VPN
Configuring the Cisco IPSec VPN Client
Cisco ISA500 Series Integrated Security Appliance Administrator Guide
244
8
•
Server (Remote Address):
Enter the IP address of the remote Cisco IPSec
VPN server.
•
Connection on Startup:
Click
On
to establish the connection with the
remote server when your security appliance starts up, or click
Off
to disable
it. Only one connection can be active on startup.
•
Authentication Method:
The client must be properly authenticated before it
can access the remote network. Choose one of the following authentication
methods:
-
Preshare:
If you choose this option, specify the pre-shared key and the
group policy in the following fields.
Password:
Enter the desired value, which the peer device must provide
to establish a connection. The pre-shared key must be entered exactly
the same here and on the remote server.
Group Name:
Enter the name of the group policy that is defined on the
remote server. Your security appliance will use this group policy to
establish the VPN tunnel with the remote server. The server pushes the
security settings over the IPSec VPN tunnel to the clients.
-
Certificate:
If you choose this option, choose a local certificate and a
peer certificate for authentication. On the remote server, the selected
local certificate should be set as the peer certificate, and the selected
peer certificate should be set as the local certificate. If the certificates are
not in the list, go to the
Device Management -> Certificate
Management
page to import the certificates. See
Certificates for Authentication, page 310
•
Mode:
Specify the operation mode before making a connection because the
client does not have a default mode. For more information about the
operation mode, see
.
•
VLAN:
If you choose the NEM mode, specify the VLAN that permits the
access from and to the private network of the remote server.
•
User Name:
Enter the user name used by the client to establish a VPN
connection.
•
User Password:
Enter the password used by the client to establish a VPN
connection.
STEP 4
In the
Zone Access Control
tab you can control the access from the zones in your
network to the remote network if you choose the Client mode. Click
Permit
to