欢迎来到天天文库
浏览记录
ID:52114471
大小:556.00 KB
页数:9页
时间:2020-03-23
《网络设备配置实训教程配套教学课件ppt谢尧王明昊课件教学资源网络设备配置实训教程 教学课件 ppt 作者 谢尧王明昊课件教学资源 PIXASA 7.x as a Remote VPN Server.doc》由会员上传分享,免费在线阅读,更多相关内容在教育资源-天天文库。
1、PIX/ASA7.xasaRemoteVPNServerCompletethesestepstoconfiguretheCiscoASAasaremoteVPNserverusingASDM.1.SelectWizards>VPNWizardfromtheHomewindow.2.SelecttheRemoteAccessVPNtunneltypeandensurethattheVPNTunnelInterfaceissetasdesired.1.TheonlyVPNClientTypeavailableisalread
2、yselected.ClickNext.2.EnteranamefortheTunnelGroupName.Supplytheauthenticationinformationtouse.Pre-sharedKeyisselectedinthisexample.3.ChoosewhetheryouwantremoteuserstobeauthenticatedtothelocaluserdatabaseortoanexternalAAAservergroup.Note: Youadduserstothelocaluser
3、databaseinstep6.Note: RefertoAuthenticationandAuthorizationServerGroupsforVPNUsersviaASDMConfigurationExampleforhowtoconfigureanexternalAAAservergroupviaASDM.1.Adduserstothelocaldatabaseifnecessary.Note: Donotremoveexistingusersfromthiswindow.SelectConfiguration>
4、DeviceAdministration>Administration>UserAccountsinthemainASDMwindowtoeditexistingentriesinthedatabaseortoremovethemfromthedatabase.1.DefineapooloflocaladdressestobedynamicallyassignedtoremoteVPNClientswhentheyconnect.2.Optional:SpecifytheDNSandWINSserverinformati
5、onandaDefaultDomainNametobepushedtoremoteVPNClients.3.SpecifytheparametersforIKE,alsoknownasIKEPhase1.Configurationsonbothsidesofthetunnelmustmatchexactly.However,theCiscoVPNClientautomaticallyselectstheproperconfigurationforitself.Therefore,noIKEconfigurationisn
6、ecessaryontheclientPC.1.SpecifytheparametersforIPsec,alsoknownasIKEPhase2.Configurationsonbothsidesofthetunnelmustmatchexactly.However,theCiscoVPNClientautomaticallyselectstheproperconfigurationforitself.Therefore,noIKEconfigurationisnecessaryontheclientPC.1.Spec
7、ifywhich,ifany,internalhostsornetworksshouldbeexposedtoremoteVPNusers.Ifyouleavethislistempty,itallowsremoteVPNuserstoaccesstheentireinsidenetworkoftheASA.2.Thiswindowshowsasummaryoftheactionsthatyouhavetaken.ClickFinishifyouaresatisfiedwithyourconfiguration.3.If
8、youhaveitconfiguredtodoso,theASAdisplaysapreviewofthecommandsthatwillbeaddedtotherunningconfiguration.ClickSendtosendthecommandstotheASA.VerifyAttempttoconnect
此文档下载收益归作者所有