Solved

Setting up Cisco VPN (remote access, Lab setup only)

Posted on 2006-11-06
7
367 Views
Last Modified: 2006-11-18
I want to setup a remote access VPN (read: Where a user uses Cisco VPN client software to connect to a VPN termination device).  This is in a lab.

Here's the thing: I have setup an IPSEC VPN between two 2501 routers, with a end user on each side. (I'm assuming this is a site to site VPN?) I still have it setup.
Would it be possible to use the exact same configuration and have a user connect to the router with VPN client software? Or would I need to change a lot of things in the routers config?

I will post the sh run of one of the routers in "the site to site" VPN shortly. Hopefully, I can use one of these routers for the job

Thanks
0
Comment
Question by:dissolved
  • 4
  • 3
7 Comments
 

Author Comment

by:dissolved
ID: 17882538
Here is the sh run from one of my routers currently in a site to site VPN. Can i use this config for remote access? If not, what would I have to change?
Thanks

NY#sh run
Building configuration...

Current configuration : 1219 bytes
!
version 12.2
no service single-slot-reload-enable
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname NY
!
logging rate-limit console 10 except errors
enable secret 5 $1$kprY$RN4NWD24I3TSc0qTVz3oo0
!
ip subnet-zero
no ip finger
!
no ip dhcp-client network-discovery
!
crypto isakmp policy 100
 authentication pre-share
 group 2
 lifetime 3600
crypto isakmp key vpntime address 192.168.1.1
!
crypto ipsec security-association lifetime seconds 1800
!
crypto ipsec transform-set 20 esp-des esp-sha-hmac
!
crypto map SanFran 120 ipsec-isakmp
 set peer 192.168.1.1
 set transform-set 20
 set pfs group2
 match address 105
!
!
!
!
interface Ethernet0
 description internal
 ip address 10.10.1.1 255.255.0.0
!
interface Serial0
 description Connected to 2500B
 ip address 192.168.3.1 255.255.0.0
 encapsulation ppp
 crypto map SanFran
!
interface Serial1
 ip address 68.34.76.5 255.255.0.0
 shutdown
!
ip kerberos source-interface any
ip classless
ip route 0.0.0.0 0.0.0.0 192.168.1.1
ip http server
!
access-list 105 permit ip 10.10.0.0 0.0.255.255 172.16.0.0 0.0.255.255
!
!
line con 0
 transport input none
line aux 0
line vty 0 4
 password testsetup
 login
!
end

NY#
0
 
LVL 43

Expert Comment

by:JFrederick29
ID: 17883162
It's been my experience with 2500's that it doesn't work.   I once spent a lot of time trying to get it to work with no success.  You really need a "non-2500" series router or PIX to setup a remote access VPN.  You can't do VPN group configuration on the 2500.  I believe the extent of the 2500's "remote access" VPN is configuring it as an Easy VPN server or client.
0
 

Author Comment

by:dissolved
ID: 17884098
I have a 2610 router and a pix501 here at the house. Can I use the 2610? If so, how would I get started? Can I steal anything from the 2500 config?

thanks
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 43

Accepted Solution

by:
JFrederick29 earned 500 total points
ID: 17884360
The PIX 501 is capable.  The 2610 should be capable as long as it has an IOS with the IPSEC feature set.

This article covers the basics of setting up an IOS based remote access VPN.

http://www.fredshack.com/docs/vpnios.html

Here's a configuration guide for the PIX:

http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a0080172787.html
0
 

Author Comment

by:dissolved
ID: 17884507
thanks! So for the 2600 link you sent me, I should pay particular attention to the first config (VPN only).  I'm going to give it a shot

For the PIX, how can I tell if I have the capability to use EasyVPN? I have ios 6.3(3). Pix501

Thanks
0
 
LVL 43

Expert Comment

by:JFrederick29
ID: 17884705
The PIX 501 is definitely capable out of the box.  I have done it before on a PIX.
0
 

Author Comment

by:dissolved
ID: 17885219
thx
0

Featured Post

Gigs: Get Your Project Delivered by an Expert

Select from freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

There are two basic ways to configure a static route for Cisco IOS devices. I've written this article to highlight a case study comparing the configuration of a static route using the next-hop IP and the configuration of a static route using an outg…
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

785 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question