Configuring IPsec Remote Access VPN
The administrator completes the following steps to configure IPsec remote access VPN on the Cisco ASAs:
Step 1 Log in to the Cisco ASA using ASDM. Step 2 On the main menu, choose Wizards. Step 3 Select the IPsec VPN Wizard.
Step 4 The IPsec VPN Wizard starts. Specify the tunnel type as shown in Figure 12-60.
Figure 12-60 Configuring the Tunnel Type
Figure 12-60 Configuring the Tunnel Type
Step 5 All remote access VPN clients will be connecting to the outside interface. Choose the outside interface from the VPN Tunnel Interface drop-down menu, as shown in Figure 12-60.
Step 6 Enable inbound IPsec sessions to bypass all configured ACLs, as shown in Figure 12-60.
Step 7 Click Next.
Step 8 The screen shown in Figure 12-61 is displayed. Under VPN Client Type, click Cisco VPN Client, Release 3.x or higher, or other Easy VPN Remote product.
Figure 12-61 Remote Access VPN Client Type
|
St VPN Wizard [x | |
|
|
" VPN Wizard |
Remote Access Client (Step 2 of...) |
|
Remote access users oF various types can open VPN tunnels to this ASA, Select the type oF VPN client For this tunnel. |
|
|
VPN Client Type: |
|
|
© Cisco VPN Client, Release 3.x or higherj or other Easy VPN Remote product |
|
|
Ilir^j |
Q MicrosoFt Windows client using L2TP over IPsec |
|
Specify the PPP authentication protocol. IF a protocol is not specified on the remote client, do not specify it. □ PAP 0 CHAP 0MS-CHAP-V1 Q M5-CHAP-V2 □EAP-PROXY 5peciFy if the client will send tunnel group name as - username@tunnelgroup, |
|
|
QjClient will send tunnel group name as username@tunnelgroup. |
|
|
1 J^i H, ^^^Pf 1 |
If pre-shared authentication is used with this option then DefaultRAGroup's pre-shared key and ppp authentication are also modified. |
|
[ < Back ]| Next > ] Finish | Cancel ] [ Help ] |
|
Step 9 Click Next.
Step 10 The screen shown in Figure 12-62 is displayed. Configure a preshared key and a VPN tunnel group, as shown in Figure 12-62. In this example, the preshared key is 1qaz2wsx, and the tunnel group is IPSEC-RA-GROUP.
Step 11 Click Next.
Step 12 The screen shown in Figure 12-63 is displayed. In this example, the Cisco ASAs are configured for external authentication to a RADIUS server. The AAA server group name is RADIUS-Server, as shown in Figure 12-63.
Figure 12-62 VPN Client Authentication Method and Tunnel Group Name
Figure 12-62 VPN Client Authentication Method and Tunnel Group Name

- Figure 12-63 Client Authentication
Step 13 Click Next.
Step 14 The screen shown in Figure 12-64 is displayed. This screen allows you to configure an IP address pool used for remote access VPN connections. Click New to add a new pool.
Figure 12-64 IPsec Remote Access VPN IP Address Pool
Figure 12-64 IPsec Remote Access VPN IP Address Pool
Step 15 Specify a name for the IP address pool. In this example, the name of the pool is IPSec-Pool.
Step 16 Configure the starting and ending IP addresses, in addition to a subnet mask. In this example, the address range in the pool is from 10.250.50.1 to 10.250.50.254, with a 24-bit subnet mask (255.255.255.0).
Step 17 Click Next.
Step 18 The screen shown in Figure 12-65 is displayed. This screen allows you to configure the primary and secondary DNS and WINS servers, in addition to the domain name. In this example, the primary DNS server is 172.18.124.12; the secondary DNS server is 172.18.124.13; the primary WINS server is 172.18.124.14; and the secondary WINS server is 172.18.124.15. The domain name is companyc.com.
Figure 12-65 DNS and WINS Server Configuration
Figure 12-65 DNS and WINS Server Configuration
Step 19 Click Next.
Step 20 The screen shown in Figure 12-66 is displayed. This screen allows you to configure the IKE policy used by remote access VPN connections. In this example, the encryption algorithm used is AES-256. SHA is used for authentication, and the Diffie-Hellman (DH) group used is 5.
Step 21 Click Next.
Step 22 The screen shown in Figure 12-67 is displayed. This screen allows you to configure the IPsec encryption and authentication parameters. In this example, the encryption protocol used is AES-256, and SHA is used for IPsec Phase 2 authentication.
Figure 12-66 Remote Access VPN IKE Policy
Figure 12-66 Remote Access VPN IKE Policy
Figure 12-67 Remote Access VPN IPsec Encryption and Authentication
Figure 12-67 Remote Access VPN IPsec Encryption and Authentication
Step 23 Click Next.
Step 24 The screen shown in Figure 12-68 is displayed. This screen allows you to configure the Cisco ASA to bypass NAT for remote access VPN connections. In this case, the inside network is selected (10.250.10.0/24). The inside 10.250.10.0/24 network will not be translated when communicating with remote access VPN clients.
Figure 12-68 Bypassing NAT and Configuring Split Tunneling
Figure 12-68 Bypassing NAT and Configuring Split Tunneling
Step 25 The screen shown in Figure 12-68 also allows you to configure split tunneling for remote access VPN connections. To enable split tunneling, select Enable split tunneling to let remote users have simultaneous encrypted access to the resources defined earlier, and unencrypted access to the Internet option.
Step 26 Click Next.
Step 27 A summary screen appears. Click Finish to apply the changes to the Cisco ASA.
Continue reading here: Configuring Load Balancing
Was this article helpful?