
4-20
Cisco IP Solution Center Integrated VPN Management Suite Security User Guide, 3.2
OL-5532-02
Chapter 4 Remote Access VPN Services
Creating Remote Access VPN Policies
Step 3 Click Next to continue to the VPN 3000 Access Hours page as shown Figure 4-20 in the “Defining the
VPN 3000 Access Hours” section on page 4-20.
Defining the VPN 3000 Access Hours
For connections made through VPN 3000 devices in your network, you can control when a user has
access to your private network through the remote access VPN.
Perform the following steps to restrict user access to specific hours during the day or night:
Step 1 The Remote Access VPN Policy – Access Hours page appears as shown in Figure 4-20.
Figure 4-20 The Remote Access VPN Policy – Access Hours Page
Allow IPsec
Through NAT
checkbox The Allow IPsec through NAT option lets you use the Cisco VPN Client to connect
to the VPN Concentrator via UDP through a firewall or router that is running NAT.
Enabling this feature creates runtime filter rules that forward UDP traffic for the
configured port even if other filter rules on the interface drop UDP traffic. These
runtime rules exist only while there is an active IPsec through NAT session. The
system passes inbound traffic to IPsec for decryption and unencapsulation, and then
passes it on to the destination. The system passes outbound traffic to IPsec for
encryption and encapsulation, applies a UDP header, and forwards it.
Check to enable the IPsec client to operate through a firewall using NAT via UDP.
Uncheck (disable) this option to prevent to IPsec clients from operating through a
firewall that is using NAT.
IPsec Through NAT
Port
text box If you selected Allow IPsec Through NAT, enter the UDP port to be used for IPsec
traffic, using any port from 4001 to 49151. The default is 10000.
Allow Password
Storage on Client
checkbox Check to allow the IPsec client to store its password locally.
Banner text box Enter the banner text to display for this group. The banner cannot exceed 512
characters.
Table 4-8 VPN 300 Editor Fields (continued)
Field Name Type Instructions
Kommentare zu diesen Handbüchern