2-9
ASA 5505 Getting Started Guide
78-18003-02
Chapter 2 Deployment Planning
Scenario 6: Easy VPN Hardware Client
• Hosts at remote sites no longer have to run VPN client software.
• Security policies reside on a central server and are pushed to the remote
hardware clients when a VPN connection is established.
• Few configuration parameters need to be set locally, minimizing the need for
on-site administration.
Figure 2-7 illustrates how the different Easy VPN components can be deployed.
Figure 2-7 ASA 5505 Installed as VPN Hardware Client
For information about how to configure the ASA 5505 as a VPN hardware client,
see Chapter 11, “Scenario: Easy VPN Hardware Client Configuration.”
Internet
190930
ISP
Router
ISP
router
Push remote
configuration
Central LAN
Cisco ASA SSC-05
Status
Security
Services
Card Slot
1
2
c
o
n
s
o
l
e
R
E
S
E
T
P
O
W
E
R
4
8
V
D
C
7
P
O
W
E
R
o
v
e
r
E
T
H
E
R
N
E
T
6
5
4
3
2
1
0
ASA 5505
VPN Headend
Device
VPN Hardware
Client
Ci
sc
o
ASA
SSC
-05
S
tatus
Secu
r
it
y
Se
rvices
Card Slot
1
2
c
o
n
s
o
l
e
R
E
S
E
T
P
O
W
E
R
4
8
V
D
C
7
P
O
W
E
R
o
v
e
r
E
T
H
E
R
N
E
T
6
5
4
2
1
0
ASA 5500 series
Cisco IOS router
with IPSec support