN connections to be initiated by traffic from the Easy VPN Remote device, so
resources are only used on demand. In client mode, the Easy VPN Remote device applies Network
Address Translation (NAT) to all IP addresses of clients connected to the inside (higher security)
interface of the Easy VPN Remote device.
Network extension mode keeps VPN connections open even when not required for transmitting traffic
and no address translation is applied. In network extension mode, the IP addresses of clients on the inside
interface of the Easy VPN Remote device are sent without change to the Easy VPN Server.
Note Client mode and network extension mode are configured on the Easy VPN Remote device. For more
information, refer to “
Using PIX Firewall as an Easy VPN Remote Device” in Chapter 4, “Using PIX
Firewall in SOHO Networks.”
The PIX Firewall uses the IKE Mode Config protocol to download the attributes to the Easy VPN
Remote device, including the following:
• DNS, WINS, and default domain (in client mode)
• Split tunnel mode attributes
The split tunnel mode allows the PIX Firewall to define a policy for encrypting certain traffic and
transmitting other traffic in clear text. With split tunnelling enabled, the VPN client PC can access the
Internet while the VPN client is running. For more information about configuring these parameters, refer
to “
Configuring Easy VPN Remote Devices with IKE Mode Config” in Chapter 8, “Managing VPN
Remote Access.”
Comentários a estes Manuais