Specifications
3-3
PIX 515E Security Appliance Getting Started Guide
78-17645-01
Chapter 3 Scenario: IPsec Remote-Access VPN Configuration
Implementing the IPsec Remote-Access VPN Scenario
• Specifying the VPN Tunnel Group Name and Authentication Method,
page 3-7
• Specifying a User Authentication Method, page 3-8
• (Optional) Configuring User Accounts, page 3-10
• Configuring Address Pools, page 3-11
• Configuring Client Attributes, page 3-12
• Configuring the IKE Policy, page 3-13
• Configuring IPsec Encryption and Authentication Parameters, page 3-15
• Specifying Address Translation Exception and Split Tunneling, page 3-16
• Verifying the Remote-Access VPN Configuration, page 3-17
Information to Have Available
Before you begin configuring the security appliance to accept remote access IPsec
VPN connections, make sure that you have the following information available:
• Range of IP addresses to be used in an IP pool. These addresses are assigned
to remote VPN clients as they are successfully connected.
• List of users to be used in creating a local authentication database, unless you
are using a AAA server for authentication.
• Networking information to be used by remote clients when connecting to the
VPN, including:
–
IP addresses for the primary and secondary DNS servers
–
IP addresses for the primary and secondary WINS servers
–
Default domain name
–
List of IP addresses for local hosts, groups, and networks that should be
made accessible to authenticated remote clients
Starting ASDM
To run ASDM in a web browser, enter the factory default IP address in the address
field: https://192.168.1.1/admin/.