cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
753
Views
0
Helpful
9
Replies

VPN Connection for Cisco ISR 1100

whughes123
Level 1
Level 1

I purchased a Cisco ISR c1111-8p router a week ago, it took me a week to configure the thing to connect to the internet and only after @balaji.bandi helped me out. I am in need of some guidance on what kind of VPN connections I should create for about 20 engineers that will be using VPN connections to connect to a file server and transfer large (20GB-40GB) files to and from the file server. Any suggestions would be extremely helpful as far as encryption protocols, whether to use FlexVPN or AnyConnect or whatever options are available. 

Thank you!!

9 Replies 9

Thank you man, I will go through those 3 links and get back to you after I review things. You're the man!!

whughes123
Level 1
Level 1

Ok so after going through those links, I assume I need to have a CA server setup for this to be configured on the Cisco router? Is that something I can do on the new Windows Server 2022 that I'm using for the File Server that the engineers will be connecting to via VPN? Can I setup a CA server on the same server they are connecting to with the VPN I'm using the CA server for? I have this in my current config but I'm not 100% on what it means or does for me.

crypto pki trustpoint SLA-TrustPoint
  enrollment pkcs12
  revocation-check crl
  hash sha256

there is bug prevent using self signed Cert in IKEv2 anyconnect 
you need to use Win Server as CA
MHM

Roger that, so I have a very specific situation but I'm sure unlimited options as to go about solving my problem. I need to meet CMMC compliance, so data in transit must be encrypted. I have 20 engineers that VPN into a file server from around the country. Currently they use OpenVPN which is configured on a commercial ASUS router. I bought a Cisco ISR 1100 router for a few reasons, but I'm trying to work it into the equation, and I need ideas as the best way to go about it. I have attached a network diagram of my current setup in my building. Any help or suggestions or direction would be greatly appreciated!!

Once you are connected VPN all the Access to Servers will be Secured, You can use PKI infrastructure - you can use MS CA or Router as CA for the certs.

The router come with cert already -

crypto pki trustpoint SLA-TrustPoint

 check @Rob Ingram already provided the link Router can ACT as CA. (make sure your PC can trust that certs.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

I'm going to get working on this Monday! I saw the SLA-TrustPoint cert in my config and assumed that's what it was. I have a Windows Server 2022 VM but I wonder if it matters the version (Standard, Data Center, Essentials) 

@Rob Ingram I'm going to try to get this setup using the links you provided and I will get back with you guys as soon as I get back in town and have time to set it up. Might be a few days.

Thank you guys SO MUCH for your help!

whughes123
Level 1
Level 1

After talking with our CEO, he just wants to continue to use OpenVPN on the existing wireless router in place (that will be connected to the Cisco ISR 1100 to provide wifi in the building) instead of setting up a CA server on Windows Server 2022 and configuring the Cisco ISR 1100 to encrypt the VPN sessions. I have another topic for questions but I will start a new thread for it, thank you guys for everything!