Cisco VPN 3000 User's Guide Page 136

  • Download
  • Add to my manuals
  • Print
  • Page
    / 502
  • Table of contents
  • TROUBLESHOOTING
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 135
7 Tunneling Protocols
7-12
VPN 3000 Concentrator Series User Guide
All of the rules, SAs, filters, and group have default parameters or those specified on this screen. You
can modify the rules and SA on the
Configuration | Policy Management | Traffic Management screens, the
group on the
Configuration | User Management | Groups screens, and the interface on the Configuration |
Interfaces
screens. However, we recommend that you keep the configured defaults. You cannot delete
these rules, SAs, or group individually; the system automatically deletes them when you delete the
LAN-to-LAN connection.
To fully configure a LAN-to-LAN connection, you must configure identical IPSec LAN-to-LAN
parameters on both VPN Concentrators, and configure mirror-image local and remote private network
addresses. For example:
If you use network lists, you must also configure and apply them as mirror images on the two VPN
Concentrators. If you use network autodiscovery, you must use it on both VPN Concentrators.
Caution: On the
Modify screen, any changes take effect as soon as you click Apply. If client sessions are using this
connection, changes delete the tunneland the sessionswithout warning.
Name
Enter a unique descriptive name for this connection. Maximum 32 characters. Since the created rules and
SA use this name, we recommend that you keep it short.
Interface
Add screen:
Click the drop-down menu button and select the configured public interface on this VPN
Concentrator for this end of the LAN-to-LAN connection. The list shows all interfaces (Ethernet or
WAN) that have the
Public Interface parameter enabled. See Configuration | Interfaces.
Modify screen:
The screen shows the configured public interface on this VPN Concentrator for this end of the
LAN-to-LAN connection. You cannot change the interface. To move the connection to another
interface, you must delete this connection and add a new one for the other interface.
Peer
Enter the IP address of the remote peer in the LAN-to-LAN connection. This must be the IP address of
the public interface on the peer VPN Concentrator. Use dotted decimal notation; e.g.,
192.168.34.56.
Configure On this VPN Concentrator On peer VPN Concentrator
Local Network 10.10.0.0/0.0.255.255 11.0.0.0/0.255.255.255
Remote Network 11.0.0.0/0.255.255.255 10.10.0.0/0.0.255.255
Page view 135
1 2 ... 131 132 133 134 135 136 137 138 139 140 141 ... 501 502

Comments to this Manuals

No comments