Cisco SSL Web××× 配置

Step 1: ( create names for networks )

names
name < network address > wpn_<name>
Step 2: ( ensure you can circulate traffic between networks )
same-security-traffic permit inter-interface
same-security-traffic permit intra-interface
Step 3: ( ensure a Split Tunnel Access-list )
access-list remote_splitTunnelAcl standard permit < network address > < subnet address >
Step 4: ( create a network group )
object network WPN_<name>
subnet < network address > < subnet address >
Step 5: ( ensure a No Nat access-list )
access-list acl_NONAT_out extended permit ip object <Local network object group > object < wpn object group>
Step 6: ( create a ip local pool for the ssl*** )
ip local pool Web×××Pool <network address.100-<network address>.200 mask <subnet address>
Step 7: ( create a nat entry )
nat (inside,any) source static Local-LAN Local-LAN destination static WPN_<name> WPN_<name>
Step 8: ( create a radius connection if you use radius )
aaa-server <servername> protocol radius
aaa-server <servername> (inside) host < ip address server >
timeout 5
key <keyname>
Step 9: ( Web*** configuration ( ensure you upload the correct/latest anyconnect software ) )
web***
enable outside
svc p_w_picpath disk0:/anyconnect-win-2.5.0217-k9.pkg 3
svc p_w_picpath disk0:/anyconnect-macosx-i386-2.5.0217-k9.pkg 4
svc enable
tunnel-group-list enable
group-policy Web×××Policy internal
group-policy Web×××Policy attributes
dns-server value <dns server >
***-tunnel-protocol svc
group-lock value Web×××AccessProfile
split-tunnel-policy tunnelspecified
split-tunnel-network-list value remote_splitTunnelAcl
default-domain value <domainname>.local
address-pools value Web×××Pool
web***
svc ask none default svc
hidden-shares none
file-entry disable
file-browsing disable
url-entry disable
Step 10: ( create tunnel-groups )
tunnel-group Web×××AccessProfile type remote-access
tunnel-group Web×××AccessProfile general-attributes
authentication-server-group <radius groupname > LOCAL
default-group-policy Web×××Policy
tunnel-group Web×××AccessProfile web***-attributes
group-alias Web××× enable
發表評論
所有評論
還沒有人評論,想成為第一個評論的人麼? 請在上方評論欄輸入並且點擊發布.
相關文章