
Configuring Virtual Private Networks (VPNs) and Security
Configuring Advanced VPN Parameters
Cisco RV120W Administration Guide
98
5
Extended Authentication (XAUTH) Parameters
Rather than configuring a unique VPN policy for each user, you can enable the VPN
gateway router to authenticate users from a stored list of user accounts or with an
external authentication server such as a RADIUS server. When connecting many
VPN clients to a VPN gateway router, Extended Authentication (XAUTH) allows
authentication of users with methods in addition to the authentication method
mentioned in the IKE SA parameters. XAUTH can be configured in the following
modes:
STEP 1
Select the XAUTH type:
•
None—Disables XAUTH.
•
Edge Device—Authentication is done by one of the following:
-
User Database—User accounts created in the router are used to
authenticate users. See
Configuring VPN Users, page 105
.
-
RADIUS-PAP—Authentication is done using a RADIUS server and
password authentication protocol (PAP).
-
RADIUS-CHAP—Authentication is done using a RADIUS server and
challenge handshake authentication protocol (CHAP).
•
IPsec Host—The router is authenticated by a remote gateway with a
username and password combination. In this mode, the router acts as a VPN
Client of the remote gateway.
STEP 2
If you selected IPsec Host, enter the username and password for the host.
Configuring VPN Policies
To configure a VPN policy:
STEP 1
Choose VPN > IPsec > Advanced VPN Setup.
STEP 2
In the VPN Policy Table, click Add.
STEP 3
Enter a unique name to identify the policy.
STEP 4
Choose the Policy Type: