!— Specify the interface which points toward the DNS server
!— to enable the ASA/PIX to use DNS.
dns domain-lookup inside
dns server-group DefaultDNS
timeout 30
*****************************************************
!— Specify the location of the DNS server in the DefaultDNS group.
name-server 172.16.1.1
domain-name cisco.com
*****************************************************
!— This access list is used for a nat zero command that prevents
!— traffic which matches the access list from undergoing NAT.
access-list 101 extended permit ip 172.16.0.0 255.255.0.0 10.16.20.0 255.255.255.0
!..ASA V8 nonat configuration changes :
object-group network obj-local_ipsec_tunnel
network-object 172.16.0.0 255.255.0.0
!
object-group network obj-remote_ipsec_tunnel
network-object 172.16.20.0 255.255.255.0
!
nat (inside,outside) source static obj-local_ipsec_tunnel
obj-local_ipsec_tunnel destination static obj-remote_ipsec_tunnel
obj-remote_ipsec_tunnel
*****************************************************
!….Corporate Network Behind The ASA. Split tunneling allows users to send only that
traffic which is destined for the corporate network across the tunnel. All other traffic
such as instant messaging, email, or casual browsing is sent out to the Internet via the
local LAN of the VPN Client.
access-list split_tunnel standard permit 172.16.0.0 255.255.0.0
*****************************************************
!— Create a pool of addresses from which IP addresses are assigned
!— dynamically to the remote VPN Clients.
ip local pool vpnclient 10.16.20.1-10.16.20.5
*****************************************************
!— NAT 0 prevents NAT for networks specified in the ACL 101.
!— The nat 1 command specifies Port Address Translation (PAT)
!— using 10.10.1.5 for all other traffic.
global (outside) 1 10.10.1.5
nat (inside) 0 access-list 101
nat (inside) 1 0.0.0.0 0.0.0.0
!…ASA V8 Nat configuration changes :
object network Private_Lan
subnet 172.16.0.0 255.255.0.0
nat (inside,outside) dynamic interface
*****************************************************
!—ip routes
route outside 10.10.0.0 255.255.255.0 10.10.1.1 1
route inside 172.16.0.0 255.255.0.0 10.11.1.3 1
route outside 0.0.0.0 0.0.0.0 10.11.1.1 1
*****************************************************
!— Create the AAA server group “vpn” and specify the protocol as RADIUS.
!— Specify the IAS server as a member of the “vpn” group and provide the
!— location and key.
aaa-server vpn protocol radius
aaa-server vpn host 10.11.1.2
key cisco123
*****************************************************
!— Create the VPN users’ group policy and specify the DNS server IP address
!— and the domain name in the group policy.
group-policy vpn3000 internal
group-policy vpn3000 attributes
dns-server value 172.16.1.1
split-tunnel-policy tunnelspecified
split-tunnel-network-list value 101
default-domain value cisco.com
*****************************************************
!— In order to identify remote access users to the Security Appliance,
!— you can also configure usernames and passwords on the device
!— in addition to using AAA.
username vpn3000 password nPtKy7KDCerzhKeX encrypted
*****************************************************
!— PHASE 2 CONFIGURATION —!
!— The encryption types for Phase 2 are defined here.
!— A single DES encryption with
!— the md5 hash algorithm is used.
crypto ipsec transform-set my-set esp-des esp-md5-hmac
*****************************************************
!— Defines a dynamic crypto map with
!— the specified encryption settings.
crypto dynamic-map dynmap 10 set transform-set my-set
*****************************************************
!— Configuring the IPsec Security Association Idle Timers feature increases the
availability of resources by deleting SAs associated with idle peers.
IPsec Security Association Idle Timers feature prevents the wasting of resources
by idle peers, more resources will be available to create new SAs as required.
crypto dynamic-map dynmap 10 set security-association lifetime seconds 86400
crypto dynamic-map dynmap 10 set security-association lifetime kilobytes 9908000
*****************************************************
!— Enable Reverse Route Injection (RRI), which allows the Security Appliance
!— to learn routing information for connected clients.
crypto dynamic-map dynmap 10 set reverse-route
*****************************************************
!— Binds the dynamic map to the IPsec/ISAKMP process.
crypto map mymap 10 ipsec-isakmp dynamic dynmap
*****************************************************
!— Specifies the interface to be used with
!— the settings defined in this configuration.
crypto map mymap interface outside
!— Allowing the decrypted IPSEC packets to be permitted
even if the outside interface ACL does not explicitly allow for it.
sysopt connection permit-ipsec
!— For traffic that enters the security appliance through a VPN tunnel and is then
decrypted, to allow the traffic to bypass interface access lists.
!—You might want to bypass interface access lists for decrypted VPN traffic to simplify
configuration and to maximize the security appliance performance. If you disable this
feature, you must apply an access list to the ingress interface that permits decrypted
VPN packets from all VPN peers
sysopt connection permit-vpn
!— To ensure that the maximum TCP segment size does not exceed the value you
set and that the maximum is not less than a specified size.
sysopt connection tcpmss
!— NAT-Traversal or NAT-T allows VPN traffic to pass through NAT or PAT devices,
such as a Linksys SOHO router. If NAT-T is not enabled, VPN Client users often appear
to connect to the PIX or ASA without a problem, but they are unable to access the internal
network behind the security appliance.
!
no isakmp nat-traversal 20
*****************************************************
!— PHASE 1 CONFIGURATION —!
!— This configuration uses ISAKMP policy 10.
!— Policy 65535 is included in the configuration by default.
!— The configuration commands here define the Phase
!— 1 policy parameters that are used.
isakmp enable outside
isakmp policy 10 authentication pre-share
isakmp policy 10 encryption des
isakmp policy 10 hash md5
isakmp policy 10 group 2
isakmp policy 10 lifetime 1000
!
isakmp policy 65535 authentication pre-share
isakmp policy 65535 encryption 3des
isakmp policy 65535 hash sha
isakmp policy 65535 group 2
isakmp policy 65535 lifetime 86400
*****************************************************
!— The Security Appliance provides the default tunnel groups
!— for remote access (DefaultRAGroup).
tunnel-group DefaultRAGroup general-attributes
authentication-server-group (outside) vpn
*****************************************************
!— Create a new tunnel group and set the connection
!— type to IPsec remote access (ipsec-ra).
tunnel-group vpn3000 type ipsec-ra
*****************************************************
!— Associate the vpnclient pool to the tunnel group using the address pool.
!— Associate the AAA server group (VPN) with the tunnel group.
tunnel-group vpn3000 general-attributes
address-pool vpnclient
authentication-server-group vpn
default-group-policy vpn3000
*****************************************************
!— Enter the pre-shared-key to configure the authentication method.
tunnel-group vpn3000 ipsec-attributes
pre-shared-key *
*****************************************************
Configuration Summary :
access-list 101 extended permit ip 172.16.0.0 255.255.0.0 10.16.20.0 255.255.255.0
access-list split_tunnel standard permit 172.16.0.0 255.255.0.0
ip local pool vpnclient 10.16.20.1-10.16.20.5
!
object-group network obj-local_ipsec_tunnel
network-object 172.16.0.0 255.255.0.0
object-group network obj-remote_ipsec_tunnel
network-object 172.16.20.0 255.255.255.0
!
nat (inside,outside) source static obj-local_ipsec_tunnel
obj-local_ipsec_tunnel destination static obj-remote_ipsec_tunnel
obj-remote_ipsec_tunnel
!
aaa-server vpn protocol radius
aaa-server vpn host 10.11.1.2
key cisco123
!
group-policy vpn3000 internal
group-policy vpn3000 attributes
dns-server value 172.16.1.1
split-tunnel-policy tunnelspecified
split-tunnel-network-list value 101
default-domain value cisco.com
!
crypto ipsec transform-set my-set esp-des esp-md5-hmac
crypto dynamic-map dynmap 10 set transform-set my-set
crypto dynamic-map dynmap 10 set security-association lifetime seconds 86400
crypto dynamic-map dynmap 10 set security-association lifetime kilobytes 9908000
crypto dynamic-map dynmap 10 set reverse-route
crypto map mymap 10 ipsec-isakmp dynamic dynmap
!
crypto map mymap interface outside
sysopt connection permit-ipsec
sysopt connection permit-vpn
sysopt connection tcpmss
no isakmp nat-traversal 20
!
isakmp enable outside
isakmp policy 10 authentication pre-share
isakmp policy 10 encryption des
isakmp policy 10 hash md5
isakmp policy 10 group 2
isakmp policy 10 lifetime 1000
!
tunnel-group DefaultRAGroup general-attributes
authentication-server-group (outside) vpn
tunnel-group vpn3000 type ipsec-ra
tunnel-group vpn3000 general-attributes
address-pool vpnclient
authentication-server-group vpn
default-group-policy vpn3000
tunnel-group vpn3000 ipsec-attributes
pre-shared-key *
*********************************************************************
VPN Client 4.8 Configuration
Complete these steps to configure the VPN Client 4.8.
- Select Start > Programs > Cisco Systems VPN Client > VPN Client.
- Click New to launch the Create New VPN Connection Entry window.
!
!
!
!
!
!
!
!
!
3. Enter the name of the Connection Entry along with a description. Enter the outside
IP address of the PIX Firewall in the Host box. Then enter the VPN Group name and
password and click Save.
!
!
!
!
!
!
!
!
!
!
!
!
!
4. Click on the connection you would like to use and click Connect from the VPN Client main window.
!
5. When prompted, enter the Username and Password information for xauth and click OK
to connect to the remote network.
!
!
!
!
!
!
6. The VPN Client gets connected with the PIX at the central site
!
!
!
!
!
!
!
!
!
Select Status > Statistics to check the tunnel statistics of the VPN Client
!
!
!
!
!
!
!
!
!
!
!
*************************************************************
Complete these steps to configure the Microsoft Windows 2003 server with IAS.
Note: These steps assume that IAS is already installed on the local machine. If not,
add this through Control Panel > Add/Remove Programs.
- Select Administrative Tools > Internet Authentication Service and right-click
on RADIUS Client to add a new RADIUS client. When you have typed the client
information, click OK.
This example shows a client named Pix with an IP address of 10.11.1.1.
Client-Vendor is set to RADIUS Standard, and the shared secret is cisco123.
!
!
!
!
!
!
!
!
!
!
!
!
1. Go to Remote Access Policies, right-click on Connections to Other Access Servers,and select Properties.
2. Ensure that the option for Grant Remote Access Permissions is selected.
Click Edit Profile and check these settings:
-
- On the Authentication tab, check Unencrypted authentication (PAP, SPAP),
MS-CHAP, and MS-CHAP-v2.
- On the Encryption tab, ensure that the option for No Encryption is selected.
!
!
!
!
!
!
!
!
!
- Select Administrative Tools > Computer Management > System Tools > Local Users and Groups, right-click on Users and select New Users to add a user into the local computer account.
- Add a user with Cisco password password1 and check this profile information:
- On the General tab, ensure that the option for Password Never Expired
is selected instead of the option for User Must Change Password.
- On the Dial-in tab, select the option for Allow access (or leave the default setting
of Control access through Remote Access Policy).
Click OK when you are finished.
!
!
!
!
!
!
!
!
!
!
!
!
!
The security appliance supports password management for the RADIUS and LDAP
protocols. It supports the password-expire-in-days option for LDAP only.
You can configure password management for IPSec remote access and
SSL VPN tunnel-groups.
When you configure the password-management command, the security
appliance notifies the remote user at login that the current password of the user
is about to expire or has expired. The security appliance then offers the user the
opportunity to change the password. If the current password has not yet expired,
the user can still log in with that password.
This command is valid for AAA servers that support such notification.
The security appliance ignores this command if RADIUS or LDAP authentication
has not been configured.
When a user password expires and the user attempts to log with a VPN client to the
ASA, the Password needs to be changed but password management
disabled error message appears on the Cisco client software.
Enable Password-Management with the password-management command in the
tunnel group general attributes mode in order to resolve this issue.
This is a sample configuration for Password-Expiry :
tunnel-group <Tunnel-group> type remote-access
tunnel-group <Tunnel-group> general-attributes
authentication-server-group LDAP-AD
default-group-policy DfltGrpPolicy
password-management password-expire-in-days <number of days>
!—- From the PIX, use the Test keyword with the aaa authentication command
in global configuration mode in order to verify the user authentication with the
AAA server. After you enter the command, the PIX prompts you to enter the username and password to validate.When the user credential is verified and it
is valid, you recieve the Authentication Successful message.
pix(config-aaa-server-host)#test aaa authentication radius host 10.11.1.2
Username: administrator
Password: *****