?
Solved

Setting up Cisco VPN (remote access, Lab setup only)

Posted on 2006-11-06
7
Medium Priority
?
416 Views
Last Modified: 2006-11-18
I want to setup a remote access VPN (read: Where a user uses Cisco VPN client software to connect to a VPN termination device).  This is in a lab.

Here's the thing: I have setup an IPSEC VPN between two 2501 routers, with a end user on each side. (I'm assuming this is a site to site VPN?) I still have it setup.
Would it be possible to use the exact same configuration and have a user connect to the router with VPN client software? Or would I need to change a lot of things in the routers config?

I will post the sh run of one of the routers in "the site to site" VPN shortly. Hopefully, I can use one of these routers for the job

Thanks
0
Comment
Question by:dissolved
  • 4
  • 3
7 Comments
 

Author Comment

by:dissolved
ID: 17882538
Here is the sh run from one of my routers currently in a site to site VPN. Can i use this config for remote access? If not, what would I have to change?
Thanks

NY#sh run
Building configuration...

Current configuration : 1219 bytes
!
version 12.2
no service single-slot-reload-enable
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname NY
!
logging rate-limit console 10 except errors
enable secret 5 $1$kprY$RN4NWD24I3TSc0qTVz3oo0
!
ip subnet-zero
no ip finger
!
no ip dhcp-client network-discovery
!
crypto isakmp policy 100
 authentication pre-share
 group 2
 lifetime 3600
crypto isakmp key vpntime address 192.168.1.1
!
crypto ipsec security-association lifetime seconds 1800
!
crypto ipsec transform-set 20 esp-des esp-sha-hmac
!
crypto map SanFran 120 ipsec-isakmp
 set peer 192.168.1.1
 set transform-set 20
 set pfs group2
 match address 105
!
!
!
!
interface Ethernet0
 description internal
 ip address 10.10.1.1 255.255.0.0
!
interface Serial0
 description Connected to 2500B
 ip address 192.168.3.1 255.255.0.0
 encapsulation ppp
 crypto map SanFran
!
interface Serial1
 ip address 68.34.76.5 255.255.0.0
 shutdown
!
ip kerberos source-interface any
ip classless
ip route 0.0.0.0 0.0.0.0 192.168.1.1
ip http server
!
access-list 105 permit ip 10.10.0.0 0.0.255.255 172.16.0.0 0.0.255.255
!
!
line con 0
 transport input none
line aux 0
line vty 0 4
 password testsetup
 login
!
end

NY#
0
 
LVL 43

Expert Comment

by:JFrederick29
ID: 17883162
It's been my experience with 2500's that it doesn't work.   I once spent a lot of time trying to get it to work with no success.  You really need a "non-2500" series router or PIX to setup a remote access VPN.  You can't do VPN group configuration on the 2500.  I believe the extent of the 2500's "remote access" VPN is configuring it as an Easy VPN server or client.
0
 

Author Comment

by:dissolved
ID: 17884098
I have a 2610 router and a pix501 here at the house. Can I use the 2610? If so, how would I get started? Can I steal anything from the 2500 config?

thanks
0
Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

 
LVL 43

Accepted Solution

by:
JFrederick29 earned 2000 total points
ID: 17884360
The PIX 501 is capable.  The 2610 should be capable as long as it has an IOS with the IPSEC feature set.

This article covers the basics of setting up an IOS based remote access VPN.

http://www.fredshack.com/docs/vpnios.html

Here's a configuration guide for the PIX:

http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a0080172787.html
0
 

Author Comment

by:dissolved
ID: 17884507
thanks! So for the 2600 link you sent me, I should pay particular attention to the first config (VPN only).  I'm going to give it a shot

For the PIX, how can I tell if I have the capability to use EasyVPN? I have ios 6.3(3). Pix501

Thanks
0
 
LVL 43

Expert Comment

by:JFrederick29
ID: 17884705
The PIX 501 is definitely capable out of the box.  I have done it before on a PIX.
0
 

Author Comment

by:dissolved
ID: 17885219
thx
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

We've been using the Cisco/Linksys RV042 for years as: - an internet Gateway - a site-to-site VPN device - a leased line site-to-site subnet-to-subnet interface (And, here I'm assuming that any RV0xx behaves the same way as an RV042.  So that's …
In short, I will be giving a guide on how to install UNMS on a virtual machine in hyper-v and change the default port for security (you don’t need to have a server, since Windows 10 supports hyper-v)
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

569 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question