通过sdm配置cisco ssl vpn.docx

上传人:b****5 文档编号:7399965 上传时间:2023-01-23 格式:DOCX 页数:34 大小:399.40KB
下载 相关 举报
通过sdm配置cisco ssl vpn.docx_第1页
第1页 / 共34页
通过sdm配置cisco ssl vpn.docx_第2页
第2页 / 共34页
通过sdm配置cisco ssl vpn.docx_第3页
第3页 / 共34页
通过sdm配置cisco ssl vpn.docx_第4页
第4页 / 共34页
通过sdm配置cisco ssl vpn.docx_第5页
第5页 / 共34页
点击查看更多>>
下载资源
资源描述

通过sdm配置cisco ssl vpn.docx

《通过sdm配置cisco ssl vpn.docx》由会员分享,可在线阅读,更多相关《通过sdm配置cisco ssl vpn.docx(34页珍藏版)》请在冰豆网上搜索。

通过sdm配置cisco ssl vpn.docx

通过sdm配置ciscosslvpn

Introduction

ClientlessSSLVPN(WebVPN)allowsausertosecurelyaccessresourcesonthecorporateLANfromanywherewithanSSL-enabledWebbrowser.TheuserfirstauthenticateswithaWebVPNgatewaywhichthenallowstheuseraccesstopre-configurednetworkresources.WebVPNgatewayscanbeconfiguredonCiscoIOS®routers,CiscoAdaptiveSecurityAppliances(ASA),CiscoVPN3000Concentrators,andtheCiscoWebVPNServicesModulefortheCatalyst6500and7600Routers.

SecureSocketLayer(SSL)VirtualPrivateNetwork(VPN)technologycanbeconfiguredonCiscodevicesinthreemainmodes:

ClientlessSSLVPN(WebVPN),Thin-ClientSSLVPN(PortForwarding),andSSLVPNClient(SVC)mode.ThisdocumentdemonstratestheconfigurationoftheWebVPNonCiscoIOSrouters.

Note:

 DonottochangeeithertheIPdomainnameorthehostnameoftherouterasthiswilltriggeraregenerationoftheself-signedcertificateandwilloverridetheconfiguredtrustpoint.Regenerationoftheself-signedcertificatecausesconnectionissuesiftherouterhasbeenconfiguredforWebVPN.WebVPNtiestheSSLtrustpointnametotheWebVPNgatewayconfiguration.Therefore,ifanewself-signedcertificateisissued,thenewtrustpointnamedoesnotmatchtheWebVPNconfigurationandusersareunabletoconnect.

Note:

 Ifyouruntheiphttps-secureservercommandonaWebVPNrouterthatusesapersistentself-signedcertificate,anewRSAkeyisgeneratedandthecertificatebecomesinvalid.Anewtrustpointiscreated,whichbreaksSSLWebVPN.Iftherouterthatusesthepersistentself-signedcertificaterebootsafteryouruntheiphttps-secureservercommand,thesameissueoccurs.

RefertoThin-ClientSSLVPN(WebVPN)IOSConfigurationExamplewithSDMinordertolearnmoreaboutthethin-clientSSLVPN.

RefertoSSLVPNClient(SVC)onIOSwithSDMConfigurationExampleinordertolearnmoreabouttheSSLVPNClient.

SSLVPNrunsontheseCiscoRouterplatforms:

Cisco870,1811,1841,2801,2811,2821and2851seriesrouters

Cisco3725,3745,3825,3845,7200and7301seriesrouters

Prerequisites

Requirements

Ensurethatyoumeettheserequirementsbeforeyouattemptthisconfiguration:

AnadvancedimageofCiscoIOSSoftwareRelease12.4(6)Torlater

OneoftheCiscorouterplatformslistedintheIntroduction

ComponentsUsed

Theinformationinthisdocumentisbasedonthesesoftwareandhardwareversions:

Cisco3825router

AdvancedEnterprisesoftwareimage-CiscoIOSSoftwareRelease12.4(9)T

CiscoRouterandSecurityDeviceManager(SDM)-version2.3.1

Theinformationinthisdocumentwascreatedfromthedevicesinaspecificlabenvironment.Allofthedevicesusedinthisdocumentstartedwithacleared(default)configuration.Ifyournetworkislive,makesurethatyouunderstandthepotentialimpactofanycommand.TheIPaddressesusedinthisexamplearetakenfromRFC1918addresseswhichareprivateandnotlegaltouseontheInternet.

NetworkDiagram

Thisdocumentusesthisnetworksetup:

Conventions

RefertotheCiscoTechnicalTipsConventionsformoreinformationondocumentconventions.

PreconfigurationTasks

Beforeyoubegin,completethesetasks:

Configureahostnameanddomainname.

ConfiguretherouterforSDM.CiscoshipssomerouterswithapreinstalledcopyofSDM.

IftheCiscoSDMisnotalreadyloadedonyourrouter,youcanobtainafreecopyofthesoftwarefromSoftwareDownload(registeredcustomersonly).YoumusthaveaCCOaccountwithaservicecontract.FordetailedinformationontheinstallationandconfigurationofSDM,refertoCiscoRouterandSecurityDeviceManager.

Configurethecorrectdate,time,andtimezoneforyourrouter.

ConfigureWebVPNonCiscoIOS

YoucanhavemorethanoneWebVPNgatewayassociatedwithadevice.EachWebVPNgatewayislinkedtoonlyoneIPaddressontherouter.YoucancreatemorethanoneWebVPNcontextforaparticularWebVPNgateway.Toidentifyindividualcontexts,provideeachcontextwithauniquename.OnepolicygroupcanbeassociatedwithonlyoneWebVPNcontext.ThepolicygroupdescribeswhichresourcesareavailableinaparticularWebVPNcontext.

CompletethesestepsinordertoconfigureWebVPNonCiscoIOS:

ConfiguretheWebVPNGateway

ConfiguretheResourcesAllowedforthePolicyGroup

ConfiguretheWebVPNPolicyGroupandSelecttheResources

ConfiguretheWebVPNContext

ConfiguretheUserDatabaseandAuthenticationMethod

Step1.ConfiguretheWebVPNGateway

CompletethesestepsinordertoconfiguretheWebVPNGateway:

WithintheSDMapplication,clickConfigure,andthenclickVPN.

ExpandWebVPN,andchooseWebVPNGateways.

ClickAdd.

TheAddWebVPNGatewaydialogboxappears.

EntervaluesintheGatewayNameandIPAddressfields,andthenchecktheEnableGatewaycheckbox.

ChecktheRedirectHTTPTrafficcheckbox,andthenclickOK.

ClickSave,andthenclickYestoacceptthechanges.

Step2.ConfiguretheResourcesAllowedforthePolicyGroup

Inordertomakeiteasiertoaddresourcestoapolicygroup,youcanconfiguretheresourcesbeforeyoucreatethepolicygroup.

Completethesestepsinordertoconfiguretheresourcesallowedforthepolicygroup:

ClickConfigure,andthenclickVPN.

ChooseWebVPN,andthenclicktheEditWebVPNtab.

Note:

 WebVPNallowsyoutoconfigureaccessforHTTP,HTTPS,WindowsfilebrowsingthroughtheCommonInternetFileSystem(CIFS)protocol,andCitrix.

ClickAdd.

TheAddWebVPNContextdialogboxappears.

ExpandWebVPNContext,andchooseURLLists.

ClickAdd.

TheAddURLListdialogboxappears.

EntervaluesintheURLListNameandHeadingfields.

ClickAdd,andchooseWebsite.

ThislistcontainsalltheHTTPandHTTPSWebserversthatyouwanttobeavailableforthisWebVPNconnection.

InordertoaddaccessforOutlookWebAccess(OWA),clickAdd,chooseE-mail,andthenclickOKafteryouhavefilledinallthedesiredfields.

InordertoallowWindowsfilebrowsingthroughCIFS,youcandesignateanNetBIOSNameService(NBNS)serverandconfiguretheappropriatesharesintheWindowsdomaininorder.

FromtheWebVPNContextlist,chooseNetBIOSNameServerLists.

ClickAdd.

TheAddNBNSServerListdialogboxappears.

Enteranameforthelist,andclickAdd.

TheNBNSServerdialogboxappears.

Ifapplicable,checktheMakeThistheMasterServercheckbox.

ClickOK,andthenclickOK.

Step3.ConfiguretheWebVPNPolicyGroupandSelecttheResources

CompletethesestepsinordertoconfiguretheWebVPNpolicygroupandselecttheresources:

ClickConfigure,andthenclickVPN.

ExpandWebVPN,andchooseWebVPNContext.

ChooseGroupPolicies,andclickAdd.

TheAddGroupPolicydialogboxappears.

Enteranameforthenewpolicy,andchecktheMakethisthedefaultgrouppolicyforcontextcheckbox.

ClicktheClientlesstablocatedatthetopofthedialogbox.

ChecktheSelectcheckboxforthedesiredURLList.

IfyourcustomersuseCitrixclientsthatneedaccesstoCitrixservers,checktheEnableCitrixcheckbox.

ChecktheEnableCIFS,Read,andWritecheckboxes.

ClicktheNBNSServerListdrop-downarrow,andchoosetheNBNSserverlistthatyoucreatedforWindowsfilebrowsinginStep2.

ClickOK.

Step4.ConfiguretheWebVPNContext

InordertolinktheWebVPNgateway,grouppolicy,andresourcestogether,youmustconfiguretheWebVPNcontext.InordertoconfiguretheWebVPNcontext,completethesesteps:

ChooseWebVPNContext,andenteranameforthecontext.

ClicktheAssociatedGatewaydrop-downarrow,andchooseanassociatedgateway.

Ifyouintendtocreatemorethanonecontext,enterauniquenameintheDomainfieldtoidentifythiscontext.IfyouleavetheDomainfieldblank,usersmustaccesstheWebVPNwithhttps:

//IPAddress.Ifyouenteradomainname(forexample,Sales),usersmustconnectwithhttps:

//IPAddress/Sales.

ChecktheEnableContextcheckbox.

IntheMaximumNumberofUsersfield,enterthemaximumnumberofusersallowedbythedevicelicense.

ClicktheDefaultGrouppolicydrop-downarrow,andselectthegrouppolicytoassociatewiththiscontext.

ClickOK,andthenclickOK.

Step5.ConfiguretheUserDatabaseandAuthenticationMethod

YoucanconfigureClientlessSSLVPN(WebVPN)sessionstoauthenticatewithRadius,theCiscoAAAServer,oralocaldatabase.Thisexampleusesalocaldatabase.

Completethesestepsinordertoconfiguretheuserdatabaseandauthenticationmethod:

ClickConfiguration,andthenclickAdditionalTasks.

ExpandRouterAccess,andchooseUserAccounts/View.

ClicktheAddbutton.

TheAddanAccountdialogboxappears.

Enterauseraccountandapassword.

ClickOK,andthenclickOK.

ClickSave,andthenclickYestoacceptthechanges.

Results

TheASDMcreatesthesecommand-lineconfigurations:

ausnml-3825-01

Buildingconfiguration...

Currentconfiguration:

4190bytes

!

!

Lastconfigurationchangeat17:

22:

23UTCWedJul262006byausnml

!

NVRAMconfiglastupdatedat17:

22:

31UTCWedJul262006byausnml

!

version12.4

servicetimestampsdebugdatetimemsec

servicetimestampslogdatetimemsec

servicepassword-encryption

!

hostnameausnml-3825-01

!

boot-start-marker

bootsystemflashc3825-adventerprisek9-mz.124-9.T.bin

boot-end-marker

!

nologgingbuffered

enablesecret5$1$KbIu$5o8qKYAVpWvyv9rYbrJLi/

!

aaanew-model

!

aaaauthenticationlogindefaultlocal

aaaauthenticationloginsdm_vpn_xauth_ml_1local

aaaauthorizationexecdefaultlocal

!

aaasession-idcommon

!

resourcepolicy

!

ipcef

!

ipdomainname

!

voice-card0

nodspfarm

!

!

---Self-SignedCertificateInformation

cryptopkitrustpointausnml-3825-01_Certificate

enrollmentselfs

展开阅读全文
相关资源
猜你喜欢
相关搜索

当前位置:首页 > 高等教育 > 理学

copyright@ 2008-2022 冰豆网网站版权所有

经营许可证编号:鄂ICP备2022015515号-1