Cisco SA520-K9 Administration Guide - Page 153

Configuring IPsec Passthrough, Configuring a Dynamic IP Range

Page 153 highlights

Configuring VPN Advanced Configuration of IPsec VPN 7 • To configure IPsec passthrough, click IPsec > Passthrough. For more information, see Configuring IPsec Passthrough, page 153. • To configure a range for a dynamic IP address, see Configuring a Dynamic IP Range, page 153. • To add the users for remote access VPN, see Configuring the User Database for the IPsec Remote Access VPN, page 142. • If you enabled rollover, be sure to configure Dynamic DNS. See Dynamic DNS, page 76. Configuring IPsec Passthrough You need to configure IPsec passthrough if there are devices behind the security appliance that need to set up IPsec tunnels independently, for example, to connect to another router on the WAN. STEP 1 Click VPN > IPsec > Passthrough. The Passthrough window opens. STEP 2 Check the box for each type of traffic that you want to allow to pass through the VPN tunnel. STEP 3 Click Apply to save your settings. Configuring a Dynamic IP Range The IP address is defined by the Dynamic IP Range and is automatically set by default. However, you can use the Dynamic IP Range page to manually specify a starting and ending range for the IP address. The Dynamic IP Range is used by IPsec VPN clients connecting to the router using Mode- Config. NOTE If you are creating a VPN policy and want to change the dynamic IP address, change it before you create the policy. Otherwise, the changes will not take affect. STEP 1 Click VPN > IPsec > Dynamic IP Range. The Dynamic IP Range window opens. STEP 2 Enter a Start IP range and End IP range for the IP address. Cisco SA500 Series Security Appliances Administration Guide 153

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240

Configuring VPN
Advanced Configuration of IPsec VPN
Cisco SA500 Series Security Appliances Administration Guide
153
7
To configure IPsec passthrough, click
IPsec > Passthrough
. For more
information, see
Configuring IPsec Passthrough, page153
.
To configure a range for a dynamic IP address, see
Configuring a Dynamic
IP Range, page 153
.
To add the users for remote access VPN, see
Configuring the User
Database for the IPsec Remote Access VPN, page 142
.
If you enabled rollover, be sure to configure Dynamic DNS. See
Dynamic
DNS, page 76
.
Configuring IPsec Passthrough
You need to configure IPsec passthrough if there are devices behind the security
appliance that need to set up IPsec tunnels independently, for example, to connect
to another router on the WAN.
STEP 1
Click
VPN
> IPsec > Passthrough
.
The Passthrough window opens.
STEP
2
Check the box for each type of traffic that you want to allow to pass through the
VPN tunnel.
STEP
3
Click
Apply
to save your settings.
Configuring a Dynamic IP Range
The IP address is defined by the Dynamic IP Range and is automatically set by
default. However, you can use the Dynamic IP Range page to manually specify a
starting and ending range for the IP address.
The Dynamic IP Range is used by IPsec VPN clients connecting to the router using
Mode- Config.
NOTE
If you are creating a VPN policy and want to change the dynamic IP address,
change it before you create the policy. Otherwise, the changes will not take affect.
STEP 1
Click
VPN
> IPsec > Dynamic IP Range.
The Dynamic IP Range window opens.
STEP
2
Enter a Start IP range and End IP range for the IP address.