Sunday, August 27, 2006

CISCO ASA User VPN definitions

*** ip pool management ***
ip local pool pool pool-prestataire-tata 192.168.1.200-192.168.1.210 mask 255.255.255.0


*** nat management ***
access-list inside_nonat0_outbound extended permit IP any 192.168.1.0 255.255.255.0
nat (inside) 0 access-list inside_nonat0_outbound


*** rights management ***
access-list prestataire-tata extended permit tcp 192.168.1.0 255.255.255.0 host 192.168.10.1 eq 3389


*** define tunnel group ***
tunnel-group prestataire-tata type ipsec-ra
tunnel-group prestataire-tata general-attributes
address-pool pool-prestataire-tata
tunnel-group prestataire-tata ipsec-attributes
pre-shared-key ******


*** group definition ***
group-policy prestataire-tata internal
group-policy prestataire-tata attributes
vpn-filter value prestataire-tata
vpn-tunnel-protocol IPSEC


*** define user and associate it the the group ***
username TATA password xxxxxxxxxxxxx encrypted privilege 0
username TATA attributes
vpn-group-policy prestataire-tata