Table Of Contents
Using the Site-to-Site VPN Connection Setup Wizard
Configuring the Crypto Connection
Configuring IKE Information (Optional)
Configuring Remote Peer Information
Configuring Traffic to Be Protected
Site-to-Site VPN Connection Setup Wizard Summary
Using the Secure GRE Tunnel Setup Wizard
Configuring the Crypto Connection
Configuring IKE Information (Optional)
Secure GRE Tunnel Setup Wizard Summary
Using the Remote Access Server Setup Wizard
Configuring Connection Parameters
Viewing Group Policy Information
Viewing RADIUS Server Information
Configuring Group Policy Lookup
Configuring Extended Authentication
Configuring Accounting Information
Remote Access Server Wizard Summary
Setup Wizards
CVDM-VPNSM allows you to set up VPN module features with the help of wizards, which simplifies complex configuration tasks.
Figure 2-1 CVDM-VPNSM Main Wizard Page
CVDM-VPNSM provides the following Setup wizards:
•
Site-to-Site VPN Connection Setup wizard—This wizard allows you to create and configure a site-to-site VPN. See Using the Site-to-Site VPN Connection Setup Wizard.
•
Secure GRE Tunnel Setup wizard—This wizard allows you to create a secure GRE tunnel on the device for protected traffic flow. See Using the Secure GRE Tunnel Setup Wizard.
•
Remote Access Server Setup wizard—This wizard allows you to create and configure a remote access server connection. See Using the Remote Access Server Setup Wizard.
Using the Site-to-Site VPN Connection Setup Wizard
The Site-to-Site VPN Connection Setup wizard allows you to create a secure site-to-site VPN and configure settings for it, such as crypto connections, IKE policy information, and policies for protecting the traffic flowing on the connection.
For more information about site-to-site VPNs, see "Site-to-Site VPN Configuration."
Step 1
Click Setup at the top of the window and click Wizard in the left-most pane. The main VPN Wizard page appears.
Step 2
Select the Site-to-Site VPN Connection radio button.
Step 3
Click Launch the Selected Task.
Configuring the Crypto Connection
In Step 1 of the Site-to-Site VPN Connection Setup wizard, you create a crypto connection between the device and the peer. CVDM-VPNSM automatically detects the inside and outside VLANs.
For more information about configuring cyrpto connections for site-to-site VPNs, see Configuring Crypto Connections.
Note
You can click the Advance... button to display the Add Crypto Connection dialog box. This dialog box provides more detailed options for defining a crypto connection. For more information, see Add Crypto Connection Dialog Box.
To create a crypto connection using the fields on this page, define the following.
GUI Element Action/DescriptionVPN Module list or field
Select, from the list, the slot on the device where the VPN module is located (if there are multiple VPN modules in the chassis).
If there is only one VPN module in the chassis, the VPN Module field displays the slot on the device where the VPN module is located. You cannot edit this field.
IP Address paneIP address field
Enter the IP address of the interface VLAN, which is the Layer 3 VLAN that contains only the VPN module inside port. This IP address is used by the remote peer to connect to this site.
Note
The interface VLAN is removed from all trunk ports on the switch.
Mask list
Select, from the list, the subnet mask address of the interface VLAN.
VPN Outside Interface paneAvailable Ports Table
Select the VPN outside interface. The outside interface is used to connect to the device. You can only select one port. If you require additional ports, you must add and configure a site-to-site VPN from the Setup > Site-to-Site page. For more information, see "Site-to-Site VPN Configuration."
This table contains the port selector, which allows you to select ports. For more information, see Port Selector.
Advance... button
Click to display the Add Crypto Connection dialog box. This dialog box provides more detailed options for defining a crypto connection. For more information, see Add Crypto Connection Dialog Box.
Add Crypto Connection Dialog Box
This dialog box provides more detailed options for configuring your crypto connection.
Define the following.
GUI Element Action/Description VPN Inside Interface paneInterface VLAN field
Specify the interface VLAN, which is the Layer 3 VLAN that contains only the VPN module inside port.
Note
The interface VLAN is removed from all trunk ports on the switch.
You can create a VLAN or select from an available VLAN.
Click
and do one of the following:
•
Select Select VLAN to open the VLAN Selector dialog box. See VLAN Selector for more information.
•
Select Create VLAN to open the Create VLAN dialog box. See Create VLAN Dialog Box for more information.
You can select Clear VLAN to clear the VLAN that is specified in this field.
IP Address field
Enter the IP address of the interface VLAN.
Mask list
Select the subnet mask of the interface VLAN from the list or enter it in the field.
VPN Outside Interface paneConnection Mode radio button
Specify the connection mode; you can select the Access/Trunk radio button to specify an access port or trunk port as the outside port, or you can select the Routed Port radio button to specify a routed port as the outside port.
If you select the Access/Trunk radio button, do the following:
1.
Specify an outside VLAN. You can create a VLAN or choose an available VLAN. From the Outside VLAN field, click
and do one of the following:
•
Select Select VLAN to open the VLAN Selector dialog box. See VLAN Selector for more information.
•
Select Create VLAN to open the Create VLAN dialog box. See Create VLAN Dialog Box for more information.
You can select Clear VLAN to clear the VLAN that is specified in this field.
2.
Specify the VPN Outside interface from the Port Selector in Step 1 of the Site-to-Site VPN Wizard page. For more information, see Configuring the Crypto Connection.
If you select the Routed Port radio button, you must select a routed port. From the Routed Port field, click
to open the Select Routed Ports dialog box. For more information, see Select Routed Port Dialog Box.
Configuring IKE Information (Optional)
In Step 2 of the Site-to-Site VPN Connection Setup wizard, you configure your Internet Key Exchange (IKE) information. For more information about configuring IKE settings, see Configuring IKE Settings.
Define the following.
GUI Element Action/DescriptionAdd New IKE Policy check box
Select this check box to create a new IKE policy. Then, edit the appropriate values:
•
Priority field—Enter the IKE policy priority value. Each policy is uniquely identified by the priority number you assign. The range of values is 1 to 10000.
•
Encryption list—Select, from the list, the protocol to be used for encrypting data. Available values are DES, 3DES, AES_128, AES_192, and AES_256.
•
Hash list—Select, from the list, the hash algorithm to be used (MD5 of SHA_1).
•
Authentication—Select, from the list, the method used for authenticating data (PRE_SHARE). CVDM-VPNSM supports only preshared keys.
•
D-H Group list—Select, from the list, the Diffie-Hellman (D-H) group for the policy. Value can be group1, group2, or group5.
A D-H key is an algorithm that allows two VPN peers who have agreed to policies to exchange information over untrusted and unencrypted networks and develop a shared key.
View Existing IKE Policies button
Select to view the IKE policies that are configured. Click
to open the IKE policy dialog box. See IKE Policy List Dialog Box for more information.
IKE Policy List Dialog Box
This dialog box can be launched from several pages and contains information about your configured IKE policies. This dialog box contains a table that displays the following information:
Configuring Remote Peer Information
In Step 3 of the Site-to-Site VPN Connection Setup wizard, you configure a peer whose IP address is the address of the remote site. You also configure a preshared key for the remote peer for IKE authentication.
Preshared keys allow for one or more peers to use individual shared secrets to authenticate encrypted tunnels to a gateway. The same preshared key must be set on the remote peer and any other participating peers.
Define the following.
GUI Element Action/Description Peer Information panePeer IP Address field
Enter the IP address of the peer.
Preshared Key field
Enter the preshared key used for the peers.
If a preshared key has previously been configured for the peer, this field is populated with that information, and you cannot edit this field.
Reenter Preshared Key field
Re-enter the preshared key used for the peers.
Add>> button
After entering a peer IP address, click to add to the Peer List table.
<<Remove button
To remove an entry from the Peer List table, select the entry and click <<Remove.
Peer List table
Displays all peers participating in the VPN tunnel.
Configuring a Transform Set
In Step 4 of the Site-to-Site VPN Connection Setup wizard, you configure the transform set that will be used to protect the traffic on this network. A transform set is a combination of security protocols, algorithms, and other settings to apply to IPSec-protected traffic. In this step, you can select from available transform sets or create a new one. For more information on transform sets, see Configuring Transform Sets.
Define the following.
GUI Element Action/DescriptionCreate New Transform Set radio button
Select this radio button to create a new transform set. Then, edit the appropriate values.
•
Create New Transform Set field—Enter a name for the transform set.
•
Encryption (ESP)—Select the ESP protocol (DES, 3DES, Null, AES, AES-192, or AES-256) used for encrypting data. Use ESP encryption when ESP authentication is selected.
•
Authentication (ESP)—Select the ESP algorithm (SHA or MD5) used for ensuring data integrity.
Note
Tunnel mode is the default mode for the VPN tunnel. In tunnel mode, both the data sent by VPN clients and the inside IP address of the client are encrypted.
Use Existing Transform Set radio button
Select this radio button to select from available transform sets. Then, click
to open the Transform Set List dialog box. See Transform Set List Dialog Box for more information.
Transform Set List Dialog Box
This dialog box can be launched from several pages and contains information about your configured transform sets. It contains a table that displays the following information:
Configuring Traffic to Be Protected
In Step 5 of the Site-to-Site VPN Connection Setup wizard, you specify how the traffic on the VPN is protected. You can specify the subnets on which all traffic is protected, or you can specify an IPSec rule to be used for protecting traffic.
Define the following.
GUI Element Action/DescriptionProtect all traffic between the following subnets radio button
Select this radio button to specify two subnets between which traffic is protected. Only traffic between the source and destination on the tunnel is protected. Then, do the following:
•
In the Local Site pane, specify the local site from which the protected traffic originates. Then:
–
In the IP Address field, enter the IP address of the source.
–
From the Subnet list, select the subnet mask address of the source.
•
In the Remote Site pane, specify the remote site on which protected traffic terminates. Then:
–
In the IP Address field, enter the IP address of the destination.
–
From the Subnet list, select the subnet mask address of the destination.
CVDM-VPNSM automatically creates the rule that permits all IP traffic from the local site network to the remote site network.
Protect traffic specified by IPSec rule radio button
Select this radio button to specify an IPSec rule to be applied for traffic protection. Click
and select Select ACL... to select from available IPSec rules. The Select a Rule dialog box appears. See Select a Rule Dialog Box for more information.
You can also clear the entry in this field by selecting Clear Selection....
For more information about IPSec rules, see Configuring Access and IPSec Rules.
Select a Rule Dialog Box
This dialog box can be launched from several pages and allows you to select an IPSec rule. It displays the following information.
Site-to-Site VPN Connection Setup Wizard Summary
The summary page of the wizard shows you the information that you entered.
Click Finish to send the commands to the device. The Deliver Configuration to Switch/Module(s) dialog box appears if you have configured CVDM-VPNSM to display the accumulated CLI commands after you have completed a wizard (for information on configuring this option, see Editing Preferences).
For more information on the Deliver Configuration to Switch/Module(s) dialog box, see Delivering CLI Commands to the Device.
Using the Secure GRE Tunnel Setup Wizard
In the Secure GRE Tunnel Setup wizard, you create and configure secure GRE tunnels between your device and a remote peer. Generic routing encapsulation (GRE) is a tunneling protocol that can encapsulate different protocol packet types inside encrypted IP packets. The device and the peer must be configured with the same information for the GRE tunnel to work.
For more information about GRE tunnels, see Configuring GRE Tunnels.
Step 1
Click Setup at the top of the window and click Wizard in the left-most pane. The main VPN Wizard page appears.
Step 2
Select the Configure Secure GRE Tunnel radio button.
Step 3
Click Launch the Selected Task.
Configuring the Crypto Connection
In Step 1 of the Secure GRE Tunnel Setup wizard, you configure a crypto connection between the device and the peer. For more information on crypto connections, see Configuring Crypto Connections.
Note
You can click the Advance... button to display the Add Crypto Connection dialog box. This dialog box provides more detailed options for defining a crypto connection. For more information, see Add Crypto Connection Dialog Box.
To create a crypto connection using the fields on this page, define the following.
GUI Element Action/DescriptionVPN Module list
Select, from the list, the slot on the device where the VPN module is located (if there are multiple VPN modules in the chassis).
If there is only one VPN module in the chassis, the VPN Module field displays the slot on the device where the VPN module is located. You cannot edit this field.
IP Address paneIP address field
Enter the IP address of the interface VLAN, which is the Layer 3 VLAN that contains only the VPN module inside port. This IP address is used by the remote peer to connect to this site.
Note
The interface VLAN is removed from all trunk ports on the switch.
Mask list
Enter the subnet mask address of the interface VLAN.
VPN Outside Interface paneAvailable Ports Table
Select the VPN outside interface. The outside interface is used to connect to the device. You can only select one port. If you require additional ports, you must add and configure a site-to-site VPN from the Setup > Site-to-Site page. For more information, see "Site-to-Site VPN Configuration."
This table contains the port selector, which allows you to select ports. For more information, see Port Selector.
Advance... button
Click to display the Add Crypto Connection dialog box. This dialog box provides more detailed options for defining a crypto map. For more information, see Add Crypto Connection Dialog Box.
Configuring Tunnel Parameters
In Step 2 of the Secure GRE Tunnel Setup wizard, you define the parameters for the GRE tunnel. For more information about GRE tunnels, see Configuring GRE Tunnels.
Define the following:
Configuring IKE Information (Optional)
In Step 3 of the Secure GRE Tunnel Setup wizard, you configure your Internet Key Exchange (IKE) information. For more information about configuring IKE settings, see Configuring IKE Settings.
Define the following.
GUI Element Action/DescriptionAdd New IKE Policy check box
Select this check box to create a new IKE policy. Then, edit the appropriate values:
•
Priority field—Enter the IKE policy priority value. Each policy is uniquely identified by the priority number you assign. The range of values is 1 to 10000.
•
Encryption list—Select, from the list, the protocol to be used for encrypting data. Available values are DES, 3DES, AES_128, AES_192, and AES_256.
•
Hash list—Select, from the list, the hash algorithm to be used (MD5 of SHA_1).
•
Authentication—Select, from the list, the method used for authenticating data (PRE_SHARE). CVDM-VPNSM supports only preshared keys.
•
D-H Group list—Select, from the list, the Diffie-Hellman (D-H) group for the policy. Value can be group1, group2, or group5.
A D-H key is an algorithm that allows two VPN peers who have agreed to policies to exchange information over untrusted and unencrypted networks and develop a shared key.
View Existing IKE Policies button
Select to view the IKE policies that are configured. Click
to open the IKE policy dialog box. See IKE Policy List Dialog Box for more information.
Configuring a Transform Set
In Step 4 of the Secure GRE Tunnel Setup wizard, you configure the transform set that will be applied to the traffic flowing on this tunnel. A transform set is a combination of security protocols, algorithms, and other settings to apply to IPSec protected traffic. In this step, you can select from available transform sets or create a new one. For more information on transform sets, see Configuring Transform Sets.
Define the following.
GUI Element Action/DescriptionCreate New Transform Set radio button
Select this radio button to create a new transform set. Then, edit the appropriate values.
•
Create New Transform Set field—Enter a name for the transform set.
•
Encryption (ESP)—Select the ESP protocol (DES, 3DES, Null, AES, AES-192, or AES-256) used for encrypting data. Use ESP encryption when ESP authentication is selected.
•
Authentication (ESP)—Select the ESP algorithm (SHA, or MD5) used for ensuring data integrity.
Note
Transport mode is the default mode for the GRE tunnel. In transport mode, only the data sent by VPN clients is encrypted.
Use Existing Transform Set radio button
Select this radio button to select from available transform sets. Then, click
to open the Transform List dialog box. See Transform Set List Dialog Box for more information.
After you have made your configurations in the Secure GRE Tunnel Setup wizard, CVDM-VPNSM creates IPsec rules that protect the traffic flowing from an interface IP address and terminating on a tunnel destination IP address.
Secure GRE Tunnel Setup Wizard Summary
The summary page of the wizard shows you the information that you entered.
Click Finish to send the commands to the device. The Deliver Configuration to Switch/Module(s) dialog box appears if you have configured CVDM-VPNSM to display the accumulated CLI commands after you have completed a wizard (for information on configuring this option, see Editing Preferences).
For more information on the Deliver Configuration to Switch/Module(s) dialog box, see Delivering CLI Commands to the Device.
Using the Remote Access Server Setup Wizard
In the Remote Access Server Setup wizard, you configure the settings for the server that establishes and manages secure connections between remote users and this device.
For more information about configuring remote access connections, see "Remote Access Configuration."
Step 1
Click Setup at the top of the window and click Wizards in the left-most pane. The main VPN Wizard page appears.
Step 2
Select the Configure Remote Access Server radio button.
Step 3
Click Launch the Selected Task.
Configuring Connection Parameters
In Step 1 of the Remote Access Server Setup wizard, you configure the connection a remote device will use to establish a VPN connection with the module. For more information on crypto connection configuration, see Configuring Crypto Connections.
Note
You can click the Advance... button to display the Add Crypto Connection dialog box. This dialog box provides more detailed options for defining a crypto connection. For more information, see Add Crypto Connection Dialog Box.
To create a crypto connection using the fields on this page, define the following.
GUI Element Action/DescriptionVPN Module list or field
Select, from the list, the slot on the device where the VPN module is located (if there are multiple VPN modules in the chassis).
If there is only one VPN module in the chassis, the VPN Module field displays the slot on the device where the VPN module is located. You cannot edit this field.
IP Address paneIP Address field
Enter the IP address of the interface VLAN, which is the Layer 3 VLAN that contains only the VPN module inside port. This IP address is used by the remote peer to connect to this site.
Note
The interface VLAN is removed from all trunk ports on the switch.
Mask list
Select, from the list, the subnet mask address of the interface VLAN.
VPN Outside Interface paneAvailable Ports Table
Select the VPN outside interface. The outside interface is used to connect to the device. You can only select one port. If you require additional ports, you must add and configure a remote access VPN from the Setup > Remote Access page. For more information, see "Remote Access Configuration."
This table contains the port selector, which allows you to select ports. For more information, see Port Selector.
Advance... button
Click to display the Add Crypto Connection dialog box. This dialog box provides more detailed options for defining a crypto connection. For more information, see Add Crypto Connection Dialog Box.
Configuring IKE Policies
In Step 2 of the Remote Access Server Setup wizard, you configure your Internet Key Exchange (IKE) information. For more information about configuring IKE settings, see Configuring IKE Settings.
Define the following.
GUI Element Action/DescriptionAdd New IKE Policy check box
Select this check box to create a new IKE policy. Then, edit the appropriate values:
•
Priority field—Enter the IKE policy priority value. Each policy is uniquely identified by the priority number you assign. The range of values is 1 to 10000.
•
Encryption list—Select, from the list, the protocol to be used for encrypting data. Available values are DES, 3DES, AES_128, AES_192, and AES_256.
•
Hash list—Select, from the list, the hash algorithm to be used (MD5 of SHA_1).
•
Authentication—Select, from the list, the method used for authenticating data (PRE_SHARE). CVDM-VPNSM supports only preshared keys.
•
D-H Group list—Select, from the list, the Diffie-Hellman (D-H) group for the policy. Value can be group1, group2, or group5.
A D-H key is an algorithm that allows two VPN peers who have agreed to policies to exchange information over untrusted and unencrypted networks and develop a shared key.
View Existing IKE Policies button
Select to view the IKE policies that are configured. Click
to open the IKE policy dialog box. See IKE Policy List Dialog Box for more information.
Configuring Transform Sets
In Step 3 of the Remote Access Server Setup wizard, you configure the transform set that will be used to protect the traffic on this network. A transform set is a combination of security protocols, algorithms, and other settings to apply to IPSec-protected traffic. In this step, you can select from available transform sets or create a new one. For more information on transform sets, see Configuring Transform Sets.
Note
By default, the configured transform set runs in tunnel mode.
Define the following.
GUI Element Action/DescriptionCreate New Transform Set radio button
Select this radio button to create a new transform set. Then, edit the appropriate values.
•
Create New Transform Set field—Enter a name for the transform set.
•
Encryption (ESP)—Select the ESP protocol (DES, 3DES, Null, AES, AES-192, or AES-256) used for encrypting data. Use ESP encryption when ESP authentication is selected.
•
Authentication (ESP)—Select the ESP algorithm (SHA or MD5) used for ensuring data integrity.
Note
Tunnel mode is the default mode for the VPN tunnel. In tunnel mode, both the data sent by VPN clients and the inside IP address of the client are encrypted.
Use Existing Transform Set radio button
Select this radio button to select from available transform sets. Then, click
to open the Transform Set List dialog box. See Transform Set List Dialog Box for more information.
Configuring Group Policies
In Step 4 of the Remote Access Server Setup wizard, you configure the parameters for a new group policy.
Note
This step is optional if a group policy has already been configured for the remote access server and a local database has not been selected for authorization purposes.
Define the following.
GUI Element Action/DescriptionCreate a New Group Policy check box
Select to enable the fields in this page of the wizard.
Group Name field
Enter a name for the new group policy.
Key field
Enter the key used to communicate with the device.
Confirm Key field
Re-enter the key used to communicate with the device.
Create a new pool radio button
Select to create a new IP address pool.
In the IP Address Range fields, enter the IP addresses that begin and end the desired address range.
Select from an existing pool radio button
Select this radio button to select an IP address pool that has already been configured on the device.
See Selecting an IP Pool for more information.
View Group Policies button
Click to launch the List of Group Policies dialog box. See Viewing Group Policy Information for more information.
Selecting an IP Pool
From this dialog box, you can assign an IP pool to a new group policy by selecting one from the list of IP pools that have already been configured on the device.
Step 1
In Step 4 of the Remote Access Server Setup wizard, select the Select from an existing pool radio button.
Step 2
Click
to launch the Select an IP Pool dialog box.
Step 3
Select an IP pool and click OK.
Viewing Group Policy Information
From the List of Group Policies dialog box, you can view detailed information about the group policies that have already been configured on the device. The following information is provided.
Configuring RADIUS Servers
In Step 5 of the Remote Access Server Setup wizard, you configure the parameters for a new Remote Authentication Dial-In User Service (RADIUS) server. This server handles authentication, authorization, and accounting (AAA) for remote users who want to access the module.
Note
This step is optional if either a RADIUS server has already been configured or a RADIUS server is not used for AAA.
Define the following.
GUI Element Action/DescriptionCreate a new RADIUS Server check box
Select to enable the fields in this page of the wizard.
IP Address field
Enter the IP address of the RADIUS server.
Type field
Indicates that you are configuring a RADIUS server. This field cannot be edited.
Key field
Enter the key used to communicate with the server.
Confirm Key field
Re-enter the key used to communicate with the server.
Accounting Port field
Enter the server port used for accounting requests.
The default is 1646.
Authentication Port field
Enter the server port used for authentication requests.
The default is 1645.
Timeout (sec) field
Enter the number of seconds that the router should attempt to contact this server before going on to another server.
The default is 5 seconds.
View RADIUS Servers button
Click to launch the List of Servers dialog box. See Viewing RADIUS Server Information for more information.
Viewing RADIUS Server Information
From the List of Servers dialog box, you can view detail information for the RADIUS servers that have already been configured on the device. The following information is provided.
Configuring Group Policy Lookup
In Step 6 of the Remote Access Server Setup wizard, you select one of the methods described in the following table for the lookup of group policies.
Configuring Extended Authentication
In Step 7 of the Remote Access Server Setup wizard, you select one of the Extended Authentication (Xauth) methods described in the following table.
GUI Element Action/DescriptionUse RADIUS and local database for Xauth radio button
Select to first look into the RADIUS server and then the local database for group authentication.
Use local database for Xauth radio button
Select to look into the local database for group authentication.
Use existing list, whose methods will be used for Xauth radio button
Select to use an existing list for group authentication.
1.
Click
to launch the Select an Authentication List dialog box.
2.
Select a list and then click OK.
Configure Xauth User button
Click to launch the Add Xauth User dialog box.
See Adding an Xauth User for more information.
Adding an Xauth User
In this dialog box, you can configure the parameters for a new Extended Authentication (Xauth) user.
Step 1
In Step 7 of the Remote Access Server Setup wizard, click Configure Xauth User.
Step 2
Define the following:
Step 3
Click OK.
Configuring Accounting Information
In Step 8 of the Remote Access Server Setup wizard, you select one of the methods described in the following table for the accounting of network-related service requests.
Remote Access Server Wizard Summary
The summary page of the wizard shows you the information that you entered.
Click Finish to send the commands to the device. The Deliver Configuration to Switch/Module(s) dialog box appears if you have configured CVDM-VPNSM to display the accumulated CLI commands after you have completed a wizard (for information on configuring this option, see Editing Preferences).
For more information on the Deliver Configuration to Switch/Module(s) dialog box, see Delivering CLI Commands to the Device.



and do one of the following:
to open the Select Routed Ports dialog box. For more information, see