Cisco WS-CE500-24TT Administration Guide - Page 167

Configuring Client Routes for Split Tunnel Mode, Configuring VPN, Configuring Client Routes

Page 167 highlights

Configuring VPN Configuring SSL VPN for Browser-Based Remote Access 7 • Secondary DNS Server (Optional): Enter the IP address of the secondary DNS Server for this client. • Client Address Range Begin: Enter the first IP address that will be assigned to SSL VPN clients. • Client Address Range End: Enter the last IP address that will be assigned to SSL VPN clients. NOTE Configure an IP address range that does not directly overlap with any of addresses on your local network. For example, the default range is 192.168.251.1 to 192.168.251.254. STEP 3 Click Apply to save your settings. NOTE Next steps: If you enable Split Tunnel Support, you also will need to configure SSL VPN Client Routes. After you complete this procedure, see Configuring Client Routes for Split Tunnel Mode, page 167. Configuring Client Routes for Split Tunnel Mode If Full Tunnel support is disabled on the SSL VPN Client page, then you must configure client routes for Split Tunnel Mode. The Configured Client Routes entries are added by the SSL VPN Client such that only traffic to these destination addresses is redirected through the SSL VPN tunnels, and all other traffic is redirected using the hosts (SSL VPN Clients) native network interface. For example if the SSL VPN Client attempts to access this device's LAN network then in Split Tunnel mode, the user should add the LAN subnet as the Destination Network using this page. NOTE You can configure client routes only if Split Tunnel support is enabled on the SSL VPN Client page. See Configuring the SSL VPN Client, page 166. Cisco SA500 Series Security Appliances Administration Guide 167

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240

Configuring VPN
Configuring SSL VPN for Browser-Based Remote Access
Cisco SA500 Series Security Appliances Administration Guide
167
7
Secondary DNS Server (Optional):
Enter the IP address of the secondary
DNS Server for this client.
Client Address Range Begin:
Enter the first IP address that will be assigned
to SSL VPN clients.
Client Address Range End:
Enter the last IP address that will be assigned to
SSL VPN clients.
NOTE
Configure an IP address range that does not directly overlap with any
of addresses on your local network. For example, the default range is
192.168.251.1 to 192.168.251.254.
STEP
3
Click
Apply
to save your settings.
NOTE
Next steps:
If you enable Split Tunnel Support, you also will need to configure SSL VPN Client
Routes. After you complete this procedure, see
Configuring Client Routes for
Split Tunnel Mode, page 167
.
Configuring Client Routes for Split Tunnel Mode
If Full Tunnel support is disabled on the SSL VPN Client page, then you must
configure client routes for Split Tunnel Mode.
The Configured Client Routes entries are added by the SSL VPN Client such that
only traffic to these destination addresses is redirected through the SSL VPN
tunnels, and all other traffic is redirected using the hosts (SSL VPN Clients) native
network interface. For example if the SSL VPN Client attempts to access this
device’s LAN network then in Split Tunnel mode, the user should add the LAN
subnet as the Destination Network using this page.
NOTE
You can configure client routes only if Split Tunnel support is enabled on the SSL
VPN Client page. See
Configuring the SSL VPN Client, page 166
.