<?xml version="1.0" encoding="iso-8859-1"?>
<?xml-stylesheet href="http://info.routermonkey.org/styles/rss.css" type="text/css"?>
<rdf:RDF 
  xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" 
  xmlns="http://my.netscape.com/rdf/simple/0.9/"
>

 <channel>
  <title>www.routermonkey.org</title>
  <link>http://info.routermonkey.org/index.php?blogId=1</link>
  <description></description>
 </channel>
    <item>
   <title>Cisco PIX Remote Access VPN PIX v7.2(2)</title>
   <description>&lt;p align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;text-align: center&quot;&gt;&lt;span style=&quot;font-size: medium; font-family: courier new,courier&quot;&gt;&lt;strong&gt;Cisco PIX Remote
Access VPN&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;div align=&quot;center&quot;&gt;
&lt;/div&gt;&lt;p align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;text-align: center&quot;&gt;&lt;span style=&quot;font-size: medium; font-family: courier new,courier&quot;&gt;&lt;strong&gt;PIX v7.2(2)&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;div align=&quot;center&quot;&gt;
&lt;/div&gt;&lt;p align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;text-align: center&quot;&gt;&lt;span style=&quot;font-size: medium; font-family: courier new,courier&quot;&gt;&lt;strong&gt;Barney Gaumer &amp;ndash;
10/24/2007&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;





&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span style=&quot;font-size: medium&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;This howto is written for intermediate Pix users who
intend to implement VPN Remote Access to their Cisco PIX without using
Certificates and/or other secure authentication methods for tunnel negotiation.&lt;/p&gt;



&lt;p class=&quot;MsoNormal&quot;&gt;For the VPN Client I recommend you use a 5.x version of the
Cisco VPN client.&lt;/p&gt;



&lt;p class=&quot;MsoNormal&quot;&gt;My example is base on pre-shared keys using xauth which will
be explained later in this paper.&lt;span&gt;&amp;nbsp;
&lt;/span&gt;Additionally, Post IKE authentication is offloaded to Microsoft AD via
Kerberos which will also be discussed later.&lt;/p&gt;



&lt;p class=&quot;MsoNormal&quot;&gt;Let&amp;rsquo;s get started!&lt;/p&gt;



&lt;p class=&quot;MsoNormal&quot;&gt;You should already have a management IP on &amp;ldquo;INSIDE&amp;rdquo;
interface on the PIX device and have ASDM 5.x or better and have ASDM
open.&lt;span&gt;&amp;nbsp; &lt;/span&gt;Now click on the &amp;ldquo;Configuration&amp;rdquo;
button!&lt;/p&gt;





&lt;p class=&quot;MsoNormal&quot;&gt;Click on &amp;ldquo;Properties&amp;rdquo; on the left pane of your ASDM window
and choose AAA Setup.&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot;&gt;We need to define AAA Server Groups by clicking on &amp;ldquo;Add&amp;rdquo; for
groups (the top box) and servers (bottom box) see the example in figure 1.0.&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Figure 1.0&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;

&lt;a id=&quot;res_84&quot; href=&quot;http://info.routermonkey.org/gallery/1/auth-kerb.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/auth-kerb.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot;&gt;Figure 1.1 shows an example of the AAA Server detail being
added.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Figure 1.1&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;

&lt;a id=&quot;res_85&quot; href=&quot;http://info.routermonkey.org/gallery/1/auth-server.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/auth-server.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;Let&amp;rsquo;s keep working backwards! Still on the configuration
tab, click on VPN on the left control pane.&lt;span&gt;&amp;nbsp;
&lt;/span&gt;Go all the way down to IP Address Management and select IP Pools as you
will need to have an address pool for your VPN users during tunnel group setup.&lt;/p&gt;



&lt;p class=&quot;MsoNormal&quot;&gt;Figure 1.2 shows the basic IP Pool configuration&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Figure 1.2&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;

&lt;a id=&quot;res_113&quot; href=&quot;http://info.routermonkey.org/gallery/1/ip-address-management.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/ip-address-management.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;Now lets move to IKE/Global Parameters and enable NAT-T for
RA clients that are behind a firewall and enable IKE on the interface your users
will attempt connections to on your PIX (outside for most of us).&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot;&gt;See the example in Figure 1.3&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Figure 1.3&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;

&lt;a id=&quot;res_111&quot; href=&quot;http://info.routermonkey.org/gallery/1/ike-global-parms.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/ike-global-parms.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot;&gt;Next we&amp;rsquo;ll take a look at the IKE policies.&lt;span&gt;&amp;nbsp; &lt;/span&gt;Click on IKE/Policies, in my example in
figure 1.4 I&amp;rsquo;ve setup the crypto as &amp;ldquo;3des&amp;rdquo; and &amp;ldquo;md5&amp;rdquo; for the hash, &amp;ldquo;diffie-hellman
group 2&amp;rdquo; for key exchange.&lt;span&gt;&amp;nbsp; &lt;/span&gt;Our authentication
will be set to &amp;ldquo;pres-share&amp;rdquo; and the default lifetime is used.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;MsoNormal&quot;&gt;Note: I have setup 3des/md5/D-H 2/pre-share with priority
value of 20 for l2l-tunnels.&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;Additionally, I have setup 3des/sha/D-H 2/pre-share with a
priority value of 65,535 for RA-tunnels.&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Figure 1.4&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;

&lt;a id=&quot;res_112&quot; href=&quot;http://info.routermonkey.org/gallery/1/ike-policies.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/ike-policies.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot;&gt;Now its time to configure IPSec rules for remote
access.&lt;span&gt;&amp;nbsp; &lt;/span&gt;In figure 1.5 I have both static
and dynamic crypto-maps defined.&lt;span&gt;&amp;nbsp; &lt;/span&gt;The
dynamic crypto-map will be used for remote access.&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot;&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Figure 1.5&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;

&lt;a id=&quot;res_117&quot; href=&quot;http://info.routermonkey.org/gallery/1/ipsec-rules.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/ipsec-rules.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;Under IPSec Rules if you click &amp;ldquo;ADD&amp;rdquo; the type needs to be dynamic;
you should see the screen shown in figure 1.6.&lt;span&gt;&amp;nbsp;
&lt;/span&gt;Here you will select your transform sets (default Transform Set already
exists).&lt;span&gt;&amp;nbsp; &lt;/span&gt;You want encapsulated services
protocol (ESP) so Add ESP-3DES-SHA and ESP-3DES-MD5.&lt;/p&gt;



&lt;p class=&quot;MsoNormal&quot;&gt;Check the box for Perfect Forward Secrecy and use Group 2.&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Figure 1.6&lt;/strong&gt;&lt;/p&gt;

&lt;a id=&quot;res_114&quot; href=&quot;http://info.routermonkey.org/gallery/1/114-ipsec-crypto-map.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/114-ipsec-crypto-map.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;Figure 1.7 shows the Crypto Map Advanced Tab, click on this
to set SA lifetime and enable NAT-T as well as reverse route injection.&lt;span&gt;&amp;nbsp; &lt;/span&gt;You want reverse route injection if you use a
dynamic process as it will create /32 routes for each tunnel session and inject
them into your dynamic process so your VPN users will be able to access resources
specified in remote access design specification.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Figure 1.7&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;

&lt;a id=&quot;res_115&quot; href=&quot;http://info.routermonkey.org/gallery/1/115-ipsec-crypto-map-adv.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/115-ipsec-crypto-map-adv.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;Next we will define our traffic selection.&lt;/p&gt;



&lt;p class=&quot;MsoNormal&quot;&gt;This segment can be a bit confusing for many.&lt;span&gt;&amp;nbsp; &lt;/span&gt;The confusion seems to be regarding what
traffic should be protected.&lt;span&gt;&amp;nbsp; &lt;/span&gt;For RA on
using a PIX you need to need to specify the interface (outside for most of us)
then the source address for the tunnel.&lt;span&gt;&amp;nbsp;
&lt;/span&gt;We are using &amp;ldquo;any&amp;rdquo; because this is a dynamic map and the source address
for the clients will be different depending on their location and ISP.&lt;/p&gt;





&lt;p class=&quot;MsoNormal&quot;&gt;The Destination address will be the subnet that you used
when you created your address pool back in figure 1.2.&amp;nbsp; You will want to use IP as the protocol unless there are
security related objectives the require being more restrictive.&lt;/p&gt;



&lt;span style=&quot;font-size: 12pt; font-family: &#039;Times New Roman&#039;&quot;&gt;Note: Most security related issues are better handled
via Security Policy and will be covered later.&lt;/span&gt;

&lt;p class=&quot;MsoNormal&quot;&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Figure 1.8&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;

&lt;a id=&quot;res_116&quot; href=&quot;http://info.routermonkey.org/gallery/1/ipsec-crypto-map-traffic-selection.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/ipsec-crypto-map-traffic-selection.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;Now let&amp;rsquo;s walk back up the tree to General/Group
Policy.&lt;span&gt;&amp;nbsp; &lt;/span&gt;I will click &amp;ldquo;ADD&amp;rdquo; and name my
group &amp;ldquo;lab-vpn&amp;rdquo;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Figure 1.9&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;

&lt;a id=&quot;res_141&quot; href=&quot;http://info.routermonkey.org/gallery/1/141-group_policy.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/141-group_policy.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: 12pt; font-family: &#039;Times New Roman&#039;&quot;&gt;Figure 2.0 shows the edit detail for the
Internal Group Policy &amp;ldquo;lab-vpn&amp;rdquo;. On the &amp;ldquo;general tab&amp;rdquo; just make sure that IPSec
is checked for the Cisco VPN Client.&lt;span&gt;&amp;nbsp;
&lt;/span&gt;L2TP over IPSec is not needed for this exercise and typically will
require you to use &amp;ldquo;certificates&amp;rdquo; during IKE phases which is not covered in
this document.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Figure 2.0&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;

&lt;a id=&quot;res_139&quot; href=&quot;http://info.routermonkey.org/gallery/1/139-group_pol_edit_general.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/139-group_pol_edit_general.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Next, click on the IPSec tab for lab-vpn.&lt;span&gt;&amp;nbsp; &lt;/span&gt;Enable PFS (perfect forward secrecy) this
will use the Diffie-Hellman Group 2 which was setup when you defined your
crypto-map.&lt;span&gt;&amp;nbsp; &lt;/span&gt;We will come back to this
section to specify Tunnel Group Lock later after we setup the Tunnel Group for
lab-vpn.&lt;span&gt;&amp;nbsp; &lt;/span&gt;Lets move on for now.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Figure 2.1&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;

&lt;a id=&quot;res_140&quot; href=&quot;http://info.routermonkey.org/gallery/1/140-group_pol_edit_ipsec.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/140-group_pol_edit_ipsec.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot;&gt;In Figure 2.2 we address parameters that will be passed to
the Cisco VPN Client after authentication.&amp;nbsp; Add your default domain and define your split tunnel
policy.&lt;span&gt;&amp;nbsp; &lt;/span&gt;For lab-vpn I am allowing split
tunnels. I am only allowing this in my Lab; otherwise you can choose to tunnel
everything. &lt;/p&gt;



&lt;p&gt;Under &amp;ldquo;Address Pools&amp;rdquo; you should see the &amp;ldquo;pix-tun-users&amp;rdquo;
pool you created earlier.&lt;span&gt;&amp;nbsp; &lt;/span&gt;Choose to add
that as you pool for lab-vpn group policy.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Figure 2.2&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;

&lt;a id=&quot;res_132&quot; href=&quot;http://info.routermonkey.org/gallery/1/132-group_pol_edit_client_conf.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/132-group_pol_edit_client_conf.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;In figure 2.2 under the split tunnel policy I have chosen to
tunnel the networks in the list &amp;ldquo;isi-vpn-nets&amp;rdquo;&lt;/p&gt;



&lt;p class=&quot;MsoNormal&quot;&gt;Below in 2.2(a) you can see the ACL that permits the
networks for this group policy.&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Figure 2.2(a)&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;

&lt;a id=&quot;res_96&quot; href=&quot;http://info.routermonkey.org/gallery/1/group_pol_edit_client_conf-nets.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/group_pol_edit_client_conf-nets.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;In figure 2.3 I&amp;rsquo;ve chosen to explicitly allow IPSec over UDP
for this group and have explicitly defined the port as 10000.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Figure 2.3&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;

&lt;a id=&quot;res_133&quot; href=&quot;http://info.routermonkey.org/gallery/1/133-group_pol_edit_client_conf-cisco-client-parms.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/133-group_pol_edit_client_conf-cisco-client-parms.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;Figure 2.4, 2.5, 2.6 and 2.7 are included for review but
will not be discussed as you may just accept the inherited values. &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Figure 2.4&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;

&lt;a id=&quot;res_134&quot; href=&quot;http://info.routermonkey.org/gallery/1/134-group_pol_edit_client_conf-ms-client-parms.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/134-group_pol_edit_client_conf-ms-client-parms.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Figure 2.5&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;

&lt;a id=&quot;res_136&quot; href=&quot;http://info.routermonkey.org/gallery/1/136-group_pol_edit_client_fw.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/136-group_pol_edit_client_fw.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Figure 2.6&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;

&lt;a id=&quot;res_137&quot; href=&quot;http://info.routermonkey.org/gallery/1/137-group_pol_edit_client_hw_client.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/137-group_pol_edit_client_hw_client.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Figure 2.7&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;

&lt;a id=&quot;res_138&quot; href=&quot;http://info.routermonkey.org/gallery/1/138-group_pol_edit_client_nac.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/138-group_pol_edit_client_nac.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;Time to create the Tunnel Group for lab-vpn.&lt;span&gt;&amp;nbsp; &lt;/span&gt;On the screen in figure 2.8 choose add and
name your Tunnel Group, I called mine &amp;ldquo;lab-vpn&amp;rdquo;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Figure 2.8&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;

&lt;a id=&quot;res_142&quot; href=&quot;http://info.routermonkey.org/gallery/1/tun-group-main-a.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/tun-group-main-a.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;In figure 2.9 At the general/basic tab while editing the
tunnel group &amp;ldquo;lab-vpn&amp;rdquo; explicitly select &amp;ldquo;lab-vpn&amp;rdquo; in the group policy section.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Figure 2.9&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;

&lt;a id=&quot;res_106&quot; href=&quot;http://info.routermonkey.org/gallery/1/tun-edit-basic.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/tun-edit-basic.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;Back in figure 1.0 and 1.1 we defined our authentication
server through Microsoft Windows AD via Kerberos. Tunnel
Group/General/Authentication is were we will apply this. Figure 3.0 shows that
&amp;ldquo;lab_authen&amp;rdquo; has been selected as the Authentication Server Group.&lt;/p&gt;



&lt;p class=&quot;MsoNormal&quot;&gt;Note: Use LOCAL if Server Group Fails is checked in this
example, this will allow authentication to default to the Pix local user
database in the event that servers in the defined ASG are unavailable.&lt;/p&gt;&lt;p&gt;NAC is not covered in this document.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Figure 3.0&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;

&lt;a id=&quot;res_104&quot; href=&quot;http://info.routermonkey.org/gallery/1/tun-edit-authen.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/tun-edit-authen.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;We will skip Authorization and Accounting as they are not
implemented in this how-to document. &lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot;&gt;We are using a local address pool for our implementation and
no DHCP scope is defined therefore the only thing needed in figure 3.1 is to
add the address pool &amp;ldquo;pix-tun-users&amp;rdquo;.&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Figure 3.1&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;

&lt;a id=&quot;res_107&quot; href=&quot;http://info.routermonkey.org/gallery/1/tun-edit-client-addy.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/tun-edit-client-addy.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;In figure 3.2 Tunnel Group/General/Advanced we will assign
lab_authen to the outside interface and choose &amp;ldquo;add&amp;rdquo;.&lt;span&gt;&amp;nbsp; &lt;/span&gt;Then we will repeat this process for our
address pool, assigning pix-tun-users to the outside interface and choosing
&amp;ldquo;add&amp;rdquo;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Figure 3.2&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;

&lt;a id=&quot;res_103&quot; href=&quot;http://info.routermonkey.org/gallery/1/tun-edit-advanced.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/tun-edit-advanced.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;In figure 3.3 we setup the IPSec parms for Tunnel Group
&amp;ldquo;lab-vpn&amp;rdquo;.&lt;span&gt;&amp;nbsp; &lt;/span&gt;We need to set a Pre-shared
Key (I am using &amp;ldquo;cisco&amp;rdquo; as my key), now make sure that xauth is used as the
Authentication Mode.&lt;span&gt;&amp;nbsp; &lt;/span&gt;This is important
when authentication is unidirectional or is offloaded to another device such as
RADIUS or two factor like RSA.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Figure 3.3&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;

&lt;a id=&quot;res_108&quot; href=&quot;http://info.routermonkey.org/gallery/1/tun-edit-ipsec.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/tun-edit-ipsec.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-size: 12pt; font-family: &#039;Times New Roman&#039;&quot;&gt;Figure 3.4 shows Tunnel Group/PPP, I&amp;rsquo;ve just
accepted the defaults as this will not be used in our implementation.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Figure 3.4&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;

&lt;a id=&quot;res_109&quot; href=&quot;http://info.routermonkey.org/gallery/1/tun-edit-ppp.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/tun-edit-ppp.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;Now you will want to revisit figure 2.1 in the Group Policy
and set your Tunnel Group Lock to &amp;ldquo;lab-vpn&amp;rdquo;.&lt;/p&gt;&lt;p&gt;Next if you are using NAT/PAT on your PIX, you will need to
set some NAT Exemptions for the address pool and networks that participate in
your VPN RA setup.&lt;span&gt;&amp;nbsp; &lt;/span&gt;If you examine figure
3.5 you will see that there are exemptions for isi-l2l-networks and
10.2.0.0/24.&lt;span&gt;&amp;nbsp; &lt;/span&gt;10.2.0.0/24 is our local
address pool and isi-l2l-networks is defined as the networks that will be
tunneled to clients in lab-vpn.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Figure 3.5&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;

&lt;a id=&quot;res_88&quot; href=&quot;http://info.routermonkey.org/gallery/1/nat.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/nat.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;Next we need to setup policy to allow our VPN RA connected
clients access to networks that are defined in isi-l2l-networks.&lt;/p&gt;



&lt;p class=&quot;MsoNormal&quot;&gt;You can see in figure 3.6 on rule 19 that 10.2.0.0/24 is
allowed to access the networks in isi-l2l-networks for protocol &amp;ldquo;IP&amp;rdquo;.&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Figure 3.6&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;

&lt;a id=&quot;res_89&quot; href=&quot;http://info.routermonkey.org/gallery/1/policy.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/policy.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;Be sure &amp;amp; save your config and good luck!&lt;/p&gt;



&lt;p class=&quot;MsoNormal&quot;&gt;This document was done in a hurry and the post mortem is
several months beyond the implementation date.&lt;span&gt;&amp;nbsp;
&lt;/span&gt;Additionally, I&amp;rsquo;ve used MS Paint to sanitize the information in the
images :)&lt;span&gt;&amp;nbsp; &lt;/span&gt;Therefore any
questions/comments should be directed to forums.routermonkey.org &lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot;&gt;&amp;nbsp;&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot;&gt;Regards,&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot;&gt;Barney Gaumer

&lt;/p&gt;&lt;p&gt;

RoUtermOnKey.org&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;Here are some &amp;ldquo;Monitor Screen Shots&amp;rdquo; for VPN RA Session.&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Exhibit A&lt;/strong&gt;&lt;/p&gt;

&lt;a id=&quot;res_90&quot; href=&quot;http://info.routermonkey.org/gallery/1/ra_mon.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/ra_mon.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;strong&gt;Exhibit B&lt;/strong&gt;&lt;/p&gt;

&lt;a id=&quot;res_91&quot; href=&quot;http://info.routermonkey.org/gallery/1/ra_mon-detail.JPG&quot;&gt;&lt;img src=&quot;http://info.routermonkey.org/gallery/1/previews-med/ra_mon-detail.JPG&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&amp;nbsp;&lt;/p&gt;</description>
   <link>http://info.routermonkey.org/index.php?op=ViewArticle&amp;articleId=8&amp;blogId=1</link>
      <pubDate>Wed, 24 Oct 2007 19:37:40 -0500</pubDate>   
  </item>
  </rdf:RDF>

