240 likes | 261 Views
Network Security 2. Module 6 – Configure Remote Access VPN. Module 6 – Configure Remote Access VPN. Lesson 6.2 Configure the EasyVPN Server. Easy VPN Server General Configuration Tasks. The following general tasks are used to configure Easy VPN Server on a Cisco router –
E N D
Network Security 2 Module 6 – Configure Remote Access VPN
Module 6 – Configure Remote Access VPN Lesson 6.2 Configure the EasyVPN Server
Easy VPN Server General Configuration Tasks • The following general tasks are used to configure Easy VPN Server on a Cisco router – • Task 1 – Create IP address pool. • Task 2 – Configure group policy lookup. • Task 3 – Create ISAKMP policy for remote VPN Client access. • Task 4 – Define group policy for mode configuration push. • Task 5 – Create a transform set. • Task 6 – Create a dynamic crypto map with RRI. • Task 7 – Apply mode configuration to the dynamic crypto map. • Task 8 – Apply the crypto map to the router interface. • Task 9 – Enable IKE DPD. • Task 10 – Configure XAUTH. • Task 11 – (Optional) Enable XAUTH save password feature.
Task 2 – Configure Group Policy Lookup • Creates a user group for local AAA policy lookup
Task 4 – Define Group Policy for Mode Configuration Push • Task 4 contains the following steps – • Step 1 – Add the group profile to be defined. • Step 2 – Configure the ISAKMP pre-shared key. • Step 3 – Specify the DNS servers. • Step 4 – Specify the WINS servers. • Step 5 – Specify the DNS domain. • Step 6 – Specify the local IP address pool.
Task 6 – Create a Dynamic Crypto Map with RRI • Task 6 contains the following steps – • Step 1 – Create a dynamic crypto map. • Step 2 – Assign a transform set. • Step 3 – Enable RRI.
Task 7 – Apply Mode Configuration to Crypto Map • Task 7 contains the following steps – • Step 1 – Configure the router to respond to mode configuration requests. • Step 2 – Enable IKE querying for a group policy. • Step 3 – Apply the dynamic crypto map to the crypto map.
Task 10 – Configure XAUTH • Task 10 contains the following steps – • Step 1 – Enable AAA login authentication. • Step 2 – Set the XAUTH timeout value. • Step 3 – Enable ISAKMP XAUTH for the dynamic crypto map.