Nokia Mobile VPN How to configure Nokia Mobile VPN for Cisco ASA with PSK/xAuth authentication



Similar documents
Configuring IPsec VPN with a FortiGate and a Cisco ASA

Use Shrew Soft VPN Client to connect with IPSec VPN Server on RV130 and RV130W

Scenario: Remote-Access VPN Configuration

Configuring TheGreenBow VPN Client with a TP-LINK VPN Router

VPN Configuration Guide. Cisco ASA 5500 Series

VPN Client User s Guide Issue 2

This topic discusses Cisco Easy VPN, its two components, and its modes of operation. Cisco VPN Client > 3.x

Shrew Soft VPN Client Configuration for GTA Firewalls

Scenario: IPsec Remote-Access VPN Configuration

Quick Guide to Using your Nokia Phone with Windows 95 Fax - Exchange for Windows 95 or Windows Messaging for Windows 95

Configuration Guide. How to set up the IPSec site-to-site Tunnel between the D-Link DSR Router and the Cisco Firewall. Overview

Fireware How To VPN. Introduction. Is there anything I need to know before I start? Configuring a BOVPN Gateway

SUPPORT GUIDE FOR. NOKIA MODEM DRIVER AND DIAL-UP for the Nokia 610. Copyright Nokia. All rights reserved Issue 0.4

Configuring Windows 2000/XP IPsec for Site-to-Site VPN

How To Configure An Ipsec Tunnel On A Network With A Network Gateways (Dfl-800) On A Pnet 2.5V2.5 (Dlf-600) On An Ipse Vpn

VPN Configuration Guide WatchGuard Fireware XTM

Dial-Up VPN auf eine Juniper

How to configure VPN function on TP-LINK Routers

Application Notes. How to Configure UTM with Apple OSX and ios Devices for IPsec VPN

Configuring GTA Firewalls for Remote Access

Nokia E90 Communicator Backing up data

SUPPORT GUIDE FOR. NOKIA MODEM DRIVER AND DIAL-UP for the Nokia 810. Copyright Nokia. All rights reserved Issue 0.4

Issue 2EN. Nokia and Nokia Connecting People are registered trademarks of Nokia Corporation

Windows XP VPN Client Example

How to configure VPN function on TP-LINK Routers

Configure IPSec VPN Tunnels With the Wizard

VPN. VPN For BIPAC 741/743GE

Create a VPN on your ipad, iphone or ipod Touch and SonicWALL NSA UTM firewall - Part 1: SonicWALL NSA Appliance

SUPPORT GUIDE FOR SETTINGS IN NOKIA 6600 IMAGING PHONE

Issue 1. Nokia and Nokia Connecting People are registered trademarks of Nokia Corporation

GNAT Box VPN and VPN Client

VPN Configuration of ProSafe VPN Lite software and NETGEAR ProSafe Router:

Nokia E90 Communicator Printing guide

VPN Wizard Default Settings and General Information

VPN Configuration Guide. ZyWALL USG Series / ZyWALL 1050

How To Industrial Networking

VPN Quick Configuration Guide. Astaro Security Gateway V8

External Authentication with Cisco VPN 3000 Concentrator Authenticating Users Using SecurAccess Server by SecurEnvoy

Lab 4.4.8a Configure a Cisco GRE over IPSec Tunnel using SDM

Nokia Call Connect v1.1 for Cisco User s Guide. Part Number: N Rev 003 Issue 1

OvisLink 8000VPN VPN Guide WL/IP-8000VPN. Version 0.6

Application Note: Integrate Cisco IPSec or SSL VPN with Gemalto SA Server. January

Cisco VPN Concentrator Implementation Guide

Chapter 5 Virtual Private Networking Using IPsec

HUAWEI HG256s. Home Gateway Quick Start

Using IKEv2 on Juniper Networks Junos Pulse Secure Access Appliance

Connecting Remote Offices by Setting Up VPN Tunnels

Dell One Identity Cloud Access Manager How To Deploy Cloud Access Manager in a Virtual Private Cloud

VPN Configuration Guide. Juniper Networks NetScreen / SSG / ISG Series

Chapter 7 Managing Users, Authentication, and Certificates

GlobalProtect Configuration for IPsec Client on Apple ios Devices

IP Office Technical Tip

VNS3 to Cisco ASA Instructions. ASDM 9.2 IPsec Configuration Guide

VPN Configuration Guide. Cisco Small Business (Linksys) WRV210

Defender 5.7. Remote Access User Guide

How To Set Up Checkpoint Vpn For A Home Office Worker

VPNC Interoperability Profile

Configuring an IPSec Tunnel between a Firebox & a Check Point FireWall-1

VPN Configuration Guide LANCOM

SUPPORT GUIDE FOR NOKIA PC SYNC

FortiOS Handbook IPsec VPN for FortiOS 5.0

Configuration Procedure

axsguard Gatekeeper IPsec XAUTH How To v1.6

How To Set Up A Vpn Tunnel Between Winxp And Zwall On A Pc 2 And Winxp On A Windows Xp 2 On A Microsoft Gbk2 (Windows) On A Macbook 2 (Windows 2) On An Ip

How To Establish IPSec VPN connection between Cyberoam and Mikrotik router

Netgear ProSafe VPN firewall (FVS318 or FVM318) to Cisco PIX firewall

Sophos UTM. Remote Access via PPTP. Configuring UTM and Client

Nokia for Business. Nokia and Nokia Connecting People are registered trademarks of Nokia Corporation

Nokia for Business. Nokia and Nokia Connecting People are registered trademarks of Nokia Corporation

Nokia E90 Communicator Transferring data

Cyberoam IPSec VPN Client Configuration Guide Version 4

DFL-210/260, DFL-800/860, DFL-1600/2500 How to setup IPSec VPN connection

VPN Configuration Guide D-Link DFL-800

SUPPORT GUIDE FOR USING WLAN AND UPNP

Understanding the Cisco VPN Client

IP Office Technical Tip

Cisco ASA 5500-X Series ASA 5512-X, ASA 5515-X, ASA 5525-X, ASA 5545-X, and ASA 5555-X

VPN Tracker for Mac OS X

Chapter 8 Lab B: Configuring a Remote Access VPN Server and Client

Sample Configuration: Cisco UCS, LDAP and Active Directory

Global VPN Client Getting Started Guide

Configuring Remote Access IPSec VPNs

Case Study - Configuration between NXC2500 and LDAP Server

TechNote. Configuring SonicOS for Amazon VPC

Sophos UTM. Remote Access via SSL. Configuring UTM and Client

Astaro Security Gateway V8. Remote Access via SSL Configuring ASG and Client

Use the below instructions to configure your wireless settings to connect to the secure wireless network using Microsoft Windows Vista/7.

Chapter 6 Basic Virtual Private Networking

Lab a Configure Remote Access Using Cisco Easy VPN

Configuring SSH Sentinel VPN client and D-Link DFL-500 Firewall

Configuration Guide. How to set up the IPSec site-to-site Tunnel between the D-Link DSR Router and the Sonicwall Firewall.

Configuring a Check Point FireWall-1 to SOHO IPSec Tunnel

VPN Configuration Guide SonicWALL with SonicWALL Simple Client Provisioning

VPN Configuration Guide. Cisco Small Business (Linksys) RV016 / RV042 / RV082

Viewing VPN Status, page 335. Configuring a Site-to-Site VPN, page 340. Configuring IPsec Remote Access, page 355

Configure an IPSec Tunnel between a Firebox Vclass & a Check Point FireWall-1

Creating a Gateway to Client VPN between Sidewinder G2 and a Mac OS X Client

Cisco RV 120W Wireless-N VPN Firewall

Transcription:

Nokia Mobile VPN How to configure Nokia Mobile VPN for Cisco ASA with PSK/xAuth authentication

Table of Contents Introduction... 3 Internal address pool configuration... 4 Creating VPN policies... 7 Creating a user for XAUTH authentication...11 Creating VPN client policy...13

Introduction This document explains the configuration of Cisco ASA for use with Nokia Mobile VPN Client, with instructions for Pre- Shared Key (PSK) and XAUTH authentication. The user group is authenticated by the PSK and the actual user is then authenticated by XAUTH (user name/password combination). It is assumed that the Cisco ASA basic configuration is in place. This covers any network-related configurations, such as inside and outside interface assignments, IP address configuration, hostname, domain, default routes and so on. This document uses Cisco ASA 5505 with software version 8.0(3). The configuration interface is Cisco ASDM (Adaptive Security Device Manager) version 6.1(1). These software updates are available from www.cisco.com.

Internal address pool configuration Navigate to Network (Client) Access -> Address Assignment -> Address Pools. Click Add to create a new address pool to be used for internal address assignment. Enter a name for the pool, starting and ending IP addresses, and the subnet mask. This address pool must not conflict with any other network object. Be careful to not define the addresses from the same range as any of the gateway interfaces. Click OK to close.

Navigate to Network (Client) Access -> Group Policies. Highlight the DfltGrpPolicy (System Default) and click Edit. Click Select to assign the address pool.

Select the previously defined IA_pool and click Assign. Click OK. Navigate to Servers. Enter the DNS server address in the DNS Servers field. This will be handed out to client. It allows internal DNS resolutions. Click OK to close the DfltGrpPolicy properties dialog.

Creating VPN policies Navigate to Network (Client) Access -> Advanced -> IPsec -> IKE Policies. Click Add to create a new IKE policy.

Enter the priority number for IKE policy. Encryption method default is DES, which is not very secure. It is recommended that you change it to AES-128. Hash algorithm is SHA, authentication PRE-SHARE, and D-H Group is 2 (by default it is set to 1). Click OK. Navigate to Network (Client) Access -> IPsec Connection Profiles. Check outside interface to Allow Access for IPsec access. Highlight DefaultRAGroup and click Edit.

In the IKE Peer Authentication section, enter the Pre-shared Key. This string can be anything, and it will be used as the password string for group authentication. It is recommended to configure this to be long enough with various alphanumeric characters (A-Z, 0-9) and possibly with special characters (!, %, &, #, etc). In the Identity Certificate, select the device certificate requested in earlier steps. In Client Address Assignment section, select the IA_pool created earlier for the Client Address Pools field.

Navigate to Advanced -> IPsec -> IKE Authentication on the left window pane. In the Default Mode pull-down menu, select XAUTH (Extended user authentication). Click OK.

Creating a user for XAUTH authentication Navigate to AAA/Local Users -> Local Users. Click Add to create a new user account.

Enter the Username and Password. Then Confirm Password. Add this user to belong to DefaultRAGroup under Member-of section. Click OK to create the user. This user account will be used for client XAUTH authentication. REMEMBER TO APPLY and SAVE THE CONFIGURATION TO THE GATEWAY!

Creating VPN client policy Start Nokia VPN Client Policy Tool and press the Load Template button. Select the Cisco_ASA_crack.pol policy from the Cisco\ASA directory.

Add the correct VPN gateway address and group password (must be the same that was defined on GW side, page 9). To export the VPN policy, press the Generate VPN Policy button, and store Cisco_ASA_pskxauth.vpn to your PC. Consult the Nokia Mobile VPN Client User s Guide, Chapter 6.1, for details on how to install a given policy file to your device.

Legal Notice Reproduction, transfer, distribution or storage of part or all of the contents in this document in any form without the prior written permission of Nokia is prohibited. Nokia and Nokia Connecting People are trademarks or registered trademarks of Nokia Corporation. Other product and company names mentioned herein may be trademarks or tradenames of their respective owners. Nokia operates a policy of continuous development. Nokia reserves the right to make changes and improvements to any of the products described in this document without prior notice. Under no circumstances shall Nokia be responsible for any loss of data or income or any special, incidental, consequential or indirect damages howsoever caused. The contents of this document are provided as is. Except as required by applicable law, no warranties of any kind, either express or implied, including, but not limited to, the implied warranties of merchantability and fitness for a particular purpose, are made in relation to the accuracy, reliability or contents of this document. Nokia reserves the right to revise this document or withdraw it at any time without prior notice. Work together. Smarter. Nokia Inc. 102 Corporate Park Drive, White Plains, NY 10604 USA Americas Tel: 1 877 997 9199 Email: usa@nokiaforbusiness.com Asia Pacific Tel: +65 6588 33 64 Email: asia@nokiaforbusiness.com Europe France +33 170 708 166 UK +44 161 601 8908 Email: europe@nokiaforbusiness.com Middle East and a Africa Dubai +971 4 3697600 Email: mea@nokiaforbusiness.com www.nokiaforbusiness.com 2008 Nokia. All rights reserved. Nokia and Nokia Connecting People are registered trademarks of Nokia Corporation. Other trademarks mentioned are the property of their respective owners. Nokia operates a policy of continuous development, therefore, reserves the right to make changes and improvements to any of the products described in this document without prior notice.