Contents
xx
Cisco Security Appliance Command Line Configuration Guide
OL-10088-01
CHAPTER
28 Configuring L2TP over IPSec 28-1
L2TP Overview 28-1
IPSec Transport and Tunnel Modes 28-2
Configuring L2TP over IPSec Connections 28-3
Tunnel Group Switching 28-5
Viewing L2TP over IPSec Connection Information 28-5
Using L2TP Debug Commands 28-7
Enabling IPSec Debug 28-8
Getting Additional Information 28-8
CHAPTER
29 Setting General IPSec VPN Parameters 29-1
Configuring VPNs in Single, Routed Mode 29-1
Configuring IPSec to Bypass ACLs 29-1
Permitting Intra-Interface Traffic 29-2
NAT Considerations for Intra-Interface Traffic 29-3
Setting Maximum Active IPSec VPN Sessions 29-3
Using Client Update to Ensure Acceptable Client Revision Levels 29-3
Understanding Load Balancing 29-5
Implementing Load Balancing 29-6
Prerequisites 29-6
Eligible Platforms 29-7
Eligible Clients 29-7
VPN Load-Balancing Cluster Configurations 29-7
Some Typical Mixed Cluster Scenarios 29-8
Scenario 1: Mixed Cluster with No WebVPN Connections 29-8
Scenario 2: Mixed Cluster Handling WebVPN Connections 29-8
Configuring Load Balancing 29-9
Configuring the Public and Private Interfaces for Load Balancing 29-9
Configuring the Load Balancing Cluster Attributes 29-10
Configuring VPN Session Limits 29-11
CHAPTER
30 Configuring Tunnel Groups, Group Policies, and Users 30-1
Overview of Tunnel Groups, Group Policies, and Users 30-1
Tunnel Groups 30-2
General Tunnel-Group Connection Parameters 30-2
IPSec Tunnel-Group Connection Parameters 30-3
WebVPN Tunnel-Group Connection Parameters 30-4
Configuring Tunnel Groups 30-5