VPN
Configuring a Site-to-Site VPN
Cisco ISA500 Series Integrated Security Appliances Administration Guide
290
8
NOTE
CSTP is a Cisco proprietary protocol for SSL VPN tunneling. “In” represents that the
packet comes from the client. “Out” represents that the packet is sent to the client.
The client is the PC running the Cisco AnyConnect Secure Mobility Client software
that connects to the security appliance running the SSL VPN server. A CSTP frame
is a packet carrying the CSTP protocol information. There are two major frame
types, control frames and data frames. Control frames implement control functions
within the protocol. Data frames carry the client data, such as the tunneled payload.
Configuring a Site-to-Site VPN
A site-to-site VPN tunnel connects two routers to secure traffic between two sites
that are physically separated.
Figure 3 Site-to-Site VPN
Out CSTP Bytes
Total number of bytes in the CSTP frames sent to the
client.
Out CSTP Data
Number of CSTP data frames sent to the client.
Out CSTP Control
Number of CSTP control frames sent to the client.
Field
Description
2
83
057
S
ite A
I
S
A500
I
S
A500
S
ite B
In
s
ide
10.10.10.0
O
u
t
s
ide
209.165.200.226
O
u
t
s
ide
209.165.200.2
3
6
In
s
ide
10.20.20.0
Per
s
on
a
l comp
u
ter
s
Per
s
on
a
l comp
u
ter
s
Printer
Printer
Internet