VPN
Configuring the Cisco IPSec VPN Server
Cisco ISA500 Series Integrated Security Appliance Administrator Guide
237
8
NOTE
The VPN access rules that are automatically generated by the Zone Access
Control settings will be added to the firewall access rule table with the
priority higher than the default access rules, but lower than the custom
access rules.
STEP 6
In the
Mode Config Settings
tab, enter the following information:
•
Primary DNS Server:
Enter the IP address of the primary DNS server.
•
Secondary DNS Server:
Enter the IP address of the secondary DNS server.
•
Primary WINS Server:
Enter the IP address of the primary WINS server.
•
Secondary WINS Server:
Enter the IP address of the secondary WINS
server.
•
Default Domain:
Enter the default domain name.
•
Backup Server 1/2/3:
Enter the IP addresses of backup servers. When the
primary server is down, the client can connect to the backup server. The
backup server 1 has the highest priority and the backup server 3 has the
lowest priority.
NOTE
The backup servers that you specified on the Cisco IPSec VPN
Server will be sent to the remote clients when initiating the VPN
connection. The remote clients will cache them.
•
Split Tunnel:
Click
On
to enable the split tunneling feature, or click
Off
to
disable it. Split tunneling allows only the traffic that is specified by the VPN
client routes to corporate resources through the VPN tunnel. If you enable the
split tunneling feature, you need to define the split subnets. To add a subnet,
enter the IP address in the
IP
filed and and netmask address in the
Netmask
filed, and then click
Add
. To delete a subnet, choose a subnet from the list
and then click
Delete
.
•
Split DNS:
Split DNS directs DNS packets in clear text through the VPN
tunnel to domains served by the corporate DNS. To add a domain, enter the
IP address or domain name in the
Domain Name
filed and then click
Add
. To
delete a domain, select it from the list and then click
Delete
.