Solved

CISCO Pix 501 and Windows Server 2003 VPN Configuration

Posted on 2008-10-02
4
481 Views
Last Modified: 2012-05-05
Hello,

I have the need to allow remote users access to one of our file servers in our internal network. We use a Cisco Pix 501 firewall and a Windows 2003 Domain with Active Directory. I'm thoroughly confused, don't know whether the configuration should take place in the domain or the pix. Would appreciate any help on this issue.

This is the first time for me so would appreciate step by step explanation.

Thanks in advance,

Frank
0
Comment
Question by:falp
  • 2
4 Comments
 
LVL 8

Expert Comment

by:Jay_Gridley
Comment Utility
I would personnally recommend using the PIX as your VPN terminator. I.e. configure your pix to allow incoming VPN sessions. This way they can securely access your network in general and the fileserver in particular.

I don't have a PIX handy to actually tell you all the seperate steps, so what I would recommend doing is the following.
Use the VPN wizard to setup your Mobile VPN. This should get you started. If you have specific problems you can post your config and I (and the other experts) will help you further.
0
 
LVL 79

Expert Comment

by:lrmoore
Comment Utility
I second the motion to use the inherent capabilities of the PIX. You could simply allow remote desktop through the pix to the server by allowing tcp 3389 (or set the server to listen on any other non-standard port... or setup the PIX for remote access VPN. The wizard does walk you through it, but it won't tell you that you need to use a different subnet for the address pool.
Here's a step-by-step command line example
http://www.cisco.com/en/US/products/sw/secursw/ps2308/products_configuration_example09186a00801e71c0.shtml
0
 

Author Comment

by:falp
Comment Utility
I still don't understand. Jay's suggestion of just allowing vpn traffic through and leaving WIndows server 2003 to deal with authentication, makes sense, but I just didn't see a way of configuring this in the pix, the vpn wizard ask me to set up a AAA server and I don't know how to set up this. Any help both front would be appreciated.
0
 
LVL 8

Accepted Solution

by:
Jay_Gridley earned 500 total points
Comment Utility
I would start with just setting up the mobile VPN itself.
Create a local user with which you can test.

After that you can setup the Pix to use Radius for authentication instead. You can use IAS from Microsoft wich is inculded in Windows Server 2003. You can install this through add/remove programs and add windows features.
When you have IAS installed it's only a few commands on the pix to have it use the Windows server for authentication.

If you prefer to do it all in one go this is also possible. Then start with setting up IAS on the Windows server and use this as your AAA server in the vpn wizard.
0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

This article will cover setting up redundant ISPs for outbound connectivity on an ASA 5510 (although the same should work on the 5520s and up as well).  It’s important to note that this covers outbound connectivity only.  The ASA does not have built…
I've written this article to illustrate how we can implement a Dynamic Multipoint VPN (DMVPN) with both hub and spokes having a dynamically assigned non-broadcast multiple-access (NBMA) network IP (public IP). Here is the basic setup of DMVPN Pha…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now