!— In order to set AAA authentication at login, use the aaa authentication login
!— command in global configuration mode

!
aaa authentication login default local
!
!— Here, list name ” easyvpnlist” is specified for
!— the authentication of the clients.

aaa authentication login easyvpnlist local
aaa authorization network Comms-Networks local
!
!— Create an ISAKMP policy for Phase 1 negotiations.

crypto isakmp policy 1
encr aes 256
authentication pre-share
group 2
!
crypto isakmp client configuration address-pool local EASYVPN_POOL
!
!— Defines the pre-shared key as P0wder07

crypto isakmp client configuration group Comms-Networks
key P0wder07
dns 192.168.3.1
netmask 255.255.255.0
domain Comms-Networks
pool EASYVPN_POOL
acl EASY_VPN
save-password
!
!— Create the Phase 2 policy for actual data encryption.

crypto ipsec transform-set leeipsecvpn esp-aes 256 esp-sha-hmac
!
crypto dynamic-map Comms-Networks 10
set transform-set leeipsecvpn
reverse-route
!
!
!— Specifies the crypto map parameters.

crypto map Leeipsec client authentication list easyvpnlist
crypto map Leeipsec client configuration address respond
crypto map Leeipsec isakmp authorization list Comms-Networks
crypto map Leeipsec 3000 ipsec-isakmp dynamic Comms-Networks
!
!— Applies the crypto map Leeipsec to the interface.

interface FastEthernet0/0
description WAN
crypto map Leeipsec
!
!— Creates a local pool named EASYVPN_POOL for issuing IP
!— addresses to clients

ip local pool EASYVPN_POOL 192.168.3.2 192.168.3.6
!
!— Creates an access-list extended EASY_VPN

permit ip 192.168.3.0 0.0.0.7 any
remark Access_To_MediaServer
permit ip 192.168.2.0 0.0.0.7 any