Cisco – EASY VPN SERVER with XAUTH and SPLIT TUNNELING
INTRODUCTION
How to configure a host to router Easy VPN Solution, based:
Cisco VPN Client, and Easy VPN Server.
1. The Cisco Easy VPN negotiates tunnel parameters and establishes IPsec tunnels.
2. Xauth adds another level of authentication that identifies the user who
requests the IPsec connection.
3. Split tunneling enables the remote client to forward the Internet destined
traffic directly without forwarding it over the encrypted tunnel.
PREREQUISITES
The sample configuration is based on the following assumptions:
• The IP address at the Cisco Easy VPN Server is static.
• The IP address at the Cisco VPN Client is static or dynamic.
• The Cisco Easy VPN Client encrypts only traffic that is forwarded to the hub.
• Traffic destined for the Internet is forwarded, unencrypted, directly from the remote site.
• Traffic from the remote host is forwarded after applying Network Address Translation/Port
Address Translation (NAT/PAT).
• User level authentication is used for authorizing VPN access.
Configuration on Cisco Server end :
aaa authentication login easyvpnlist local
aaa authorization network Comms-Networks local
!
crypto isakmp policy 1
encr aes 256
authentication pre-share
group 2
crypto isakmp client configuration address-pool local EASYVPN_POOL
crypto isakmp xauth timeout 60
!
crypto isakmp client configuration group Comms-Networks
key P0wder07
dns 192.168.3.1
domain Comms-Networks
pool EASYVPN_POOL
acl EASY_VPN
save-password
pfs
max-users 5
netmask 255.255.255.248
!
crypto ipsec transform-set easyvpnvpn esp-aes 256 esp-sha-hmac
!
crypto dynamic-map Comms-Networks 10
set transform-set easyvpnvpn
reverse-route
!
crypto map easyvpn 3000 ipsec-isakmp dynamic Comms-Networks
!
crypto map easyvpn client authentication list easyvpnlist
crypto map easyvpn client configuration address respond
crypto map easyvpn isakmp authorization list Comms-Networks
crypto map easyvpn 1 ipsec-isakmp dynamic Comms-Networks
!
ip local pool EASYVPN_POOL 192.168.3.2 192.168.3.6
!
ip access-list extended EASY_VPN
permit ip 192.168.3.0 0.0.0.7 any
remark Access_to_Media_Server
permit ip 192.168.2.0 0.0.0.7 any
!
interface FastEthernet0/0
description WAN_INTERFACE
crypto map easyvpn
Note :
Don’t forget to configure nonat DENY statement from the 192.168.2.0 network over to 192.168.3.0 network, same vice-versa. This will ensure no NAT traffic is going over the ipsec encrypted tunnel.
The nonat ACL will bind to the corresponing Interfaces where traffic is to be initiated from.