Professional Documents
Culture Documents
SNRS v2.04-1
SNRS v2.04-2
Creating a local address pool is optional if you are using an external DHCP server.
SNRS v2.04-3
R1
aaa new-model aaa authentication login vpn-users local aaa authorization network vpn-group local username cisco password 0 cisco
SNRS v2.04-4
SNRS v2.04-5
R1
R1(config)# crypto isakmp client configuration group R6 R1(config-isakmp-group)# key VPNKEY R1(config-isakmp-group)# dns 10.0.1.13 10.0.1.14 R1(config-isakmp-group)# wins 10.0.1.13 10.0.1.14 R1(config-isakmp-group)# domain cisco.com R1(config-isakmp-group)# pool Remote-Pool R1(config-isakmp-group)# save-password
SNRS v2.04-6
R1
isakmp enable isakmp policy 10 authentication pre-share encryption 3des group 2 end
SNRS v2.04-7
Remote Clients
R1
SNRS v2.04-8
SNRS v2.04-9
Remote Clients
Dynamic-Map 10
transform-set VPNTRANSFORM reverse-route
R1
R1(config)# crypto dynamic-map Dynamic-Map 10 R1(config-crypto-map)# set transform-set VPNTRANSFORM R1(config-crypto-map)# reverse-route R1(config-crypto-map)# end
SNRS v2.04-10
SNRS v2.04-11
R1
client configuration address respond isakmp authorization list vpn-group client authentication list vpn-users 65535 ipsec-isakmp dynamic Dynamic-Map
SNRS v2.04-12
Remote Client
Fa0/1
R1
SNRS v2.04-13
R1
router(config)#
SNRS v2.04-14
Configure XAUTH
Step 1: Enable AAA login authentication. Step 2: Set the XAUTH timeout value. Step 3: Enable ISAKMP XAUTH for the dynamic crypto map.
SNRS v2.04-15
Remote Client
SNRS v2.04-16
20 Seconds
Remote Client VPN user group VPNUSERS R1
SNRS v2.04-17
Remote Client
SNRS v2.04-18
R1
Group VPN-REMOTE-ACCESS
This step could have been completed in Step 1 of Task 4 following the crypto isakmp client configuration group command.
2007 Cisco Systems, Inc. All rights reserved. SNRS v2.04-19
Verify
SNRS v2.04-20
Configuring Cisco Easy VPN Remote for the Cisco VPN Client v4.x: General Tasks
Install Cisco VPN Client v4.x. Create a new client connection entry. Choose an authentication method. Configure transparent tunneling. Enable and add backup servers. Configure a connection to the Internet through dialup networking.
SNRS v2.04-21
SNRS v2.04-22
SNRS v2.04-23
SNRS v2.04-24
SNRS v2.04-25
SNRS v2.04-26
SNRS v2.04-27
SNRS v2.04-28
Routes Table
SNRS v2.04-29
SNRS v2.04-30
SNRS v2.04-31
Summary
Cisco Easy VPN simplifies the configuration of VPNs using routers as Easy VPN servers and clients. An access router can be configured as a Cisco Easy VPM remote client. The Cisco Easy VPN Server feature allows a remote end user to communicate using IPsec with any Cisco IOS VPN gateway. The Cisco VPN Client is simple to deploy and operate.
SNRS v2.04-32
SNRS v2.04-33