07-13-2005 07:45 AM
Hi All,
I have a Cisco Pix 515 and a vpn group setup on it. I was wondering how to setup multiple vpn groups on a pix if possible.
I am running IOS 6.33.
Thanks,
Paul Hong
07-18-2005 10:35 AM
Hi Paul,
Yes you can, just use different names in the VPNGROUP command. The group name has to match the username you configure in the vpn client.
vpngroup VPNUSER1 address-pool VPNUSER
vpngroup VPNUSER1 idle-time 1800
vpngroup VPNUSER1 password user1
vpngroup VPNUSER2 address-pool VPNUSER
vpngroup VPNUSER2 idle-time 1800
vpngroup VPNUSER2 password user2
Hope thats clear enough,
Andy
07-18-2005 02:50 PM
you may further restrict the remote vpn access:
1. apply individual account - all user needs to provide individual username/password as well as the group username/password (i.e. the pcf file)
aaa-server LOCAL protocol local
crypto map mymap client authentication LOCAL
crypto map mymap client configuration address initiate
crypto map mymap client configuration address respond
username xxx password yyy
2. apply acl - restrict access to particular server(s)
access-l 100 permit ip
vpngroup vpnclient split-tunnel 100
3. disable sysopt connection permit-ipsec - all ipsec traffic will be inspected by checking the inbound acl. typically used when further restriction is required , for example remote vpn users need only access an internal email server.
no sysopt connection permit-ipsec
access-l 110 permit tcp
access-g 110 in inter outside
07-19-2005 01:29 PM
Thank you Andy,
I am going to try it today and see if it works.
BTW, Whats the maximum number of vpn users this 515 pix can support?
Thanks,
Paul Hong
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide