| [ LiB ] |
The following is a step-by-step discussion of the Practical Exercise solution.
PIX(config)#access-list 101 permit ip 10.1.1.0 255.255.255.0 10.1.2.0 255.255.255.0
PIX(config)#ip local pool ippool 10.1.2.1-10.1.2.254
PIX(config)#nat (inside) 0 access-list 101
PIX(config)#sysopt connection permit-ipsec
PIX(config)#isakmp enable outside PIX(config)#isakmp identity address
PIX(config)#isakmp policy 10 authentication pre-share PIX(config)#isakmp policy 10 encryption des PIX(config)#isakmp policy 10 hash md5 PIX(config)#isakmp policy 10 group 2 PIX(config)#isakmp policy 10 lifetime 86400
PIX(config)#isakmp policy 20 authentication pre-share PIX(config)#isakmp policy 20 encryption des PIX(config)#isakmp policy 20 hash md5 PIX(config)#isakmp policy 20 group 1 PIX(config)#isakmp policy 20 lifetime 86400
PIX(config)#vpngroup vpn3000 address-pool ippool PIX(config)#vpngroup vpn3000 dns-server 10.1.1.2 PIC(config)#vpngroup vpn3000 wins-server 10.1.1.2 PIX(config)#vpngroup vpn3000 default-domain cisco.com PIX(config)#vpngroup vpn3000 idle-time 1800 PIX(config)#vpngroup vpn3000 password cisco PIX(config)#vpngroup vpn3000 split-tunnel 101
PIX(config)#crypto ipsec transform-set myset esp-des esp-md5-hmac PIX(config)#crypto dynamic-map dynmap 10 set transform-set myset PIX(config)#crypto map mymap 10 ipsec-isakmp dynamic dynmap PIX(config)#crypto map mymap interface outside PIX(config)#crypto dynamic-map dynmap 10 set transform-set myset PIX(config)#crypto map mymap 10 ipsec-isakmp dynamic dynmap PIX(config)#crypto map mymap interface outside
- Click New to create a new connection, and assign a name to your entry in the Connection Entry box, as shown in Figure 14-12.

- Enter the IP address of the destination's public interface, as shown in Figure 14-13.

- Under Group Access Information, enter the group name and group password, as shown in Figure 14-14.

- Click Finish to save the profile in the Registry, as shown in Figure 14-15.

- Click Connect to test the connection, as shown in Figure 14-16.

| [ LiB ] |