62-2
Cisco ASA 5500 Series Configuration Guide using ASDM
OL-20339-01
Chapter 62 VPN
VPN Wizard
• Authenticates users
• Authorizes users for specific levels of use and access
• Performs accounting functions
• Assigns user addresses
• Encrypts and decrypts data
• Manages security keys
• Manages data transfer across the tunnel
• Manages data transfer inbound and outbound as a tunnel endpoint or router
The adaptive security appliance invokes various standard protocols to accomplish these functions
VPN Wizard
The VPN wizard lets you configure basic LAN-to-LAN and remote access VPN connections. Use
ASDM to edit and configure advanced features.
Note The VPN wizard lets you assign either preshared keys or digital certificates for authentication. However,
to use certificates, you must enroll with a certification authority and configure a trustpoint prior to using
the wizard. Use the ASDM Device Administration > Certificate panes and online Help to accomplish
these tasks.
VPN Overview
The adaptive security appliance creates a Virtual Private Network by creating a secure connection across
a TCP/IP network (such as the Internet) that users see as a private connection. It can create
single-user-to-LAN connections and LAN-to-LAN connections.
For LAN-to-LAN connections using both IPv4 and IPv6 addressing, the security appliance supports
VPN tunnels if both peers are Cisco ASA 5500 series security appliances, and if both inside networks
have matching addressing schemes (both IPv4 or both IPv6). This is also true if both peer inside
networks are IPv6 and the outside network is IPv6.
The secure connection is called a tunnel, and the adaptive security appliance uses tunneling protocols to
negotiate security parameters, create and manage tunnels, encapsulate packets, transmit or receive them
through the tunnel, and unencapsulate them. The adaptive security appliance functions as a bidirectional
tunnel endpoint: it can receive plain packets, encapsulate them, and send them to the other end of the
tunnel where they are unencapsulated and sent to their final destination. It can also receive encapsulated
packets, unencapsulate them, and send them to their final destination.
The adaptive security appliance performs the following functions:
• Establishes tunnels
• Negotiates tunnel parameters
• Authenticates users
• Assigns user addresses
• Encrypts and decrypts data
• Manages security keys