Cisco PIX 525 Dokumentacja Strona 243

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
  • Strona
    / 466
  • Spis treści
  • BOOKMARKI
  • Oceniono. / 5. Na podstawie oceny klientów
Przeglądanie stron 242
CHAPTER
7-1
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
7
Site-to-Site VPN Configuration Examples
A site-to-site VPN protects the network resources on your protected networks from unauthorized use by
users on an unprotected network, such as the public Internet. The basic configuration for this type of
implementation has been covered in
Chapter 6, “Configuring IPSec and Certification Authorities. This
chapter provides examples of the following site-to-site VPN configurations:
Using Pre-Shared Keys, page 7-1
Using PIX Firewall with a VeriSign CA, page 7-7
Using PIX Firewall with an In-House CA, page 7-13
Using an Encrypted Tunnel to Obtain Certificates, page 7-20
Connecting to a Catalyst 6500 and Cisco 7600 Series IPSec VPN Services Module, page 7-25
Manual Configuration with NAT, page 7-35
Note Throughout the examples in this chapter, the local PIX Firewall unit is identified as PIX Firewall 1 while
the remote unit is identified as PIX
Firewall 2. This designation makes it easier to clarify the
configuration required for each.
Using Pre-Shared Keys
This section describes an example configuration for using pre-shared keys. It contains the following
topics:
Scenario Description, page 7-1
Configuring PIX Firewall 1 with VPN Tunneling, page 7-2
Configuring PIX Firewall 2 for VPN Tunneling, page 7-5
Scenario Description
In the example illustrated in Figure 7-1, the intranets use unregistered addresses and are connected over
the public Internet by a site-to-site VPN. In this scenario, NAT is required for connections to the public
Internet. However, NAT is not required for traffic between the two intranets, which can be transmitted
using a VPN tunnel over the public Internet.
Przeglądanie stron 242
1 2 ... 238 239 240 241 242 243 244 245 246 247 248 ... 465 466

Komentarze do niniejszej Instrukcji

Brak uwag