Cisco Systems OL-16647-01 Network Router User Manual


  Open as PDF
of 1230
 
35-80
Cisco ASDM User Guide
OL-16647-01
Chapter 35 General
System Options
Add or Edit an IP Address Pool
Configures or modifies an IP address pool.
Fields
Name—Specifies the name assigned to the IP address pool.
Starting IP Address—Specifies the first IP address in the pool.
Ending IP Address—Specifies the last IP address in the pool.
Subnet Mask—Selects the subnet mask to apply to the addresses in the pool.
Modes
The following table shows the modes in which this feature is available:
Authenticating SSL VPN Connections
The SSL VPN Connections > Advanced > Authentication window lets you configure authentication
attributes for SSL VPN connections.
System Options
The System Options pane lets you configure features specific to VPN sessions on the security appliance.
Fields
Enable inbound IPSec sessions to bypass interface access-lists. Group policy and per-user
authorization access lists still apply to the traffic—By default, the security appliance allows VPN
traffic to terminate on a security appliance interface; you do not need to allow IKE or ESP (or other
types of VPN packets) in an access rule. When this option is checked, you also do not need an access
rule for local IP addresses of decrypted VPN packets. Because the VPN tunnel was terminated
successfully using VPN security mechanisms, this feature simplifies configuration and maximizes
the security appliance performance without any security risks. (Group policy and per-user
authorization access lists still apply to the traffic.)
Firewall Mode Security Context
Routed Transparent Single
Multiple
Context System
——
Firewall Mode Security Context
Routed Transparent Single
Multiple
Context System
——