Cisco SA520-K9 Administration Guide - Page 147

Configuring VPN, the User Database for the IPsec Remote Access VPN,

Page 147 highlights

Configuring VPN Advanced Configuration of IPsec VPN 7 NOTE The double-quote character (") is not permitted for the shared key. • Pre-shared key: Enter the alpha-numeric key to be shared with IKE peer. • Diffie-Hellman (DH) Group: Choose the Diffie-Hellman algorithm to use when exchanging keys. The DH Group sets the strength of the algorithm in bits. • SA Lifetime (seconds): Enter the number of seconds for the Security Association to remain valid. • Enable Dead Peer Detection: Check this box to enable the security appliance to detect whether a peer is alive or not. If a peer is detected as dead, then the security appliance deletes the IPsec and IKE Security Association. • Detection Period (seconds): Detection Period is the interval between consecutive DPD R-U-THERE messages. DPD R-U-THERE messages are sent only when the IPsec traffic is idle. • Reconnect after failure count: Maximum number of DPD failures allowed before tearing down the connection. STEP 7 In the Extended Authentication (XAUTH) area, you can enable the VPN gateway router to authenticate users from the User Database (default choice) or an external authentication server such as a RADIUS server. Choose one of the following XAUTH Types: • None: Choose this option to disable XAUTH. • User Database: Choose this option if you want to authenticate users based on the accounts that you create in this Configuration Utility. If you choose this option, be sure to add the users on the IPsec Users page. See Configuring the User Database for the IPsec Remote Access VPN, page 142. • IPsec Host: Choose this option if you want the security appliance to be authenticated with a username and password combination. In this mode, the security appliance acts as a VPN Client of the remote gateway. If you choose this option, also enter a Username and Password. - Username: If you chose IPsec Host as the XAUTH Type, enter the user name for the security appliance to use when connecting to the remote server. The username can include any alphanumeric characters. - Password: Enter the password for the security appliance to use when connecting to the remote server. Cisco SA500 Series Security Appliances Administration Guide 147

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240

Configuring VPN
Advanced Configuration of IPsec VPN
Cisco SA500 Series Security Appliances Administration Guide
147
7
NOTE
The double-quote character (“) is not permitted for the shared key.
Pre-shared key:
Enter the alpha-numeric key to be shared with IKE peer.
Diffie-Hellman (DH) Group:
Choose the Diffie-Hellman algorithm to use
when exchanging keys. The DH Group sets the strength of the algorithm in
bits.
SA Lifetime (seconds):
Enter the number of seconds for the Security
Association to remain valid.
Enable Dead Peer Detection:
Check this box to enable the security
appliance to detect whether a peer is alive or not. If a peer is detected as
dead, then the security appliance deletes the IPsec and IKE Security
Association.
Detection Period (seconds):
Detection Period is the interval between
consecutive DPD R-U-THERE messages. DPD R-U-THERE messages are
sent only when the IPsec traffic is idle.
Reconnect after failure count:
Maximum number of DPD failures allowed
before tearing down the connection.
STEP 7
In the
Extended Authentication (XAUTH)
area, you can enable the VPN gateway
router to authenticate users from the User Database (default choice) or an external
authentication server such as a RADIUS server. Choose one of the following
XAUTH Types
:
None:
Choose this option to disable XAUTH.
User Database:
Choose this option if you want to authenticate users based
on the accounts that you create in this Configuration Utility. If you choose this
option, be sure to add the users on the IPsec Users page. See
Configuring
the User Database for the IPsec Remote Access VPN, page142
.
IPsec Host:
Choose this option if you want the security appliance to be
authenticated with a username and password combination. In this mode, the
security appliance acts as a VPN Client of the remote gateway. If you choose
this option, also enter a Username and Password.
-
Username:
If you chose IPsec Host as the XAUTH Type, enter the user
name for the security appliance to use when connecting to the remote
server. The username can include any alphanumeric characters.
-
Password:
Enter the password for the security appliance to use when
connecting to the remote server.