Overview of Port Address Translation

38 Overview of Port Address Translation In order to understand the issues involved when using Port Address Translation (PAT), you first need to understand how Network Address Translation (NAT) works. NAT is the process of changing the source IP address on all packets sent out by a host and changing the destination IP address of all incoming packets for that host. This prevents hosts outside of the LAN from knowing the true IP address of a local host. While not a true security method in itself,...

Chapter 2Do I Know This Already

1 Which Cisco hardware product families support IPSec VPN technology Cisco IOS routers, PIX Firewalls, and VPN 3000 Series Concentrators, including the VPN 3002 Hardware Client, support IPSec VPN technology. 2 What are the two IPSec protocols The two IPSec protocols are Authentication Header (AH) and Encapsulating Security Payload (ESP). 3 Which type of VPNs use a combination of the same infrastructures that are used by the other two types of VPNs Business-to-business, or extranet, VPNs use a...

RSA Encrypted Nonces

A twist in the way digital signatures are used is the process of using RSA encrypted nonces for peer authentication. A nonce is a pseudorandom number. This process requires registration with a CA to obtain RSA digital certificates. Peers do not share public keys in this form of authentication. They do not exchange digital certificates. The process of sharing keys is manual and must be done during the initial setup. RSA encrypted nonces permit repudiation of the communication, where either peer...

Cisco Secure VPN Concentrators Comparison and Features

6 Cisco VPN 3000 Concentrator Series models Now that you've learned about some of the features of the Cisco VPN 3000 Series Concentrators, this section takes a closer look at the individual products in the series. Each of the concentrators in this series is shipped with the Cisco VPN Client, with unlimited distribution licensing. Additionally, each of these concentrators contains the powerful Cisco VPN Manager software in memory. These systems come as a complete package, ready to drop into your...

Unit and User Authentication for the VPN 3002 Hardware Client

28 Overview of VPN 3002 interactive unit and user authentication feature 29 Configuring VPN 3002 integrated unit authentication feature 30 Configuring VPN 3002 user authentication When two devices begin negotiations to establish an IPSec VPN connection between them, they must perform an authentication process during IKE Phase 1. This authentication process is structured around preshared keys or digital signatures. Additionally, the Cisco VPN 3000 Series Concentrators and the VPN 3002 Hardware...

Performance and Scalability

The 3DES-encrypted throughput on the Cisco VPN Concentrators is rated at up to 100 Mbps without performance degradation. This is accomplished by using Scalable Encryption Processors (SEPs) on the modular devices. These SEPs are powered by programmable digital signal processors (DSPs) in the encryption engine. Each SEP provides 25 Mbps of 3DES encryption, making the VPN concentrators scalable. The software-based DSPs give Cisco the ability to respond to changing standards without the need for...

IPSec protocol framework

IP Security Protocol (IPSec) is a collection of open standards that work together to establish data confidentiality, data integrity, and data authentication between peer devices. These peers can be pairs of hosts or pairs of security gateways (routers, firewalls, VPN concentrators, and so on), or they can be between a host and a security gateway, as in the case of remote access VPNs. IPSec can protect multiple data flows between peers, and a single gateway can support many simultaneous, secure...

Chapter 5Do I Know This Already

1 What Public Key Cryptography Standard (PKCS) is used to enroll with a CA PKCS 10 is the standard form generally used to request certificate enrollment with a CA. 2 What field in the certificate request should match the IPSec group name on the VPN concentrator The Organization Unit (OU) should match the IPSec group name on the VPN concentrator. 3 What elements make up the X.500 distinguished name Six fields make up the X.500 distinguished name Common Name (CN), Organizational Unit (OU),...

Final Exam Preparation Tips

This book contains most of the material that you need to pass the Cisco Secure VPN exam. Remember, you do not need to know all the answers to pass the exam. Few individuals become certified having received 100 percent on any of the required exams. For the record, the tests are only graded Pass or Fail. Passing by one point is just as good as passing with 100 percent as far as the certification process is concerned. Although you do not need to answer 100 percent of the questions correctly, you...

Chapter Glossary

The following terms were introduced in this chapter or have special significance to the topics within this chapter. antireplay A security service where the receiver can reject old or duplicate packets to protect itself against replay attacks. IPSec provides this optional service by use of a sequence number combined with the use of data authentication. Cisco Unified Client Framework A consistent connection, policy, and key management method across Cisco routers, security appliances, and VPN...

DHCP and ESP are not automatically blocked when using the Stateful Firewall Always On feature Additionally traffic from

5 Why is CPP not used with the Tunnel Everything option CPP is designed to be used with split tunneling because the Tunnel Everything option already blocks all nontunneled traffic. 6 How often does the VPN Client poll the personal firewall when using AYT The VPN Client polls the personal firewall every 30 seconds. 7 How is the Always On option set on the VPN Client The Always On option is set in the Options pull-down menu. The default setting is to have Always On disabled. CPP is configured on...

Configuring Auto Update for the VPN 3002 Hardware Client

35 Overview of the VPN 3002 Auto-Update Feature 36 Configuring the VPN 3002 Auto-Update Feature Auto-update is a process by which the VPN concentrator requires that the connecting clients use a specific version of software. A client attempting to connect to the VPN concentrator with an incorrect software version will be denied access until after the software version becomes current. The VPN concentrator provides VPN Client users a link to the download server where the software can be obtained....

Simple Certificate Enrollment Process Authentication Methods

For Cisco VPN 3000 Concentrators to work with CAs, the CAs must support Cisco's Public Key Infrastructure (PKI) Protocol and the Simple Certificate Enrollment Process (SCEP). VPN concentrators support the use of SCEP to automate the exchange of certificates with a CA server. Cisco sponsored SCEP as an Internet Engineering Task Force (IETF) draft as a way of managing the certificate life cycle. SCEP uses the PKCS 7 standard from RSA Security Inc. to encrypt and sign certificate enrollment...

Unable to ping with an Established Tunnel

If you have an established tunnel and you are still unable to ping the private interface on the VPN Concentrator, you could have overlapping Security Associations (SAs) or you could be incorrectly filtering out the IPSec packets. In the VPN 3002 Hardware Client Manager, go to the Monitoring System Status screen and note the Octets Out field. Next, go to the Monitoring Statistics IPSec screen shown in Figure 8-4 and note the Received Bytes counter. Attempt to ping the VPN Concentrator's inside...

Cisco VPN 3000 Concentrator Series LED Indicators

While the LED indicator panel for the 3005 Concentrator only provides information for system status, the front panel on the 3015 through 3080 Concentrators, shown in Figure 3-16, has numerous LEDs that you can use to quickly check the health of the unit. Figure 3-16 Cisco VPN Concentrator 3015-3080 Front LED Display Panel System Ethernet Linl- Status Expansion Modules CPU Utilization m Active Sessions A description of the LEDs on the front panel of the Cisco 3000 Series Concentrators is given...

Do I Know This Already Quiz

The purpose of the Do I Know This Already quiz is to help you decide what parts of the chapter to use. If you already intend to read the entire chapter, you do not need to answer these questions now. This 15-question quiz helps you determine how to spend your limited study time. The quiz is sectioned into six smaller quizlets, which correspond to the six major topic headings in this chapter. Figure 8-1 outlines suggestions on how to spend your time in this chapter based on your quiz score. Use...

Firewall Setting

The default setting is No Firewall, which means that there is no requirement for any firewall, including the Stateful Firewall (Always On) feature. The other two choices, Firewall Required and Firewall Optional, both work with the Firewall field discussed in the next section. Choosing Firewall Required means that all the users within this group must use the specified firewall. Additionally, this firewall must be running during the time that the tunnel is active. Should the firewall software...

Modify GroupsPPTPL2TP

If you selected PPTP, L2TP, or L2TP over IPSec as an allowable tunneling protocol to be used for VPN connections, you might need to make adjustments to the attributes displayed on the PPTP L2TP Tab, shown in Figure 4-26. Client and VPN concentrator settings must match during VPN tunnel negotiations, or the tunnel is not established. The following attributes are shown on this screen Use Client Address You can allow clients to supply their own address for the client end of the VPN tunnel. This is...

Configuring System Information

The System Info screen is the next screen displayed. Figure 4-9 shows this screen. The date and time settings were entered during the CLI configuration steps. You can enter a system name here along with DNS server, domain name, and default gateway information. Figure 4-9 Configuration Quick System Info Assign a system name hostname to this device. This maybe required if you use DHCP to obtain an address. System Name vpnOl Enter a hostname for the system, e.g. vpnOl. Set the time on your device....

Tunnel Mode

IPSec tunnel mode is used between gateways such as Cisco IOS Software routers, Cisco PIX Firewalls, and Cisco VPN 3000 Series Concentrators. It is also typically used when a host connects to one of these gateways to gain access to networks controlled by that gateway, as would be the case with most remote access users dialing in to a router or concentrator. In Tunnel mode, instead of shifting the original IP header to the left and then inserting the IPSec header, the original IP header is copied...

How IPSec works

Overview of VPN and IPSec Technologies The Internet is an integral part of business communications today. Corporations use it as an inexpensive extension of their local- or wide-area networks. A local connection to an Internet service provider (ISP) enables far-reaching communications for e-commerce, mobile users, sales personnel, and global business partners. The Internet is cheap, easily enabled, stable, resilient, and omnipresent. But it is not secure, at least not in its native state. As a...

Configuring Firewall Filter Rules

Before you can use filter rules from the concentrator, you must configure those rules. Although the concentrator's default configuration comes with some rules, these are not meant for production networks. The default rules are too open for a truly secure environment because they were designed merely to facilitate the building of rules for your individual network. Rules, which are specifications that allow or deny specific types of traffic, can be applied to either an interface or a VPN group....

SCEP Overview

44 Root certificate installation 45 Identity certificate installation Simple Certificate Enrollment Protocol SCEP is a protocol that eases your job as an administrator by enrolling devices with certificate authorities CAs . The advantages of SCEP are that the job of the administrator are greatly simplified by removing much of the manual process previously required and added support for differing operating systems. Using SCEP enables the administrator to use certificates in much less time....

On a Cisco VPN 3005 Concentrator a blinking green system LED indicates that the system is in a shutdown halted state

Chapter 4 Do I Know This Already 505 38 On a Cisco VPN 3000 Concentrator, what does a blinking amber system LED indicate On any of the Cisco VPN 3000 Concentrators, a blinking amber system LED indicates that the system has crashed and halted. 39 What does a blinking green Ethernet link status LED indicate on a Cisco VPN Concentrator A blinking green Ethernet link status LED indicates that the interface is connected to the network and configured, but the interface has been disabled. 40 What does...

VPN 3002 Hardware Client Backup Servers

33 Configuring the VPN 3002 backup server feature Backup servers allow VPN 3002 Hardware Clients to connect to an alternative site when the primary site fails. You can configure backup servers either on a group basis at the central VPN concentrator or on an individual basis on the VPN 3002 Hardware Client. Configuration done on a group basis is pushed to the individual VPN 3002 Hardware Clients defined in the relevant group. As an example, suppose that a company has two main offices and that...

IPSec on the VPN 3002 Hardware Client

Internet Protocol Security IPSec is the standard that enables the VPN 3002 Hardware Client to connect securely to the centralized VPN concentrator. IPSec security methods include address data privacy, authentication, integrity, key management, and tunneling. With the VPN 3002 Hardware Client, two IPSec options are available to you IPSec over TCP IP and IPSec over UDP. You may choose one of these, which will automatically disable the other option. The next sections describe both options in more...