Solved

How to setup Cisco VPN Client to tunnel to Pix 515E

Posted on 2004-08-24
5
1,543 Views
Last Modified: 2013-11-16
I have a couple vendors that will need to tunnel in via the VPN Client to access accounting software and etc.
I would like to configure the Pix 515E to accept a couple users in to the LAN.  I understand I need to setup a
RADIUS Server.  I have a Win2003 Server I will use for RADIUS.  What do I need to setup on the Pix to allow
them in.  Cisco documentation appears to be very cryptic to follow.  Plus I didn't see anything for RADIUS setup.
Please help?  I was asked to make this happen in the next two days.  
0
Comment
Question by:rick_me27
  • 3
  • 2
5 Comments
 
LVL 79

Expert Comment

by:lrmoore
ID: 11883729
This document is pretty striaghtforward and shows exatly how to setup a Win2k server. Identical config on Win2k3 server

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00800b6099.shtml
0
 

Author Comment

by:rick_me27
ID: 11884325
Yes I found this ealier today and plan to use it as a guide tonight when I work on this.  Is there anything in particular I need to allow on the screening router.  I am having a T1 installed next week and I will be bring up the 2650 infront on the Pix.
I know I need to change default route and etc but what about for VPN access?
0
 
LVL 79

Accepted Solution

by:
lrmoore earned 250 total points
ID: 11884943
If you have a screening access router, you need to permit udp 500, tcp 50 (esp), udp 10000 and udp 4500 from any.

example

<inbound acl>
access-list 101 permit esp any host <ip address of PIX outside>
access-list 101 permit udp any host <ip address of PIX outside> eq 500
access-list 101 permit udp any host <ip address of PIX outside> eq 4500
access-list 101 permit udp any host <ip address of PIX outside> eq 1000
0
 

Author Comment

by:rick_me27
ID: 11884964
Thanks so much.  What is ESP?
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 11887778
udp port 500 = isakmp phase 1
esp / tcp port 50 = encapsulating security payload - this is the actual encrypted data stream, phase 2
Unless the client is behind a NAT device, then udp 4500 = ipsec payload
Older client software behind NAT device uses udp 10000 for encrypted payload
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Cisco Trunk question 4 40
ISP has issued 5 static IP addresses 4 39
ASA 5505 packet drops 14 54
Cisco 887VA secondary outgoing IP Address diferent from Default Dialer 4 52
From Cisco ASA version 8.3, the Network Address Translation (NAT) configuration has been completely redesigned and it may be helpful to have the syntax configuration for both at a glance. You may as well want to read official Cisco published AS…
This past year has been one of great growth and performance for OnPage. We have added many features and integrations to the product, making 2016 an awesome year. We see these steps forward as the basis for future growth.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

679 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question