Manuel d'utilisation / d'entretien du produit VPN 3002 du fabricant Cisco
Aller à la page of 282
Corporate He adquarters Cisco System s, Inc . 170 West Ta sman Drive San Jos e, CA 95134 -1706 USA http://www.ci sco.com Tel: 408 526-4000 800 553- NETS (638 7) Fax: 408 526-4100 VPN 3 0 02 Hardware Clien t Reference R ele ase 3 .
THE SPECIFICATIONS AND INFORMATION REG ARDING THE PRODUCT S IN THIS MANUAL ARE SUBJECT TO CHANGE WITHOU T NOTICE. ALL STATEMENTS , INFORMATION, AND RECOMM ENDATIONS IN THIS MANUA L ARE BELIEVED TO BE ACCURATE BUT ARE PRESENTED WITHOUT WARRANT Y OF ANY KIND, EXPRESS OR IMPLIED.
iii VPN 3000 Serie s Concentrato r Reference V olume I: Configu ration 78-13782-01 CONTEN TS Preface ix Prereq uisites ix Organi zation ix Relat ed Do cume ntatio n xi Document ation conven tions xii .
Cont ents iv VPN 3000 Seri es Concentrato r Reference V olume I: Configu ration 78-13782-01 Servers 5-1 Config uration | Syste m | Serve rs 5-1 Config uration | Syste m | Serve r s | DNS 5-1 Tunneling.
Content s v VPN 3000 Serie s Concentrator Referenc e Volume I: Conf igurati on 78-13782-01 Config uration | Syste m | Event s | Classes | Add or Modify 9-10 Config uration | Sys te m | Event s | Trap .
Cont ents vi VPN 3000 Seri es Concentrato r Reference V olume I: Configu ration 78-13782-01 Adminis t rat io n | Certificat e Management | Enroll | Cert if icat e T ype | PKCS10 12-39 Adminis tratio n.
Content s vii VPN 3000 Serie s Concentrator Referenc e Volume I: Conf igurati on 78-13782-01 Monitor ing | Stat istic s | PPPoE 13-36 Monito ring | Statis tics | MIB-II 13 -39 Monito ring | Statis tic.
Cont ents viii VPN 3000 Seri es Concentrato r Reference V olume I: Configu ration 78-13782-01.
ix VPN 3002 Hard ware Clie nt Refe rence OL-1893-01 Preface The VPN 300 2 H ardwar e Clie nt Re ference pr ovide s gui del ine s f or co nfi guri ng the Ci sco VPN 30 02, details on all the func tions availab le in the VPN 3002 Hardware Client Man ager , and instructions for using th e V PN 3 002 Co mm and L i ne I nter fac e.
x VPN 3002 Hardwar e Client Referenc e OL-1893-01 Preface Organization Chap ter 5 Servers Explains how t o con fig ure the V PN 3 002 to communica te with DNS servers to convert hostnames to IP addr es ses. Chap ter 6 Tu n n e l in g Explain s how to conf igure I PSec.
xi VPN 3002 Hardware C lient Referen ce OL-1893-01 Pre face Related Docu mentat ion Related Documentation Refer to t he follow ing doc uments for fu rther inf ormati on about Cisco VPN 3000 Seri es appl ications an d products .
xii VPN 3002 Hardwar e Client Referenc e OL-1893-01 Preface Docum ent ation con ve ntions version s on the Cisco w eb site, cl ick the Suppor t icon on t he toolbar a t the top of the VPN Co ncentra tor Manager, Hardware Client Manager, or Client window .
xiii VPN 3002 Hardware C lient Referen ce OL-1893-01 Pre face Obtaining Docu mentation Data Formats As you configure and manage the system, enter data in the following formats unless the instruct io ns indi cate ot herwise: Obtaining Documentation The follow ing sec tions provi de sources fo r obtaining doc umen tation from Ci sco System s.
xiv VPN 3002 Hardwar e Client Referenc e OL-1893-01 Preface Obtain in g technica l assistan ce Ordering docu mentation Cisco do cumentati on is availab le in the follow ing ways: • Register ed Cisco D irect C ustom ers c an o rde r Ci sco Pr odu ct doc umen tat ion from t he N etwo rking Products Ma rketPlace : http://www .
xv VPN 3002 Hardware C lient Referen ce OL-1893-01 Pre face Obtaining technical assistance Customers a nd partn ers can self-reg ister on Cisco.com to obt ain addit ional pers onalized i nforma tion and services.
xvi VPN 3002 Hardwar e Client Referenc e OL-1893-01 Preface Obtain in g technica l assistan ce.
C HAPTER 1-1 VPN 3002 Hard ware Clie nt Refe rence OL-1893-01 1 Using the VPN 3002 Hardwa re Client Manager The VPN 3002 Har dware Client Manager is an HTML-based int erface that lets you config ure, admini ste r , monit or, and manage the VPN 3002 w it h a sta nd ard w eb bro ws er .
1-2 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapt er 1 Using the V PN 3002 Hardware Client Ma nager Connecting t o the VPN 3002 Us ing HTT P Java Sc ript and C o okies Be sure Java Script and Cookies a re enabl ed in the b rowser . Refer t o the docu mentatio n for y our browser for in struct ions.
1-3 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 1 Using th e VPN 3 00 2 H ard ware Client M ana ger Installing the SSL Certificate in Your Browser Figur e 1 -1 VPN 3002 Hardw are Client Ma nage r Login Sc r een T o contin ue usin g H TTP for the wh ole sessi on, sk ip to “ L ogging i nto the VP N 3002 Hardw are Clien t Manager .
1-4 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapt er 1 Using the V PN 3002 Hardware Client Ma nager Installing the SSL Certificat e in Your Brows er Follow these steps to inst all and use the SSL certificat e for the first time. W e provide separate instru cti ons fo r Int erne t Exp lo rer an d N et sca pe Navi ga tor wh en th ey div erge.
1-5 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 1 Using th e VPN 3 00 2 H ard ware Client M ana ger Installing the SSL Certificate in Your Browser Figur e 1 -3 Inter net Explor er File Do wnload Dialog Box 3. Click the Open this file from its curr ent locat ion ra dio but ton, then cl ick OK .
1-6 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapt er 1 Using the V PN 3002 Hardware Client Ma nager Installing the SSL Certificat e in Your Brows er Figur e 1 -5 Inter net Explor er Certifi c at e Manag er Impor t Wizard Dialog Bo x 5. Click Next to cont inue.
1-7 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 1 Using th e VPN 3 00 2 H ard ware Client M ana ger Installing the SSL Certificate in Your Browser Figur e 1 -7 Inter net Explor er Certifi c at e Manag er Impor t Wizard Dialog Bo x 7. Click Fi nish .
1-8 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapt er 1 Using the V PN 3002 Hardware Client Ma nager Installing the SSL Certificat e in Your Brows er Figur e 1 -1 0 Int er net Explore r Secur ity Alert Dialog Bo x 11. Click OK . The VPN 300 2 Hardw are Client displa ys the HTT PS version of the Manager log in screen.
1-9 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 1 Using th e VPN 3 00 2 H ard ware Client M ana ger Installing the SSL Certificate in Your Browser Figur e 1-1 2 Int er net Explor er 4.0 Cer tifica te P ro pert ies Scr een Click any of the Field items to see Det ails.
1-10 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapt er 1 Using the V PN 3002 Hardware Client Ma nager Installing the SSL Certificat e in Your Brows er Reinstallation Y ou need to inst all the SSL certifica te from a given VPN 3002 only once . If you try to reinstall it, Net scape displays the note in Fi gure 1-14 .
1-11 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 1 Using th e VPN 3 00 2 H ard ware Client M ana ger Installing the SSL Certificate in Your Browser Figur e 1 -16 Netsca pe New Cer tificate A uthorit y Scr een 2 2. Click Next> to proc eed.
1-12 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapt er 1 Using the V PN 3002 Hardware Client Ma nager Installing the SSL Certificat e in Your Brows er Figur e 1 -18 Netsca pe New Cer tificate A uthorit y Scr een 4 4. Y ou mus t check at leas t the first bo x, Accept t his Cert ificate A uthority for Cert ifying network sites .
1-13 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 1 Using th e VPN 3 00 2 H ard ware Client M ana ger Installing the SSL Certificate in Your Browser Figur e 1 -20 Netsca pe New Cer tificate A uthorit y Scr een 6 6. In the Nickname field, enter a descript ive name for this certifica te.
1-14 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapt er 1 Using the V PN 3002 Hardware Client Ma nager Installing the SSL Certificat e in Your Brows er Figur e 1 -22 VPN 3002 Hardw are Cli ent M.
1-15 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 1 Using th e VPN 3 00 2 H ard ware Client M ana ger Installing the SSL Certificate in Your Browser Figur e 1 -23 Netscape Se cur ity Info Wi ndo w Click V iew Certif icate t o see details of the specific certi f icate in use.
1-16 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapt er 1 Using the V PN 3002 Hardware Client Ma nager Connecting t o the VPN 3002 Us ing HTT PS Figur e 1 -25 Netsca pe Cert ificat es Signer s List Select a cert ificate, then click Edit, V erify , or Delete .
1-17 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 1 Using th e VPN 3 00 2 H ard ware Client M ana ger Logging in to the VPN 3002 Hardware Client Ma nager Figur e 1 -26 VPN Hardw are Clie nt.
1-18 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapt er 1 Using the V PN 3002 Hardware Client Ma nager Logging into the VPN 300 2 Hardw are Client M anage r Figur e 1 -27 Manag er Main W elcome Scr een From here yo u can nav igate the Mana ger using either the table of cont ents in th e left frame, or t he Manage r toolb ar in the top fr ame.
1-19 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 1 Using th e VPN 3 00 2 H ard ware Client M ana ger Interactive Hardware Client and Individual User Authentication Interactive Hardware Cli.
1-20 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapt er 1 Using the V PN 3002 Hardware Client Ma nager Logging In Wi th Int era ctive Hardw are Client and Individual Us er Authen ticat ion Figur e 1 -28 VPN 3002 Hardw are Cli ent Manag er Login Scr een Step 1 Click the Connection Login Status butt on.
1-21 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 1 Using th e VPN 3 00 2 H ard ware Client M ana ger Logging In With Interactive Hardware Client and Individual User Authentication Figu re 1 - 30 VP N 30 02 In teractive A uth entic atio n Screen Step 1 Enter the u ser na me a nd passw ord f or the VP N 3 002 .
1-22 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapt er 1 Using the V PN 3002 Hardware Client Ma nager Logging In Wi th Int era ctive Hardw are Client and Individual Us er Authen ticat ion Figur e 1 -32 Individual User A uthentication Scr een Step 1 Enter the us erna me and pa sswor d f or t his VPN 3002 u s er .
1-23 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 1 Using th e VPN 3 00 2 H ard ware Client M ana ger Understan ding the VPN 3002 Har dware Clien t Manager Wi ndow Understandin g the VPN 30.
1-24 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapt er 1 Using the V PN 3002 Hardware Client Ma nager Unders tanding th e VPN 3 002 Hardw are Client Manager Window Titl e ba r The title b ar at th e t op o f the bro wser window i nc lude s the VPN 30 02 device na me o r I P a ddre ss in br ac ket s, for e xa mpl e, [ 10.
1-25 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 1 Using th e VPN 3 00 2 H ard ware Client M ana ger Understan ding the VPN 3002 Har dware Clien t Manager Wi ndow Save Click the Save icon to save the active configurat io n and make it the boot configura tion.
1-26 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapt er 1 Using the V PN 3002 Hardware Client Ma nager Unders tanding th e VPN 3 002 Hardw are Client Manager Window Open or expanded Click th e open/exp ande d icon to close subordinat e sections an d titles.
1-27 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 1 Using th e VPN 3 00 2 H ard ware Client M ana ger Organiz ation of the VPN 3002 Hardware Client Ma nager Organization of the VPN 3002 Har.
1-28 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapt er 1 Using the V PN 3002 Hardware Client Ma nager Naviga ting the VPN 3002 Hardw are Client Manage r Navigating the VPN 3002 Hardware Client Man ager Y our prima ry tool fo r naviga ting the V PN 3002 H ardware C lient Man ager is th e table of contents in the left f rame.
C HAPTER 2-1 VPN 3002 Hard ware Clie nt Refe rence OL-1893-01 2 Configuration Configuring th e VPN 3 002 means settin g all the p arameters tha t govern its u se and f unctionality a s a VPN devic e.
2-2 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Cha p ter 2 Co nf i gur at i on Configur ation.
C HAPTER 3-1 VPN 3002 Hard ware Clie nt Refe rence OL-1893-01 3 Interfaces This sec tion of th e VPN 3002 Hardware Client Manag er applies f unctions that are inte rface-spec ific, rather than s ystem-wi d e. Y ou confi gure two ne twork interfa ces for th e VPN 3002 to oper ate as a VPN device: the priv ate inter face and the public interface.
3-2 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 3 Interface s Configur ation | Interfaces Figu re 3-1 VP N 30 02 Con fig uration | Inter faces S creen T o configur e a module , either clic.
3-3 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 3 Interface s Configuration | Interfaces Status The oper ational statu s of this interface: • UP (green) = Configured , enabled, and operat ional; rea dy to pass d ata t raf fic. • DOWN (red) Configu red but disab led or discon necte d.
3-4 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 3 Interface s Configur ation | Interfaces | Pri va te Configuration | In terfaces | Priva te This screen lets y ou c o nfigur e par am ete rs fo r the p r ivate i n terfac e. It disp lay s th e c urr en t para meter s , if any .
3-5 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 3 Interface s Configuration | Interfaces | Private Subnet Mask Enter the subnet mask for th is inter face, using d otted de cimal no tation (fo r example 255.2 55.255.0) . The Manager automatic ally supplies a stan dar d subnet mask appropr iate for the IP address you just enter ed.
3-6 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 3 Interface s Configur ation | Interfaces | Pub lic Configuration | In terfaces | Public This scre en lets you select a conne ction me thod — DHCP , PPPoE, or static IP addressing — for the pu blic interfac e.
3-7 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 3 Interface s Confi guratio n | Interf aces | Public PPPoE User Name If you have selecte d PPPoE, enter a v alid PPPoE username. PPPoE Password If you have selecte d PPPoE, enter the PPPoE password for the username you enter ed above.
3-8 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 3 Interface s Configur ation | Interfaces | Pub lic Duplex If you ar e using sta tic IP addr es sin g, c lick t he dr op- down me nu but ton.
C HAPTER 4-1 VPN 3002 Hard ware Clie nt Refe rence OL-1893-01 4 System Configuration System co nfigurat ion mean s configur ing parame ters for syste m-wide functions in the VPN 3002.
4-2 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 4 System Configuration Configur ation | System.
C HAPTER 5-1 VPN 3002 Hard ware Clie nt Refe rence OL-1893-01 5 Servers Configuring server s means identifying DNS serv ers to the VPN 3002 so it can communi cate with them correc tly . DNS ser vers con vert host names to I P addresse s. The V P N 3002 f unc tions as a client o f these servers.
5-2 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 5 Se rv e rs Configur ation | Syst em | Se rvers | DN S Figur e 5-2 Con figur ation | S ystem | Serv ers | DNS Scr een Enabled T o use D NS f unct ions, check Enabled (the defa ult ). T o disa ble DN S, cle ar the box.
5-3 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 5 Servers Confi guratio n | System | Servers | DNS Timeout Period Enter the initial time in seconds to wait for a response to a DNS query before sendi ng the query to the next serve r . Minimum is 1, de fault is 2, maxi mum is 3 0 seconds.
5-4 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 5 Se rv e rs Configur ation | Syst em | Se rvers | DN S.
C HAPTER 6-1 VPN 3002 Hard ware Clie nt Refe rence OL-1893-01 6 Tunneling T unnel ing is t he h eart of virt u al pri vat e ne twork in g. Tunnels make it p ossibl e t o use a p ubl ic T CP/IP networ k, such as the Internet , to crea te secure con nections between re mote use rs and a priv ate corpor ate network.
6-2 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 6 Tunneling Configur ation | System | Tunn eling Protocol s Configuration | System | Tunne ling Protocol s This section let s you configure the IPSec tunn eling protocol. Click IPSec on the Tunneling Protoco ls screen .
6-3 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 6 Tunnel ing Config uration | Syste m | Tunnel ing Pr otocols | IPS ec – DES-56 – 3DES-168 • Extended Auth entication (XAu th) • Mod.
6-4 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 6 Tunneling Configur ation | System | Tunn eling Protocol s | IPSe c Note If you a re using host names, it is w ise to have ba ckup DNS an d WINS serve rs on a separa te networ k from tha t of the prima ry DN S an d WINS se rve rs.
6-5 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 6 Tunnel ing Config uration | Syste m | Tunnel ing Pr otocols | IPS ec The VPN 3 002 in Farg o first tries to reach Sa n Jose. If the initial I KE packet for th at connection (1) t imes out (8 seconds), it tri es to connect to Austin (2).
6-6 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 6 Tunneling Configur ation | System | Tunn eling Protocol s | IPSe c About IPSec over T CP IPSec over TCP en capsulate s encrypted data traf fic within TCP pack ets.
6-7 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 6 Tunnel ing Config uration | Syste m | Tunnel ing Pr otocols | IPS ec Password In the Group Pa ssword field, e nter a unique password for this group. Th is is the gro up password config ured on t he VPN Concentra tor t o w hich thi s VPN 300 2 conn ec ts.
6-8 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 6 Tunneling Configur ation | System | Tunn eling Protocol s | IPSe c.
C HAPTER 7-1 VPN 3002 Hard ware Clie nt Refe rence OL-1893-01 7 IP Routing The V PN 300 2 inclu des a n I P r outi ng subs yste m wi th stat ic rout ing , d efau lt gat ewa ys, a nd DH CP . T o route packets , the subs ystem uses static ro utes and th e default gateway .
7-2 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 7 IP Routing Configurati on | System | IP Routin g | Stat ic Routes Configuration | System | IP Ro uting | Static Routes This se cti on of t he Ma nage r lets you c onf igur e stati c ro ut es fo r IP rou tin g.
7-3 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 7 IP Routing Configuration | System | IP Routing | Static Routes | Add or M odify Configuration | System | IP Ro uting | Static Routes | Add or Mo dify These Ma nager scr eens let you : • Add : Configure and add a new static, or manual, rout e to the IP rout ing table.
7-4 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 7 IP Routing Configur ati on | System | IP Routin g | Default Gat ew ay s Destination Click a ra dio butt on to select the outb ound des tination fo r these pack ets. Y ou can select on ly one destinatio n: either a specific r outer/g ateway , or a VPN 3 002 interfac e.
7-5 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 7 IP Routing Configuration | System | IP Routing | Default Gateways Default Gateway Enter the IP addr es s of the defa ult gat ewa y or ro uter. Use dot ted deci mal not at ion; for e xampl e, 192.
7-6 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 7 IP Routing Configur ati on | System | IP Routin g | DHCP Configuration | System | IP Routing | DHCP This sc reen le ts you con figu re D HC P (D ynami c H os t Con figu ratio n Pr otoc ol) serve r para met ers t hat apply to DHCP serve r functions within th e VPN 3002.
7-7 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 7 IP Routing Config uratio n | System | IP Routi ng | DHCP Opti ons Apply/Ca ncel T o apply the set tings for DHCP para meters, and to in clude your setting s in the active c onfiguration, cli ck Apply .
7-8 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 7 IP Routing Configur ati on | System | IP Routin g | DHCP Options | Add or Modif y T o remove a co nfigure d DHCP op tion, se lect the option fro m the list a nd click Delete . Ther e is no confir m ation or undo.
7-9 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 7 IP Routing Configuration | System | IP Routing | DHCP Options | Add or M odify Nonconfigurable DHCP Options Y ou cannot conf igure the fo .
7-10 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 7 IP Routing Configur ati on | System | IP Routin g | DHCP Options | Add or Modif y.
C HAPTER 8-1 VPN 3002 Hard ware Clie nt Refe rence OL-1893-01 8 Management Protocols The VPN 3 002 Hardware Client incl udes various b uilt-in server s, using v arious proto cols, that let you perform typical network and syste m manage ment fun ctions.
8-2 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapt er 8 Managemen t Protocol s Configurati on | System | Mana gem e nt Protocols | HTTP/HTTPS Configuration | System | Manage ment Protocols | HT.
8-3 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 8 Manage ment Protoco ls Config uratio n | System | Management Prot ocols | HTT P/HTTPS Enable HTT PS Check the bo x to enab le the HTTPS se rver . The box is ch ecked by d efault. HT TPS, also know n as HTTP over SSL, le ts y ou use the Ma nage r over an enc ry pted conn ec ti on.
8-4 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapt er 8 Managemen t Protocol s Configur ati on | System | Mana gement Proto col s | Telnet Figur e 8-3 Con figur ation | S ystem | Manag ement Pr.
8-5 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 8 Manage ment Protoco ls Confi guration | Syste m | Manageme nt Protoco ls | Tel net Enable Te lnet/SSL Check t h e box to ena ble T elnet over SSL. Th e box is checke d by de fault . T elnet/SSL uses T elnet over a secu re, encry pted conn ection.
8-6 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapt er 8 Managemen t Protocol s Configur ation | System | Mana gement Proto col s | SNMP Configuration | System | Manage ment Protoc ols | SNMP This sc reen l et s yo u con fig ure and e nabl e t he SN MP (Sim ple N etwor k Mana geme nt Protoc ol) a gent .
8-7 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 8 Manage ment Protoco ls Configuration | System | Manageme nt Protoco ls | SNM P C ommunities Reminder: T o save the active configuration and make it the boot configura tion, click the Save Needed icon at th e top of the Manage r window .
8-8 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapt er 8 Managemen t Protocol s Configur ation | System | Mana gement Proto col s | SNMP Commu nities Community Strings The Commu nity Strings list shows SNMP commu nity stri ngs that have been co nfigure d.
8-9 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 8 Manage ment Protoco ls Configuration | System | Manageme nt Protoco ls | SNM P C ommunities Figur e 8-1 0 Configur ation | Sys tem | Ma nag ement Pr otocols | SN MP Communitie s | Add Screen Community String Enter th e SNMP commu nity str ing.
8-10 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapt er 8 Managemen t Protocol s Configurati on | System | Mana gem e nt Protocols | SSL Configuration | System | Manage ment Protoc ols | SSL This scr een lets you c onfigure t he VPN 3002 SSL (Secure Sock ets Layer ) protocol se rver .
8-11 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 8 Manage ment Protoco ls Configur ation | System | Ma nagement Protocol s | SSL Figur e 8-12 Configur ation | Sys tem | Ma nagement Pr otoc.
8-12 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapt er 8 Managemen t Protocol s Configurati on | System | Mana gem e nt Protocols | SSL SSL Vers ion Click the d rop-do wn m en u but ton and sel ec t the SSL ve rs ion to use .
8-13 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 8 Manage ment Protoco ls Confi guratio n | Syst em | Managem ent Pr otocols | S SH Figur e 8-13 Configur ation | Sys tem | Manag ement Pr o.
8-14 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapt er 8 Managemen t Protocol s Configurati on | System | Mana gem e nt Protocols | SSH Enable SS H Check th e box to enab le the SSH server . T he box is ch ecked by de fault . Disabli ng the SSH server provi des addit ional securit y by preven ting SSH access .
8-15 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 8 Manage ment Protoco ls Confi guratio n | Syst em | Managem ent Pr otocols | S SH Apply / C ancel T o appl y your SSH settings, and to inclu de your settings in the active conf iguration, click Apply .
8-16 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapt er 8 Managemen t Protocol s Configur ation | System | Mana gement Proto col s | XML Configuration | System | Manage ment Protoc ols | XML This scree n lets you configure the VPN 300 2to support an XML-ba sed interface.
8-17 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 8 Manage ment Protoco ls Confi gurati on | System | Manageme nt Protoco ls | XML HTTPS IP Address Enter t he I P a ddres s fr om whi ch to a llow HTT PS ac cess on the VPN 30 02 pub lic in terfa ce.
8-18 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapt er 8 Managemen t Protocol s Configur ation | System | Mana gement Proto col s | XML.
C HAPTER 9-1 VPN 3002 Hard ware Clie nt Refe rence OL-1893-01 9 Events An event is any sig nifican t occurr ence within or af fecting t he VPN 300 2 such as an alarm, trap, error conditi on, netw ork proble m, task c ompleti on, thresh old breac h, or stat us chan ge.
9-2 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 9 Even ts Event Class EVENTM IB Event MIB changes* FSM Finite St ate Ma ch ine sub system ( for d eb uggin g)* F TPD F TP da emon su bsyst em GENERA L NTP sub system and oth er ge nera l e vents HARDW AREMON Hardware mo nitori ng (fans, tempe rature , voltages, etc .
9-3 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 9 Events Event Seve rity Level Note Th e Cisco-sp ecific event clas ses provide informa tion that is me aningful only to Cisco e ngineeri ng or suppor t perso nne l.
9-4 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 9 Even ts Event Log Event Log The VPN 3002 records events in an event log, which is stored in nonvo latile memory .
9-5 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 9 Events Configuration | System | Events Configuration | System | Events This sect ion of the Ma nager l ets you conf igure how the VPN 30 02 handle s events. Events provide inform ation fo r system moni toring, auditing , manage ment, ac count ing, and trou blesh ooting.
9-6 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 9 Even ts Configur ati on | System | Even ts | G ene ral Syslog Fo rmat Click the Sy slog Form at dro p-dow n menu bu tto n and c hoose th e f orm at for a ll eve nts se nt to U NIX syslog serv ers.
9-7 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 9 Events Config uratio n | Syst em | Event s | General The Origin al severitie s and the Cisco IOS sever ities dif fer . Orig inal severitie s number f rom 1-13. (Fo r the meaning o f each Original sev erity , see T ab le 9-2 on page 9-3 .
9-8 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 9 Even ts Configur ati on | System | Even ts | Classes Severity to Trap Click the drop-d own menu button and select the ran ge of event severity levels to send to an SNMP network manageme nt system (NMS) by default.
9-9 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 9 Events Confi gurati on | System | Events | Cla sses Figur e 9-3 Con figuration | S ystem | Eve nts | Classe s Scr een T o configu re defaul t event handli ng, click t he highlight ed link tha t says “ Click her e to configur e gen eral event paramete rs .
9-10 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 9 Even ts Configur ati on | System | E ven ts | Classe s | Add or Modify Configuration | System | Events | Classes | Add or Modify These scr eens let you: Add: Configure and add the spe cial handling of a specif ic event class.
9-11 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 9 Events Config uratio n | System | Events | Classes | Add or Modify Severity to Console Click th e drop-dow n menu bu tton and se lect the ra nge of ev ent severi ty leve ls to display on the con sole.
9-12 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 9 Even ts Configur ati on | System | Even ts | Trap Desti nat ions Configuration | System | Events | T rap Destinations This sectio n of t he Mana ge r lets you con figur e SNM P networ k ma nage ment system s as de stina tio ns of even t tra ps.
9-13 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 9 Events Config uratio n | System | E vents | T rap Destin ations | Add or Modify T o remove an SN MP tra p dest inati on tha t ha s been c onfi gur ed, sel ect th e dest ina tion from t he list an d click Delet e .
9-14 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 9 Even ts Configur ati on | System | Even ts | Sysl og Servers Port Enter the UD P p ort num ber by w hich you ac cess t he de sti natio n SNM P se rv er . U se a d eci mal numb er from 0 to 6553 5.
9-15 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 9 Events Config uratio n | Syst em | Event s | Syslog Serv ers Syslog Se rvers The Sysl og Servers list s ho ws th e UNI X sy s lo g se rv er s that h a ve been config u red a s re cip ien ts of ev en t messages.
9-16 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 9 Even ts Configur ati on | System | Even ts | Sy sl og Servers | A dd or M odify Configuration | System | Events | Syslog Servers | Add or Modify These Ma nager scr eens let you : Add : Conf ig ur e an d ad d a UNIX sys lo g ser ve r as a rec ipi ent of event messa ge s.
9-17 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 9 Events Con f igur atio n | S yst em | E vent s | Sysl og S er vers | Add or M od ify Add or Apply/C ancel T o add this server to the list o f syslog server s, click Add . O r to ap ply your changes to thi s syslog se rver, click Apply .
9-18 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 9 Even ts Configur ati on | System | Even ts | Sy sl og Servers | A dd or M odify.
C HAPTER 10-1 VPN 3002 Hard ware Clie nt Refe rence OL-1893-01 10 General General config uration paramet ers include VPN 3002 environ ment items: system identifica tion, time, and date . Configuration | System | General This secti on of the Ma nager l ets you conf igure gene ral VPN 3002 parame ters.
10-2 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapt er 10 General Configur ati on | System | Gen eral | Identificat io n Configuration | System | General | Identification This scree n lets y ou configure system identif ication p arameters t hat are stor ed in the standard MIB-II system obje ct.
10-3 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 10 General Configur ation | System | General | Time and Date Configuration | System | General | Time and Dat e This screen lets you set the time and date on the VPN 3002. Setting the correct tim e is very important so th at l ogg ing inf orm at ion is acc ur ate .
10-4 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapt er 10 General Configur ati on | System | Gen eral | Time and Dat e Reminder: T o save the active configuration and make it the boot configura tion, click the Save Need ed icon at the top of the Manage r window .
C HAPTER 11-1 VPN 3002 Hard ware Clie nt Refe rence OL-1893-01 11 Policy Management The VPN 300 2 works in eit her of two mode s: Client mode or Networ k Extensi on mode. Policy ma nage ment o n the VPN 30 02 includ es deci din g w het her y ou wa nt t he V PN 3002 t o use Cl ie nt Mode o r Ne tw ork E xten si on mod e.
11-2 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapt er 11 Policy Mana gement Netwo rk Extensi on M ode The net work and ad dresses on th e privat e side of the V PN 3002 ar e hidden , and ca nnot be acce ssed direct ly .
11-3 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 11 Policy Mana gem e nt Networ k Extensi on Mode Network Extension Mode with Split Tunneling Y ou alwa ys assi g n the VPN 30 02 to a clie nt gr oup on the cen tral- site VPN Co ncen tr ato r .
11-4 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapt er 11 Policy Mana gement Netwo rk Extensi on M ode Tunnel Initiation The VPN 3 002 always initiat es the tun nel to th e central-site VPN Concentrator . The central- site VPN Concent rator cannot ini tiate a tunn el to a VPN 3002 .
11-5 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 11 Policy Mana gem e nt Config uration | Po licy Manag ement T able 1 1 -1 D ata Initiation: VPN 3002 and Centr al-Site VPN Conce ntrat or Configuration | Policy Managemen t The Con fi gura tion | Polic y Ma na geme nt s cr een int roduc es thi s sec tio n o f th e Man ager .
11-6 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapt er 11 Policy Mana gement Configur ati on | Policy Manag ement | Traffi c M anageme nt | PAT PAT T o configure P A T (Por t Address T ransl ation) cli ck PAT .
11-7 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 11 Policy Mana gem e nt Confi gurati on | Poli cy Manage ment | Traf fic Man agement | PAT | Ena ble PAT Enable d Check the box to ena ble Client Mode (P A T), or clear it to enable Netwo rk Extensio n Mode.
11-8 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapt er 11 Policy Mana gement Configur ati on | Policy Manag ement | Traffi c M anageme nt | PAT | Enable.
C HAPTER 12-1 VPN 3002 Hard ware Clie nt Refe rence OL-1893-01 12 Administration Admin istering th e V PN 3002 inv ol ves a ctiv itie s tha t k eep t he syst em op erat iona l a nd se cu re.
12-2 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Admini st ration | Soft wa re Update Figur e 12-1 A dmin istr ation Scre en Administration | Software Update This sect ion of the Ma nager l ets you upda te the VP N 3002 exec utable syst em softwa re.
12-3 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Administration | Software Update Figur e 12-2 A dministr ation | Softw are Updat e Scr een Current So ftware Re vision The n ame, ver sion numbe r , and date of the softwa re imag e curr ently ru nning o n the system.
12-4 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Admini st ration | Soft wa re Update Software Update Prog ress This windo w shows th e pr ogres s of t he so ftw are up load . It re fr esh es the num be r of by tes tra nsf erre d at 10-second intervals.
12-5 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Admi ni s trati on | S ystem Rebo o t Figur e 12-5 A dministr ation | Softw are U pdate E r r or Scr een Administration | System Re boot This scre en lets you re boot or shut down (halt ) the VPN 30 02 with variou s options.
12-6 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Admini st ration | Syst em Reb oot Figur e 12-6 A dmin istr ation | Syst em Reboo t Scr e en Action Click a r adio but ton to selec t t he de sired a c tion. Y o u ca n sele ct only on e act ion.
12-7 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Administr ation | Pi ng • Reboot ignoring the Configuration file = Rebo ot using all the factory defa ults; that is, start the system as if it had no CONFIG file.
12-8 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Admini st ration | Ping Addres s/Hostn ame to Pin g Enter the IP addr es s or h ostna me o f the syste m you wa nt to t est. (If you co nfi gured a DN S se r ver, you can ente r a hostna me; othe rwise, en ter an IP add ress.
12-9 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Administr a tion | Access Rights Administration | Access Rights This se cti on of t he Ma nage r lets you c onfi gur e an d c on trol ad mi nistra ti ve acc ess t o t he V PN 30 02.
12-10 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Administrati on | Access Right s | Administrato rs Administrator The VP N 3002 has three prede fined ad ministra tors: • admin = System administrator with access to, and rights to change, all areas.
12-11 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Administratio n | Access Rights | Access Setti ngs Administration | Access Rights | Access Settings This screen lets you co nfigure general optio ns for administrator access to the Manager .
12-12 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Admini stration | F il e Ma nagemen t Administration | File Management This sect ion of the M anager lets you manage files in VPN 300 2 Flash mem ory . (Flash mem ory acts like a disk.
12-13 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Administ ration | File Man agement | Swap Conf ig Files Swap Config Files Swap Confi g Files lets you swap the boot co nfigura tion fil e with the backu p configu ratio n file.
12-14 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Admini st ration | File Ma nagemen t | Conf ig File Upload Administration | File Management | Config File Upload This sc.
12-15 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Administration | File Management | Config File Upload Figur e 12-16 A dministr ation | File Manag ement | File Uploa d Prog ress Windo w When the upl oad is finishe d, or if the uploa d is cance lled, the pr ogress win dow clos es.
12-16 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Certificat e Ma nagemen t Certificate Manag ement Digital certifica tes are a form of digital identific ation used for auth entication.
12-17 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Certificate Management If you have trouble en rolling or installin g digital certif icates via SCEP , enable both the CLIENT an d CER T event classes to a ssist in trou bleshooting .
12-18 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Certificat e Ma nagemen t Step 2 Click Click he re t o install a CA certif icate . Note The Click h er e to install a CA certificate option is o nly av ail ab le f rom th is w indo w wh en n o CA cert ificates a re instal led on th e VPN 300 2.
12-19 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Certificate Management Installing CA Certificates M anually Note If you install a CA certificate using the ma nual method, you cannot use this CA later to request identity or SSL cer tificates with SCEP .
12-20 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Certificat e Ma nagemen t Enrolling and Installing Identity Certificates When you generate a re quest for an identity cer tificate, you need to provide the foll owing informati o n.
12-21 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Certificate Management V erif y Challen ge Passw ord - No Y es Re-enter the ch allenge password. Key Size - Y es Y es The algorithm for generating the p ublic-key /priva te-key pair , and the key siz e.
12-22 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Certificat e Ma nagemen t Enrolling and Installing Id entity Certificates Automaticall y Using SCEP Follow these steps for eac h identity certif icate you want to obtain: Step 1 Displa y the Adminis tration | Certifi cate Management sc reen.
12-23 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Certificate Management Figur e 12-25 A dministr a tion | Certific ate Man a gement | Enr oll | Identity Certific ate | SCE P Scree n Step 5 Fill in the fields and click Enr oll .
12-24 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Certificat e Ma nagemen t Figur e 12-26 A dministr ation | Certific ate Manag ement | Enr ollment | Request G enera ted Scr een Step 6 Click Go to Cert ificate M anage ment .
12-25 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Certificate Management Figur e 12-27 Admin is tr ation | Certific ate Man a g ement | Enr oll | Identity Certificat e | PKCS1 0 Scree n Step 5 Fill in the fields and click Enr oll .
12-26 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Certificat e Ma nagemen t Step 7 Using the e nrollm ent requ est you just gen erate d, retrie ve an ident ity cert ificate from your CA and download it to yo ur PC accord ing to the procedures outlined by the CA.
12-27 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Certificate Management Figur e 12-31 A dministr ation | Certific ate Manag ement | Insta ll | Identity Cer tificate Scr.
Obtaining SSL Certificates If you us e a secure connec tion betwe en your b rowser and t he VPN 3002, th e VPN 300 2 requ ires an SSL certif ica te. Y ou only ne ed o ne SSL cer tifi cate on yo ur VPN 30 02. When you initial ly boot the VPN 3002 , a self-signed SSL cer tificate is au to mati cally generated.
12-29 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Certificate Management Enabling Digital Certificates on the VPN 3002 Note Be fore yo u ena ble d igita l ce rti ficat es on t he VPN 300 2, you m ust o btain a t l east one C A a n d one identity c ertificate.
12-30 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Certificat e Ma nagemen t Deleting Digital Certificates Delete d igital cer tificates i n the following order : 1. Identity or SSL ce rtificate s 2. Subordina te certificates 3.
12-31 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Administration | Certificate Management Administration | Certificate Man agement This section of the Manager shows outstanding enro llment requests and all th e certificate s installed on the VP N 30 02, and it le ts yo u mana ge the m.
12-32 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Admini st ration | Certi fi cat e Managem e nt Certificate Authorities Tabl e This tabl e shows root and subord inate CA c ertifica tes instal led on the V PN 3002.
12-33 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Administration | Certificate Management SSL Certificate Table [ Generate ] This t able show s the SSL se rv er c ert ifica te insta lled on the VP N 30 02.
12-34 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Admini st ration | Certi fi cat e Managem e nt Fields These fie ld s app ear in th e Certific ate Authorit ies, Ident it.
12-35 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Administration | Certificate Management Enrollment S tatus Ta ble This table tracks the status of active en rollment request s . The VPN 3002 sup ports one (inst alled) id entity certifi cate a nd one ( outstan di ng) enr ollment request .
12-36 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Admini st ration | Certi fi cat e Managem e nt Status • In Prog ress = The reques t has been creat ed, bu t the requ este d certi ficate has not yet been installe d. This value is u sed only f or PKCS10 (manual ) enro llmen t requests .
12-37 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Administration | Certificate Management | Enroll Administration | Certificate Man agement | Enro ll Choos e whether you ar e creatin g an enrollme nt reques t for an ident ity certifi cate or an SSL certif icate.
12-38 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Admini st ration | Certi ficat e Manag em e nt | Enroll | Cer tifi cat e Type Administration | Certificate Man agement | Enro ll | Certificate Ty p e Choose the m ethod fo r enrolling the (id entity or SSL ) certific ate.
12-39 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Administration | Certificate Management | Enroll | C ertificate Type | P KCS10 Administration | Certificate Man agement.
12-40 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Admini st ration | Certifi cat e Managem e nt | Enrollmen t or Renewal | Req ues t Gen erat ed Administration | Certific.
12-41 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Administration | Certificate Management | Enroll | Identity Certificate | SCEP Go to Certificate Installation If you want to install the cer tificate you ha ve just enrolled, click Go to Certificate Installation .
12-42 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Administ ration | Certificat e Managem e nt | Enroll | SSL Certificate | SCEP Enroll / Cancel T o gene rate the certifica te request and install the identity certifica te on the VPN 3002, click Enr oll .
12-43 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Administration | Certificate Management | Enroll | SSL Certificate | SCEP Fields For an expla nation of ea ch of the fields on this screen, s ee T able 12- 1 o n pa ge 12 -20 .
12-44 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Admini st ration | Certi fi cat e Managem e nt | Install Administration | Certificate Man agement | Install Choose the type of certific ate you want to install.
12-45 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Administration | Certificate Management | Install | Certificate Obtained via Enrollment Administration | Certificate Man agement | Install | Certi ficate Obtained v ia Enrollment Once you have en rolled a certifica te, you can install it.
12-46 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Admini st ration | Certifi cat e Managem e nt | Install | Certi fi cat e Type Administration | Certificate Man agement | Install | Certi ficate Ty p e Choose the method you want to use to install the certific ate.
12-47 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Administration | Certificate Management | Install | CA Certificate | SCEP Administration | Certificate Man agement | In.
12-48 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Admini st ration | Certifi cat e Managem e nt | Install | Certi fi cat e Type | Cut and Pa ste Text Administration | Cer.
12-49 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Administration | Certificate Management | Install | Certificate Type | Upload File from Workstation Administration | Ce.
12-50 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Admini st ration | Certifi cat e Managem e nt | View Administration | Certificate Man agement | View The Mana ger displa.
12-51 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Administration | Certific ate Management | View Certificate Fields A certific ate contains some or all of the follo wing fields: Field Conte nt Subject The p erson or sys tem tha t uses the certifica te.
12-52 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Admini st ration | Certifi cat e Managem e nt | View Back T o return to the Administr ation | Certif icate Ma nagement scree n, click Ba ck. SHA1 Thumbpr int A 160- bit SHA-1 hash of the complete certifica te con tents, show n as a 20-byt e string.
12-53 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Administration | Certificate Management | Configure CA Certificate Administration | Certificate Man agement | Configure CA Certificate This screen lets you co nfigure this CA certific ate to be able to issue identity cer tificates vi a SCEP .
12-54 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Admini st ration | Certi ficat e Manag em e nt | Renewal Polling Limit Enter the number of times the VPN 3002 sho uld re-send an enr ollment request if th e CA does not issue the ce rtifica te imme diately .
12-55 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Administration | Certificate Management | Renewal Certificate This fi el d displ ays t h e ty pe o f c e rtifi c ate tha t y ou ar e re -e nrol li ng or re -k ey ing.
12-56 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Admini st ration | Certi fi cat e Managem e nt | Activa te or Re-Subm it | Stat us Administration | Certificate Man agement | Activate or Re-Submit | Status This st atus screen appea rs after you act ivate or re-s ubmit an enroll ment reque st.
12-57 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Administration | Certificate Management | Delete Administration | Certificate Man agement | Delete The Man ager display s this conf irmation scr een when y ou click Delete fo r a certific ate on the Administratio n | Certi ficate Manag ement scre en.
12-58 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Admini st ration | Certifi cat e Managem e nt | View En rollment Request Yes / No T o delete this certificate, click Ye s .
12-59 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Administration | Certificate Management | View Enrollment Req uest Enrollment R equest Fie lds An enro llment re quest contain s some or all of th e follow ing fields : Field Conte nt Subject The pers on or syste m that uses the cer tificate.
12-60 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Admini st ration | Certi fi cat e Managem e nt | Cancel Enrollm ent R eque st Back Click Back to display the Administr ation | Certificate Management scree n.
12-61 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 12 Adminis tration Admini stratio n | Certif icate Manageme nt | Delet e Enrollment Request Fields For a descriptio n of t he fields in th is enro llment req uest, see the “ En rollment Request Field s ” section on page 12-5 9 .
12-62 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 12 Administration Admini stration | Cer tificate M anag ement | De lete En rollment Reque st Fields For a descriptio n of t he fields in th is enro llment req uest, see the “ Enrollm ent Re quest Fiel ds ” section on page 12-5 9 .
C HAPTER 13-1 VPN 3002 Hard ware Clie nt Refe rence OL-1893-01 13 Monitoring The VPN 3002 tracks m any stati stics and the status of many items essential to system admin istration and manageme nt. This se ction of the Mana ger lets y ou view a ll those st atus item s and statist ics.
13-2 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 13 Monitorin g Monito rin g | Ro uti ng Table Monitoring | Routing Tab le This screen shows the VPN 3002 rou ting table at the time the scre en displays. Figur e 13-2 Monit or ing | Routing T able Scr een .
13-3 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 13 Monitorin g Monit oring | Fil tera ble Event Log Monitoring | Filterable Event Log This screen shows the events in the current event log, lets you filter and display events by various criter ia, and lets you manage the even t log file .
13-4 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 13 Monitorin g Monito rin g | Filterable Ev en t Log Select Filter Options Y ou can selec t any or all of the following opti ons for filtering and displaying the even t log. After selectin g th e option (s), cl ick a ny one of the fo ur Pa ge bu t tons.
13-5 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 13 Monitorin g Monit oring | Fil tera ble Event Log Event Log Format Each en try (recor d) in the even t log consists o f eight or nin e fields: Sequence Date Time Severity Class/Number Repeat (IPAddress) String (The IP A ddress field only ap pear s in certain ev ents.
13-6 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 13 Monitorin g Monito ring | Live Ev ent Log Monitoring | Live Event Log This scr een shows events in the cur rent event log and au tomatically update s the display ever y 5 seconds. The eve nts might tak e a fe w seconds to load when y ou fir st open the screen.
13-7 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 13 Monitorin g Monitorin g | Live Event Log Figur e 13-4 Monit or ing | Live Event Log Scr een Pause Disp lay/Resume Display T o pause the d isplay , click Paus e Disp lay .
13-8 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 13 Monitorin g Monito rin g | Sy st em St atus Monitoring | System Status This screen sh ows the status of sev eral sof tware and ha rdware variab les at t he time t he scree n displays.
13-9 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 13 Monitorin g Monit oring | S ystem Sta tus Refresh T o update the screen and its data, click Refresh . The date and tim e indicate when the scre en was last update d. VPN Clien t Type The type , or model number, of this VPN 3002 ha rdware client.
13-10 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 13 Monitorin g Monito rin g | Sy st em St atus Tunnel Es tablished to The IP ad dre ss of t he VPN C o ncen tr ato r t o w hic h t his V PN 3002 co nne cts . Duration The length of time that this t unnel has bee n up.
13-11 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 13 Monitorin g Moni t orin g | Syst em Stat us | P ri v ate/Pu blic I n terf ac e Ot her Additional in formation about this SA, inclu ding mode. Front Panel The fron t panel im age is a n inactiv e link.
13-12 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 13 Monitorin g Monito rin g | System Status | Private/Public Interface Restore T o restore the screen contents to their actual statistical values, click Restor e . Th is i con di spla ys on l y if you previously clicked the Reset ico n .
13-13 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 13 Monitorin g Moni t orin g | Syst em Stat us | P ri v ate/Pu blic I n terf ac e Rx Unicast The n umb er of uni cast packe ts that we re receiv ed by thi s interf ace sinc e the VP N 3002 wa s l ast boote d or reset.
13-14 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 13 Monitorin g Moni tori ng | User Stat us Monitoring | User Status This se ction di splays st atist ic s for de vice s be hind the VP N 30 02 Har dware Cli ent . Figur e 13-7 Monit or ing | User S tatus scr e en Refresh T o update the screen and its data, click Ref res h .
13-15 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 13 Monitorin g Monitor ing | Stat isti cs Monitoring | Statistics This se cti on of th e Mana ge r show s stati sti cs fo r traffic an d a.
13-16 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 13 Monitorin g Monitorin g | Stat is tics | IPSec Monitoring | Statistics | IPSec This screen shows sta tistics for IPSec activity , including the cur rent IPSec tunnel, on the VPN 3002 sinc e it was la st booted o r reset.
13-17 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 13 Monitorin g Monitoring | Statistics | IPSec Refresh T o update the screen and its data, click Ref res h .
13-18 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 13 Monitorin g Monitorin g | Stat is tics | IPSec Received Notifies The cumul ative total of notify packe ts received by all currently a nd previo usly activ e IKE tun nels.
13-19 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 13 Monitorin g Monitoring | Statistics | IPSec Phase-2 SA Delete Requests Sent The cumulativ e tot al of r eque sts to d ele te IPSe c Phase -2 Se cu rit y Assoc iati ons se nt by a ll c urr ently and previously active IKE tunnel s .
13-20 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 13 Monitorin g Monitorin g | Stat is tics | IPSec IPSec (Phas e 2) Sta tistics This t abl e pro vi des I PSec Pha se 2 globa l sta tisti cs. D uring I PSec Ph ase 2, t he tw o p eers ne gotia te Security Associat io ns that govern traf fic within the tunnel.
13-21 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 13 Monitorin g Monitoring | Statistics | IPSec Sent Packets Dropped The cumulative to tal of packets droppe d during send processing by all curren tly and previous ly active IPSec Phase- 2 tunnel s.
13-22 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 13 Monitorin g Monito rin g | Stat istics | HTTP System Capability Failures The tot al number of syst em capa city fail ures that occurre d during pr ocessing of all curre ntly and previo usly activ e IPSec Ph ase-2 tunn els.
13-23 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 13 Monitorin g Monitor ing | Stati stics | HTTP Reset T o reset, or s tart anew , the screen contents, click Reset . The system tem porari ly resets a co unter fo r the chosen statist ics without a f fecting the operation of the dev ice.
13-24 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 13 Monitorin g Monito rin g | Stat istics | HTTP HTTP Ses sions This se ction pr ovid es i nfo rmat ion abou t H TTP sessi ons on t he V PN 3 002 sinc e i t wa s la st bo ote d o r reset. Login Name The name o f th e admi nis tra t ive u ser f or the H TT P se ss ion .
13-25 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 13 Monitorin g Monito ring | Statis tics | Telnet Monitoring | Statistics | Telnet This sc reen show s statis tics for T elnet ac tivity on the V PN 3002 since i t was la st boote d or re set, and f or current T elnet sessions.
13-26 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 13 Monitorin g Monito rin g | Stat istics | Telnet Attempted Sessions The tota l number of attempts to establish T elnet sessio ns on the VPN 3002 since it was last b ooted or reset.
13-27 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 13 Monitorin g Monitoring | Statistics | DNS Monitoring | Statistics | DNS This screen shows statistics for DNS (Domain Name System) activity on the VPN 3002 since it was last booted or r eset.
13-28 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 13 Monitorin g Monitorin g | Stat is tics | SSL Timeouts The num ber of DNS queries t hat failed becaus e there was no resp onse from th e server .
13-29 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 13 Monitorin g Monitor ing | Stati stics | SSL Refresh T o update the screen and its data, click Ref res h .
13-30 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 13 Monitorin g Monitorin g | Stat istics | DHCP Monitoring | Statistics | DHCP This sc reen sh ows st at istic s f or D HCP ( Dy nami c H ost Confi gurat ion Pr otoc ol) serv er act ivity o n th e VPN 3002 since it w as last boot ed or re set.
13-31 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 13 Monitorin g Monitoring | Statistics | DHCP Timeouts The n umber o f DHCP qu eries that f ailed b ecause there was no respon se from the s erver . Pool Start The IP ad dres s at th e star t of the DH CP IP ad dres s pool.
13-32 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 13 Monitorin g Monitorin g | Stat is tics | SSH Monitoring | Statistics | SSH This sc reen sh ows st at istic s f or SSH ( Sec ure She ll) p rot ocol tr affic on t he V PN 3002 si nce it was la st booted or r eset.
13-33 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 13 Monitorin g Monitoring | Statistics | SSH Packets S ent/Rec eived The total num ber of SSH pac kets sent/re ceived since the VPN 3002 wa s last booted or re set. Active Sessions The numbe r of curr ently acti ve SSH sessio ns.
13-34 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 13 Monitorin g Monito rin g | Stat istics | NAT Monitoring | Statistics | NAT This screen sh ows statistics f or NA T (Network Add ress Translation) activity on the VPN 3002 since it was last booted or reset.
13-35 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 13 Monitorin g Monitoring | Statistics | NAT Translations Active The numbe r of curr ently acti ve NA T sessions. Translations Peak The ma xim um num ber of NA T session s t hat were sim ult aneou sly a ct ive on the V PN 3002 si nce it w as last booted or reset.
13-36 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 13 Monitorin g Monitoring | Stat istics | PPPoE • NetBIOS over TCP Proxy • NetBIO S over UDP Proxy • NetBIO S Datagram Service Translated Bytes/Packets The to tal numb er of tr anslat ed byt es and packets for th e NA T session.
13-37 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 13 Monitorin g Monitoring | Statistics | PPPoE User Name The username for the PPPoE session. Session ID The ID for the se ssion assigned by the IS P . The Session ID combined with the Access Co ncentrator MAC Address (see below) uni quely identifies the PPPoE session.
13-38 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 13 Monitorin g Monitoring | Stat istics | PPPoE PADT Rx The number of PPPoE Act ive Discovery T erm inate packets received. PADT Tx The number of PPPoE Act ive Discovery T erminate packets sent.
13-39 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 13 Monitorin g Monitoring | Statistics | MIB-II Monitoring | Statistics | MIB-II This section of the Manage r lets you view statistics that are record ed in standard MIB-II obje cts on the VPN 3002.
13-40 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 13 Monitorin g Mon i tor in g | St atis tics | MIB -II | I nter fa ces Monitoring | Statistics | MIB-II | Interfaces This screen sho ws statistics in MIB-II objects for VPN 3002 in terfaces since the system was last booted or rese t.
13-41 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 13 Monitorin g Monitoring | Statistics | MIB-II | Interfaces • Disabled = co nfigure d by disable d. • DOWN(DOWN/DHCP , DOWN/PPPoE) = configured but down. • T estin g = in te st mode; no regular d ata traf fic can pass.
13-42 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 13 Monitorin g Monitorin g | Statistics | MIB -II | TCP /UDP Monitoring | Statistics | MIB-II | TCP/UDP This scree n shows statisti cs in MIB-II obj ects for TCP and UDP traff ic on the VPN 3002 si nce it was last booted or reset.
13-43 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 13 Monitorin g Monitoring | Statistics | MIB-II | TCP/UDP TCP Segmen ts Trans mitted The to tal numbe r of segm e nts se nt, i ncl udin g t hos e o n curr en tly es tabli shed c on ne ction s but exc ludi n g those contai n ing only retransmitted b ytes.
13-44 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 13 Monitorin g Monitorin g | Statistics | MIB -II | TCP /UDP TCP Estab lished Res ets The numbe r of establi shed TC P connecti ons that abru ptly closed, bypassing gra ceful term inatio n.
13-45 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 13 Monitorin g Monitoring | Statistics | MIB-II | IP Monitoring | Statistics | MIB-II | IP This screen shows statistic s in MIB-II objec ts for IP traffic on the VP N 30 02 since it was last boo ted or reset.
13-46 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 13 Monitorin g Mon i tor in g | St atis tics | MIB -II | I P Packets R eceived (T otal) The tot al numbe r of IP data pack ets rece ived b y the VPN 30 02, incl uding tho se recei ved with errors.
13-47 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 13 Monitorin g Monitoring | Statistics | MIB-II | IP Outbound P ackets with No Route The numbe r of outbound IP data packets di sca rded becaus e no route cou l d be found to transm i t them to their de stinat ion.
13-48 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 13 Monitorin g Mon i tor in g | St atis tics | MIB -II | I CMP Monitoring | Statistics | MIB-II | ICMP This screen shows statistics in MIB-II objects for ICMP traffic on the VPN 3002 since it was last booted or rese t.
13-49 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 13 Monitorin g Monitoring | Statistics | MIB-II | ICMP Errors Received/Transmitted The num ber o f ICMP me ssages tha t the VP N 3002 r eceived bu t deter mined to have IC MP-specif ic err ors (bad IC MP chec ksu ms, bad l ength, etc.
13-50 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 13 Monitorin g Mon i tor in g | St atis tics | MIB -II | I CMP Timestamp Requests Received/Transmitted The n umber of ICM P T imestam p (req uest) messa ges receiv ed/sent.
13-51 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 13 Monitorin g Monit oring | S tatist ics | MIB-II | ARP Table Monitoring | Statistics | MIB-II | ARP Table This sc reen sh ows e ntrie s in the A ddre ss R esolut ion Protoc ol mappi ng t able sinc e t he VP N 3 002 wa s last booted or reset.
13-52 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 13 Monitorin g Monitorin g | Statistics | MIB-II | ARP Tab le Interface The VPN 300 2 network i nterface on which this ma pping appli es: .
13-53 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 13 Monitorin g Monitor ing | Stati stics | MIB-II | Eth ernet Monitoring | Statistics | MIB-II | Ethernet This screen shows statistic s in MIB-II objec ts for Ether net interface t raf fic on the VPN 3002 since i t was last boote d or rese t.
13-54 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 13 Monitorin g Monito rin g | Statistics | MIB -II | Ethe rnet Alignment Err or s The nu mber of f rames rece ived on th is interfac e that a re not a n integral n umber of bytes in length and do not pass the FCS (Fra me Check Sequence; used for error detec tion) check .
13-55 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 13 Monitorin g Monitor ing | Stati stics | MIB-II | Eth ernet Excessive Collisions The number of frames f or which tr ansmission on this interface failed due to excessive collisions.
13-56 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 13 Monitorin g Mon i tor in g | St atis tics | MIB -II | S NMP Monitoring | Statistics | MIB-II | SNMP This scr een shows sta tistics i n MIB-II objects fo r SNMP tra ffic on the VPN 3002 sin ce it was last booted or reset .
13-57 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 13 Monitorin g Monitoring | Statistics | MIB-II | SNMP Bad Commun ity Strin g The tota l number of SNMP message s received th at used an SNM P commu ni ty string the VPN 3002 did not recognize .
13-58 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 13 Monitorin g Mon i tor in g | St atis tics | MIB -II | S NMP.
C HAPTER 14-1 VPN 3002 Hard ware Clie nt Refe rence OL-1893-01 14 Using the Command-Line Interface The VP N 3002 Hard ware Cli ent comm and-li ne inter face (C LI) is a men u- and co mman d-line-b ased config uration, administr ation, an d monitoring syst em built int o the VPN 300 2.
14-2 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 14 Using the Command -Line Int erface Star t ing th e Com m and- l ine In ter face 3. Press Ent er on t he PC keyb oard un til you see the login p rompt. (Y ou mig ht see a password promp t and er ror m essage s as you p ress E nte r; i gn ore th em a nd stop a t the log i n prom pt .
14-3 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 14 Using the Com m and -Line Interfac e Using the Command-line Interface Using the Command-lin e Interface This se cti on e xpla ins how to : • Choo se menu it ems. • Enter val ues f or pa rame te rs and o ptio ns.
14-4 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 14 Using the Command -Line Int erface Using t he Comm and-line I nterface Navigat ing Quic kly There ar e two ways t o move quic kly throu gh the comma nd-lin e interfa ce: shortc ut numbe rs, and the Back/ Home opti ons.
14-5 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 14 Using the Com m and -Line Interfac e Using the Command-line Interface As a sh ortc ut, yo u ca n ju st e nter 2.
14-6 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 14 Using the Command -Line Int erface Using t he Comm and-line I nterface Saving the Configuration File Configurat ion and administratio n entries take ef fect immediate ly and are included in the active , or running , config urat ion.
14-7 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 14 Using the Com m and -Line Interfac e Menu Refer e nce Menu Refere nce This section shows all the menus in the firs t three levels below the main menu.
14-8 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 14 Using the Command -Line Int erface Menu Re ference 1.2.1 or 1.2.2 Configuration > Interface Configurat ion > Configure the Private.
14-9 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 14 Using the Com m and -Line Interfac e Menu Refer e nce 1.3.5 Configuration > System Management > Event Configurat ion 1) General 2) Classes 3) Trap Destinations 4) Syslog Servers 5) Back Event -> _ 1.
14-10 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 14 Using the Command -Line Int erface Menu Re ference 2.2 Administration > System Reboot 1) Cancel Scheduled Reboot/Shutdown 2) Schedule Reboot 3) Schedule Shutdown 4) Back Admin -> _ 2.
14-11 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 14 Using the Com m and -Line Interfac e Menu Refer e nce 2.4.2 Administration > Access Rights > Access Settings 1) Set Session Timeout 2) Set Session Limit 3) SertConfig File Encryption 4) Back Admin -> _ 2.
14-12 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 14 Using the Command -Line Int erface Menu Re ference 2.6.3 Administration > Certifica te Management > Certificate A uthorities Certificate Authorities . . . 1) View Certificate 2) Delete Certificate 4) Back Certificates -> _ 2.
14-13 VPN 3002 Hardware C lient Referen ce OL-1893-01 Chapter 14 Using the Com m and -Line Interfac e Menu Refer e nce 3.1 Monitoring > Routing Table Routing Table . . ’q’ to Quit, ’<SPACE>’ to Continue -> . . 1) Refresh Routing Table 2) Clear Routing Table 3) Back Routing -> _ 3.
14-14 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Chapter 14 Using the Command -Line Int erface Menu Re ference 3.4 Monitoring > User Status Authenticated Users ------------------- Username IP .
A-1 VPN 3002 Hardwar e Client Ref erence OL-1893-01 APPENDIX A T roubleshooting an d Sy stem Errors Appendix A descri bes files f or trou bleshooti ng the V PN 3002 and LED indica tors on the system. It also describe s com mon e rrors tha t mi ght o ccur whil e c onfig urin g a nd us in g th e syste m, a nd how to c orre ct them.
A- 2 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Appendi x A Troubl eshoot ing and Sys tem Errors LED Indi c at o rs crash, we ask that you sen d this file wh en you cont act T AC for ass istan ce. T o view the CRSHDUMP .TXT fil e, see Admini stra tion | Fi le Ma nage ment | V iew , an d cl ick on View Saved Log Crash Dump File .
A-3 VPN 3002 Hardware C lient Referen ce OL-1893-01 Append ix A Troubles hooting an d Sys tem Errors System Erro rs VPN 30 02 Rear LED s The LEDs on the r ear of the VPN 30 02 indicate the status of the private and public interface s.
A- 4 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Appendi x A Troubl eshoot ing and Sys tem Errors Settings on the VPN Concent rator Settings on the VPN Con centrator If your VPN 3002 exper ience s connect ivity probl ems, ch eck the con figurat ion of the VPN Conce ntrator .
A-5 VPN 3002 Hardware C lient Referen ce OL-1893-01 Append ix A Troubles hooting an d Sys tem Errors VPN 3002 Hardware C lient Manage r Errors Step 4 If you ar e using N etwor k Exte nsion m ode , c onf igure a de fa ult ga te way or a st at ic rou te to th e p riva te network of the VP N 3 002 .
A- 6 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Appendi x A Troubl eshoot ing and Sys tem Errors VPN 3002 Hardw are Client Manage r Errors Manager L ogs Out The Mana ger un expect edly lo gs out.
A-7 VPN 3002 Hardware C lient Referen ce OL-1893-01 Append ix A Troubles hooting an d Sys tem Errors VPN 3002 Hardware C lient Manage r Errors Incorrect Display The Man ager di splays an inc orrect screen o r data when you click on the browse r back o r forwar d button.
A- 8 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Appendi x A Troubl eshoot ing and Sys tem Errors VPN 3002 Hardw are Client Manage r Errors Not Allowed Message The Mana ger displa ys a screen with the me ssage: “ Not Allo wed / Y ou do not have sufficient authori zation to ac cess the specif ied page.
A-9 VPN 3002 Hardware C lient Referen ce OL-1893-01 Append ix A Troubles hooting an d Sys tem Errors VPN 3002 Hardware C lient Manage r Errors Not Found The Mana ger displa ys a screen with the me ssage: “ Not Foun d/An error has occu rred whil e attempti ng to access the specified pag e.
A-10 VPN 3002 Hardwar e Client Referenc e OL-1893-01 Appendi x A Troubl eshoot ing and Sys tem Errors Command -line Interface Errors Command-line Interfac e Errors Thes e errors may occur while using the men u-base d command-l ine interf ace fr om a c onsole or T elnet session.
IN- 1 VPN 3002 Hardware Clie nt Reference OL-1893-01 INDEX Numerics 3DES-168 /SHA SSL en crypti on algor ithm 8-11 3DES-168 SSH e ncry ption a lgorithm 8-14 A acce ssing the CLI 14-1 acces s righ ts a.
Index IN-2 VPN 3002 Hardwar e Client Referenc e OL-1893-01 cancel ling an e nrollment req uest 12-60 certifi cate PEM-en coded 12-28 Certifica te Authority (CA) definition 12-16 certif icate ma nageme.
Index IN- 3 VPN 3002 Hardware Clie nt Reference OL-1893-01 cras h, syst em saves log file A-1 CRSHDUMP.TXT file A-1 D data forma ts xiii data init iation VPN 3002 an d centra l-site c oncent rator 11-.
Index IN-4 VPN 3002 Hardwar e Client Referenc e OL-1893-01 cancel ling 12-60 crea ting 12-37 deleting 12-61 PKCS-10 12-24, 12-40 removi ng accord ing to status 12-35 status table 12-35 time limit 12-17 viewing detail s 12-58 entering v alues wi th CLI 14-3 eras ing th e ev ent lo g 13-5 erro r an erro r has oc curred .
Index IN- 5 VPN 3002 Hardware Clie nt Reference OL-1893-01 generati ng SSL server certif icate 12-33 get event log 13-5 H halting the VPN 30 02 12-5 help, CLI 14-5 Home an d Back CLI ch oices 14-5 hos.
Index IN-6 VPN 3002 Hardwar e Client Referenc e OL-1893-01 attribute s configurable on the central-site conc entr ator 6-2 config uring 6-2 statistics 13-16 IPSec ov er T CP 6-5 requir ements 6-6 ITU .
Index IN- 7 VPN 3002 Hardware Clie nt Reference OL-1893-01 required set tings o n VPN Conc entra tor 11-3 nonvola tile m e mory 12-10 even t log stor ed in 13-3 No such interface suppo rted (error) A-.
Index IN-8 VPN 3002 Hardwar e Client Referenc e OL-1893-01 browser 1-1 Intern et Expl orer 1-1 IPSec ov er T CP 6-6 Ja vaScr ipt 1-2 Nets cape Navi gator 1-1 RFC 1650, Eth ernet inter face MIB obj ect.
Index IN- 9 VPN 3002 Hardware Clie nt Reference OL-1893-01 updating on V PN 3002 proc edure 12-2 stopping an i mage updat e 12-3 version info 12-3, 13-9 split tunneling client (P AT) mo de 11-1 Networ.
Index IN- 10 VPN 3002 Hardwar e Client Referenc e OL-1893-01 superuse r See administra tors swap configura tion files 12-13 syslog form at, eve nts 9-6 syslog serv er config uri ng f or ev en ts add 9.
Index IN-11 VPN 3002 Hardware Clie nt Reference OL-1893-01 even t log 13-5 SSL cer tificates with Internet Explorer 1-8 with Netscape 1-14 VPN 3002 status, session s, statistics, and event logs 13-1 V.
Index IN- 12 VPN 3002 Hardwar e Client Referenc e OL-1893-01.
Un point important après l'achat de l'appareil (ou même avant l'achat) est de lire le manuel d'utilisation. Nous devons le faire pour quelques raisons simples:
Si vous n'avez pas encore acheté Cisco VPN 3002 c'est un bon moment pour vous familiariser avec les données de base sur le produit. Consulter d'abord les pages initiales du manuel d'utilisation, que vous trouverez ci-dessus. Vous devriez y trouver les données techniques les plus importants du Cisco VPN 3002 - de cette manière, vous pouvez vérifier si l'équipement répond à vos besoins. Explorant les pages suivantes du manuel d'utilisation Cisco VPN 3002, vous apprendrez toutes les caractéristiques du produit et des informations sur son fonctionnement. Les informations sur le Cisco VPN 3002 va certainement vous aider à prendre une décision concernant l'achat.
Dans une situation où vous avez déjà le Cisco VPN 3002, mais vous avez pas encore lu le manuel d'utilisation, vous devez le faire pour les raisons décrites ci-dessus,. Vous saurez alors si vous avez correctement utilisé les fonctions disponibles, et si vous avez commis des erreurs qui peuvent réduire la durée de vie du Cisco VPN 3002.
Cependant, l'un des rôles les plus importants pour l'utilisateur joués par les manuels d'utilisateur est d'aider à résoudre les problèmes concernant le Cisco VPN 3002. Presque toujours, vous y trouverez Troubleshooting, soit les pannes et les défaillances les plus fréquentes de l'apparei Cisco VPN 3002 ainsi que les instructions sur la façon de les résoudre. Même si vous ne parvenez pas à résoudre le problème, le manuel d‘utilisation va vous montrer le chemin d'une nouvelle procédure – le contact avec le centre de service à la clientèle ou le service le plus proche.