VPN
Configuring the Cisco IPSec VPN Server
Cisco ISA500 Series Integrated Security Appliance Administrator Guide
236
8
•
Mode:
The operation mode determines whether the inside hosts relative to
the Cisco VPN hardware client are accessible from the corporate network
over the IPSec VPN tunnel. Specifying a operation mode is mandatory
before making a connection because the Cisco VPN hardware client does
not have a default mode. For more information, see
-
Client:
Choose this mode for the group policy that is used for both the PC
running the Cisco VPN Client software and the Cisco device that works
as the Cisco VPN hardware client. In client mode, the server can assign
the IP address to the outside interface of remote clients. To define the
pool range for the clients, enter the starting and ending IP addresses in
the
Start IP
and
End IP
fields.
-
NEM:
Choose this mode for the group policy that is only used for the
Cisco device that works as the Cisco VPN hardware client. The Cisco
VPN hardware client can obtain a private IP address from a DHCP server
over the IPSec VPN tunnel.
•
WAN Failover:
Click
On
to enable WAN Failover, or click
Off
to disable it. If
you enable WAN Failover, the traffic is automatically redirected to the
secondary link when the primary link is down.
NOTE
To enable the WAN Failover for Cisco IPSec VPN tunnels, make sure
that the secondary WAN interface was configured and the WAN
redundancy was set to the Loab Balancing or Failover mode.
NOTE
The security appliance will automatically update the local WAN
gateway for the VPN tunnel based on the configurations of the backup
WAN link. For this purpose, Dynamic DNS has to be configured
because the IP address will change due to failover, or let the remote
gateway use a dynamic IP address.
STEP 5
In the
Zone Access Control
tab, you can control the access from the PC running
the Cisco VPN Client software or the private network of the Cisco VPN hardware
client to the zones over IPSec VPN tunnels. Click
Permit
to permit the access, or
click
Deny
to deny the access. By default, the access for all zones is permitted.