Добавил:
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:

Cisco Secure VPN Exam Certification Guide - Cisco press

.pdf
Скачиваний:
61
Добавлен:
24.05.2014
Размер:
19.64 Mб
Скачать

338 Chapter 7: Monitoring and Administering the VPN 3000 Series Concentrator

Foundation Summary

The Foundation Summary is a collection of tables and figures that provides a convenient review of many key concepts in this chapter. For those who are already comfortable with the topics in this chapter, this summary could help you recall a few details. For those who just read this chapter, this review should help solidify some key facts. For anyone doing final preparation before the exam, these tables and figures are a convenient way to review the day before the exam.

Administering the Cisco VPN 3000 Series

Concentrator

Figure 7-38 shows the main screen you will see after logging into the concentrator. This screen allows you to configure, administer, or monitor the concentrator.

Figure 7-38 Main Screen

Figure 7-39 shows the main administration screen, which you use to navigate between all the administration options.

Administering the Cisco VPN 3000 Series Concentrator 339

Figure 7-39 Administration Screen

Table 7-4 details the administration menu options.

Table 7-4

Administration Menu System

 

 

 

 

 

 

Menu Option

Level

Usage

 

 

 

 

 

Administration

1

Main screen for administering the VPN 3000 Concentrator. Enables all

 

 

 

of the Administration submenus.

 

 

 

 

 

Administer Sessions

2

Shows all the current sessions. Should you choose, you may filter the

 

 

 

sessions shown by group.

 

 

 

 

 

Software Update

2

Enables submenu, allowing you to choose to update either the

 

 

 

concentrator or clients.

 

 

 

 

 

Concentrator

3

Is used to update the concentrator to which you are currently

 

 

 

logged on.

 

 

 

 

 

Clients

3

Updates all the clients or clients based on groups.

 

 

 

 

 

System Reboot

2

Allows you to reboot the system either immediately or at a scheduled

 

 

 

time. This is also the screen used to reboot without using the current

 

 

 

configuration.

 

 

 

 

 

Ping

2

Allows you to check connectivity with a remote system by either name

 

 

 

or IP address.

 

 

 

 

 

Monitoring Refresh

2

Sets if the screens should automatically refresh and, if so, how often.

 

 

 

 

continues

340 Chapter 7: Monitoring and Administering the VPN 3000 Series Concentrator

Table 7-4

Administration Menu System (Continued)

 

 

 

 

 

Menu Option

Level

Usage

 

 

 

 

 

Access Rights

2

Enables submenu used for setting username/password/rights

 

 

 

combinations, Access-Control lists for configuring the concentrator,

 

 

 

setting session timeouts, and enables the submenu for AAA servers.

 

 

 

 

 

Administrators

3

Sets usernames, passwords, and rights.

 

 

 

 

 

Access Control List

3

Sets those IP addresses allowed to access the concentrator for

 

 

 

administration and configuration.

 

 

 

 

 

Access Settings

3

Sets the session timeouts, limits the number of connections, and allows

 

 

 

for encryption of the configuration file.

 

 

 

 

 

AAA Servers

3

Enables the submenu for setting the Authentication Servers.

 

 

 

 

 

Authentication

4

Allows the addition, modification, configuration, or deletion of

 

 

 

TACACS+ Servers.

 

 

 

 

 

File Management

2

Enables the submenu, allowing for swapping the backup and boot files,

 

 

 

file transfers using TFTP, file uploads using HTTP, and exporting the

 

 

 

configuration to an XML file.

 

 

 

 

 

Swap Config File

3

Allows swapping the boot and backup boot files.

 

 

 

 

 

TFTP Transfer

3

Allows uploading or downloading via a remote TFTP server.

 

 

 

 

 

File Upload

3

Allows uploading a file via HTTP.

 

 

 

 

 

XML Export

3

Allows a configuration file to be exported to an XML file.

 

 

 

 

 

Certificate Manager

2

Enables the submenu, allowing enrollment and installation of

 

 

 

Certificates.

 

 

 

 

 

Enrollment

3

Enrolls Certificates.

 

 

 

 

 

Installation

3

Installs Certificates.

 

 

 

 

Administer Sessions

Figure 7-40 presents the Administration | Administer Sessions screen, which shows the session statistics for all connected sessions. Filter the sessions by group using the Group pull-down menu.

Software Update 341

Figure 7-40 Administration | Administer Sessions

Software Update

The Administration | Software Update screen, shown in Figure 7-41, consists of the submenu options.

Figure 7-41 Administration | Software Update

342 Chapter 7: Monitoring and Administering the VPN 3000 Series Concentrator

Concentrator

The Administration | Software Update | Concentrator screen, seen in Figure 7-42, shows the current version of the software and allows you to upload a new version to the concentrator.

Figure 7-42 Administration | Software Update | Concentrator

Cisco strongly urges that you clear the browser’s cache, temporary files, and history files after updating.

Clients

The Administration | Software Update | Clients screen, shown in Figure 7-43, is used to update hardware and software clients when they become connected to the concentrator.

System Reboot 343

Figure 7-43 Administration | Software Update | Clients

System Reboot

The Administration | System Reboot screen, shown in Figure 7-44, allows you to reboot the system in a controlled manner.

Figure 7-44 Administration | System Reboot

344 Chapter 7: Monitoring and Administering the VPN 3000 Series Concentrator

Ping

The Administration | Ping screen, shown in Figure 7-45, is used to test connectivity.

Figure 7-45 Administration | Ping

Monitoring Refresh

The Administration | Monitoring Refresh screen is shown in Figure 7-46. The Enable check box sets whether the statistics screens should be refreshed. The statistics screens will be refreshed at the time (in seconds) specified by the refresh period. The default for the refresh period is 30 seconds.

Administrators 345

Figure 7-46 Administration | Monitoring Refresh

Access Rights

The Access Rights screen enables the submenu used for setting username, password and rights combinations, access control lists for configuring the concentrator, setting session timeouts, and enables the submenu for AAA servers.

Administrators

The Administration | Access Rights | Administrators screen is used to add those users who are allowed to access the concentrator’s Configuration, Administration, and Monitoring functions (see Figure 7-47). Up to five users may be allowed this type of access.

346 Chapter 7: Monitoring and Administering the VPN 3000 Series Concentrator

Figure 7-47 Administration | Access Rights | Administrators

Access Control List

The Administration | Access Rights | Access Control List screen allows for adding, modifying, and prioritizing access lists (see Figure 7-48). These access lists are used to determine those IP addresses that may access the concentrator for management functions.

Figure 7-48 Administration | Access Rights | Access Control List

Certificate Manager 347

Access Settings

The Administration | Access Rights | Access Settings screen sets the session idle timeout, sets the session limit, and enables configuration file encryption.

The Session Idle Timeout is entered in seconds. The maximum allowable time is 1800 seconds. The default is 600 seconds. The session limit default is 10 sessions. The configuration file may also be encrypted using the RC4 encryption algorithm.

AAA Servers

The Administration | AAA Servers screen is an entry screen used to navigate to the authentication screen.

Authentication

The Administration | AAA Servers | Authentication screen is used to add, modify, and test TACACS+ servers.

Remember that the Cisco VPN 3000 Series Concentrators only use TACACS+ for administrator authentication. There are no provisions for these concentrators to use RADIUS or TACACS for the authentication.

File Management

The Administration | File Management screen enables the submenu.

The submenu options are

Swap configuration files

TFTP transfers

File uploads

Export to XML

Certificate Manager

The Administration | Certificate Manager screen allows you to

See current certificates

Enroll certificates

Install certificates