Cisco PIX 525 Especificações Página 284

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 466
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes
Vista de página 283
8-4
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 8 Managing VPN Remote Access
Using the PIX Firewall as an Easy VPN Server
Enabling Redundancy
PIX Firewall Version 6.3 introduces support for redundancy among Easy VPN Servers. You can define
a list of servers on an Easy VPN Server that can be pushed to the Easy VPN Remote. When no backup
Easy VPN Server is configured, what happens after a failure to connect to the Easy VPN server depends
on SUA status and whether the Easy VPN Remote device is in client mode or network extension mode.
In client mode, without SUA, traffic continues to trigger subsequent connections to the Easy VPN
Server. In network extension mode, without SUA, the Easy VPN Remote device continually tries to
reconnect to the primary server. With SUA, a connection failure message is displayed and all connection
attempts must be manually triggered.
To define a list of backup servers, enter the following command on the PIX Firewall used as the Easy
VPN Server:
vpngroup groupname backup-server ipaddr1 [ipaddr2 .. ipaddr10]
To clear the current client configuration, enter the following command on the PIX Firewall used as the
Easy VPN Server:
vpngroup groupname backup-server clear-client-cfg
Configuring Secure Unit Authentication
Secure Unit Authentication (SUA) provides increased security when allowing access to an Easy VPN
Server from an Easy VPN Remote device. With SUA, one-time passwords, two-factor authentication,
and similar authentication schemes can be used to authenticate the Easy VPN Remote device during
Extended Authentication (Xauth). SUA is specified in the VPN Policy on the Easy VPN Server and is
downloaded to the Easy VPN Remote device. This enables SUA and determines the connection behavior
of the Easy VPN Remote device.
To add SUA to the VPN policy for a VPN group, enter the following command at the CLI of the Easy
VPN Server:
vpngroup groupname secure-unit-authentication
This command enables SUA for the VPN group identified by groupname.
To disable SUA for a VPN policy, remove the configuration for the corresponding VPN group. Note that
VPN policy changes are updated on Easy VPN Remote devices only after the next connection following the
policy configuration change.
Configuring Individual User Authentication
Individual User Authentication (IUA) supports individually authenticating clients on the inside network
of the Easy VPN Remote, based on the IP address of each inside client. IUA supports both static and
OTP authentication mechanisms.
IUA is enabled by means of the downloaded VPN policy and it cannot be configured locally. To enable
IUA on a PIX
Firewall used as the Easy VPN Server, enter the following command:
vpngroup groupname user-authentication
This command enables individual user authentication for the VPN group identified by groupname.
Vista de página 283
1 2 ... 279 280 281 282 283 284 285 286 287 288 289 ... 465 466

Comentários a estes Manuais

Sem comentários