I think it'd be better to take a look at the VPN Configuration where these attributes are used;
http://www.cisco.com/en/US
The above link should clarify it.
Cheers,
rsivanandan
Main Topics
Browse All TopicsHi,
1) I need to get clarification, confirmation and explanation (from the experts) related to Cisco VPN Configuration (Cisco ASA5500)
2) Would you please explain the meaning and the goal of this IOS commands:
First: group-policy remotevpn internal
*What is "group-policy"? It must be a kind of rule? right?
* What does it mean by "remotevpn"? (VPN is sure from Remote, right?)
* What and why "internal"? (This is confusing)
Second: group-policy remotevpn attributes
* What does the meaning of "attributes" here, and for what?
Third: dns-server value 10.254.254.10
* This means that the IP address of DNS server is 10.255.255.10? right?
Fourth: From earlier discussion, some experts say that IOS command is not the same as ASA command.
* is that right?
* Would you give the "link" to the ASA command?
3) Thank you
tjie
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
I think it'd be better to take a look at the VPN Configuration where these attributes are used;
http://www.cisco.com/en/US
The above link should clarify it.
Cheers,
rsivanandan
Business Accounts
Answer for Membership
by: PeteLongPosted on 2009-10-15 at 01:41:42ID: 25578506
>> group-policy remotevpn internal
you have a gorup polocy called rremotevpn (it could be called anything)
vpn-group-policy
To have a user inherit attributes from a configured group policy, use the vpn-group-policy command in username configuration mode. To remove a group policy from a user configuration, use the no version of this command. Using this command lets users inherit attributes that you have not configured at the username level.
vpn-group-policy {group-policy name}
no vpn-group-policy {group-policy name}
>>What is "group-policy"? It must be a kind of rule? right?
see above
>>What and why "internal"? (This is confusing)
external Enter this keyword to specify an external group policy
internal Enter this keyword to specify an internal group policy
>>Second: group-policy remotevpn attributes
>> * What does the meaning of "attributes" here, and for what?
attributes lets you configure the things to do with that policy i.e.
They are (theres a lot of them be warned)
address-pools Configure list of up to 6 address pools to Configure interactive authentication. This imeout Configure the idle timeout period in
assign addresses from
backup-servers Configure list of backup servers to be used
by the remote client
banner Configure a banner, or welcome text to be
displayed on the VPN remote client
client-access-rule Specify rules permitting/denying access to
specific client types and versions.
client-firewall Configure the firewall requirements for
users in this group-policy
default-domain Configure default domain name given to
users of this group
dhcp-network-scope Specify the range of IP addresses to
indicate to the DHCP server for address
assignment
dns-server Configure the primary and secondary DNS
servers
exit Exit from group-policy configuration mode
group-lock Enter name of an existing tunnel-group that
users are required to connect with
help Help for group_policy configuration
commands
intercept-dhcp Enable this command to use group policy for
clients requesting Microsoft DHCP
ip-comp Enter this command to enable IP compression
(LZS)
ip-phone-bypass Configure to allow Cisco IP phones behind
Hardware clients to bypass the Individual
User Authentication process.
ipsec-udp Enter this command to allow a client to
operate through a NAT device using UDP
encapsulation
ipsec-udp-port Enter the UDP port to be used by the client
for IPSec through NAT
leap-bypass Enable/disable LEAP packets from Cisco
wireless devices to bypass the individual
user authentication process. This setting
applies only to HW clients.
msie-proxy Enter this command to configure MSIE
Browser Proxy settings for a client system
nac Enable/Disable Network Admission
Control(NAC).
nac-default-acl Specify the filter to apply when NAC is
initialized
nac-reval-period Specify the NAC Revalidation timer
nac-sq-period Specify the NAC Status Query timer
nem Configure hardware clients to use network
extension mode. This setting applies only
to HW clients.
no Remove an attribute value pair
password-storage Enable/disable storage of the login
password on the client system
pfs Enter this command to indicate that the
remote client needs to perform PFS
re-xauth Enter this command to enable
reauthentication of the user on IKE rekey
secure-unit-authentication
setting applies only to HW clients.
split-dns Configure list of domains to be resolved
through the Split Tunnel
split-tunnel-network-list Configure name of access-list for split
tunnel configuration
split-tunnel-policy Select the split tunneling method to be
used by the remote client
user-authentication Configure individual user authentication.
This setting applies only to HW clients.
user-authentication-idle-t
minutes. If there is no communication in
this period, the system terminates the
connection. This setting applies only to HW
clients.
vpn-access-hours Enter name of a configured time-range
policy
vpn-filter Enter name of a configured ACL to apply to
users
vpn-idle-timeout Enter idle timeout period in minutes, enter
none to disable
vpn-nac-exempt Specify NAC Exception List entries
vpn-session-timeout Enter maximum user connection time in
minutes, enter none for unlimited time
vpn-simultaneous-logins Enter maximum number of simultaneous logins
allowed
vpn-tunnel-protocol Enter permitted tunneling protocols
webvpn Configure group policy for WebVPN
wins-server Configure the primary and secondary WINS
servers
>>Third: dns-server value 10.254.254.10
* This means that the IP address of DNS server is 10.255.255.10? right?
Spot on thats correct :)
>>Fourth: From earlier discussion, some experts say that IOS command is not the same as ASA command.
* is that right?
* Would you give the "link" to the ASA command?
Yes its very different :)
http://tools.cisco.com/S upport/CLI Lookup/clt SearchActi on.do?Appl ication_ID =CLT&Index Id=IOS&Ind exOptionId =123&Searc hPhrase="* "&Paging=2 5&ActionTy pe=getComm andList&Bo okmark=Tru e
Note you will need a valid support agreement for that link to work
ASA config guides
http://www.cisco.com /en/US/pro ducts/ps61 20/tsd_pro ducts_supp ort_config ure.html