Easy VPN
U
SER
G
UIDE
270
E
ASY
VPN
E
ASY
VPN
TUNNEL CONFIGURATION
Easy VPN is an IPSec alternative for managing VPN. It is particularly useful when the IP source
address is dynamic.
It is also compatible with leading VPN Concentrator as:
Cisco VPN concentrator 3000 Series
Cisco IOS routers
Cisco PIX / ASA Security Appliances
Juniper/Netscreen
This chapter only lists the basic parameters of Easy VPN module.
The main configuration commands are:
set ezvpn ipsec-gateway
used to set the IP address of the VPN concentrator.
set ezvpn ipsec-secre
used to set the pre-shared password key for encryption.
set ezvpn-id
used to set the VPN group.
set ezvpn xauth-username
used to set the username for XAUTH authentication.
set ezvpn xauth-password
used to set the XAUTH password.
set ezvpn vendor cisco | netscreen
used to set the type of concentrator.
set ezvpn natt cisco-udp| force-natt | natt | none
used to configure the NAT Traversal method.
cisco-UDP: Cisco proprietary protocol (UDP port 4500)
NATt as defined in the RFC3947
force-NATt always uses NAT Traversal even though there are not devices executing NAT.
none disables NAT Traversal
set ezvpn masquerade
set ezvpn no-masquerade
used to set the masquerade (PAT) of outgoing packets.
set ezvpn dpd-idle N
set ezvpn no-dpd-idle