User's Manual

Table Of Contents
VPN
Configuring the Cisco IPSec VPN Client
Cisco ISA500 Series Integrated Security Appliance Administrator Guide 242
8
NAT or PAT translation over the VPN tunnel. When accessing the remote network
192.168.100.x, the hosts 10.0.0.3 and 10.0.04 will not be translated, and hosts in
the remote network 192.168.100.x can access the hosts 10.0.0.3 and 10.0.04
directly.
The client hosts are given IP addresses that are fully routable by the destination
network over the tunnel. These IP addresses could be either in the same subnet
space as the destination network or in separate subnets, assuming that the
destination routers are configured to properly route those IP addresses over the
tunnel.
Figure 9 Cisco IPSec VPN Network Extension Connection
General Settings
You can enable the Cisco IPSec VPN Client feature, configure the Auto Initiation
Retry settings, or manually connect or disconnect the IPSec VPN tunnels.
STEP 1 Click VPN -> Remote User Access -> Cisco IPSec VPN Client.
The Cisco IPSec VPN Client window opens.
STEP 2 Enter the following information:
Cisco IPSec VPN Client Enable: Click On to enable the Cisco IPSec VPN
Client feature and set the security appliance as a Cisco VPN hardware client,
or click Off to disable it.
ISA500
as a Cisco IPSec VPN Client
10.0.0.3
10.0.0.4
Internet
Cisco Device
as a Cisco IPSec VPN Server
192.168.100.x
VPN tunnel
WAN
202.0.0.1
WAN
203.0.0.1