Cisco Secure VPN Client
Solutions Guide
For Cisco Secure VPN Client Version 1.0 or Later
Corporate Headquarters
Cisco Systems, Inc.
170 West Tasman Drive
San Jose, CA 95134-1706
USA
http://www.cisco.com
Tel: 408 526-4000
800 553-NETS (6387)
Fax: 408 526-4100
Text Part Number: OL-0259-01
,
C O N T E N T S
Preface vii
Audience vii
Document Organization viii
Business Cases Presented in This Solutions Guide viii
New and Changed Information ix
Related Documentation ix
Conventions xiii
Cisco Connection Online xiv
Documentation CD-ROM xv
CHAPTER 1 Overview of Virtual Private Networks and Cisco Secure VPN Client 1-1
What is a Virtual Private Network? 1-1
Types of Virtual Private Networks 1-2
Access VPNs 1-2
Intranet VPN 1-3
Extranet VPN 1-3
What is the Cisco Secure VPN Client? 1-4
Generating a Public/Private Key 1-5
Getting a Digital Certificate 1-5
Establishing a Security Policy 1-5
Interoperability with Cisco Routers 1-5
Recommended Cisco Routers 1-6
Cisco Routers with IP Security Protocol 1-6
Supported Configurations 1-7
Static or Dynamic Client IP Addresses with Pre-shared Keys 1-7
Static or Dynamic Client IP Addresses with Digital Certificates 1-7
Dynamic Client IP Addressing with IKE Mode Configuration 1-7
System Requirements 1-8
Client-side Requirements (Software) 1-8
Server-side Requirements (Hardware and Software) 1-8
Benefits 1-9
Client-initiated versus NAS-initiated Access VPNs 1-9
Cisco Secure VPN Client Solutions Guide
OL-0259-01 iii
, Contents
Pre-shared Keys versus Digital Certificates 1-9
Static versus Dynamic IP Addresses on the Client 1-11
Cisco Secure VPN Client versus Other VPN Solutions 1-11
CHAPTER 2 Using Pre-shared Keys: A Business Case 13
CHAPTER 3 Using Digital Certificates: Business Case Introduction 3-1
Benefits of Using Digital Certificates 3-1
Business Case Description 3-1
The Challenge 3-2
The Risk 3-2
The Solution 3-2
Supported Digital Certificates 3-6
Related Documentation 3-6
CHAPTER 4 Using Entrust Digital Certificates: A Business Case 4-1
Benefits of Using Entrust Digital Certificates 4-1
Configuring and Verifying 4-1
Configuring Entrust Digital Certifications 4-1
Configuring the Cisco Secure VPN Client 4-2
Task 1Importing the Root CA Certificate 4-3
Task 2Creating Public and Private Key Pair 4-5
Task 3Requesting Client Certificate from Entrust CA Server 4-7
Task 4Submitting the Certification Request to the Entrust Server 4-8
Task 5Importing Your Signed Entrust Digital Certificate 4-14
Task 6Configuring Other Connections for Security Policy 4-16
Task 7Configuring A New Connection for Security Policy 4-18
Task 8Specifying Identity Using RSA Signature 4-20
Task 9Specifying Encryption and Authentication Methods for Authentication, Phase 1 4-22
Task 10Specifying Encryption and Authentication Methods for Key Exchange, Phase 2 4-24
Task 11Saving Your Configuration 4-25
Configuring the Cisco Router 4-26
Task 1Configuring the Domain Name, Host Name, and Name Server 4-26
Task 2Configuring ISAKMP Policy and Defining IPSec Transform Set 4-26
Task 3Defining Crypto Dynamic Map and IKE Crypto Map to the Client 4-27
Cisco Secure VPN Client Solutions Guide
iv OL-0259-01