Cisco ASA SSL VPN 实验
拓扑图
file:///C:/Users/ADMINI~1/AppData/Local/Temp/ksohtml/wps_clip_image-32072.png
1、SSL VPN基本配置
interface Ethernet0/0
nameif outside
security-level 0
ip address 198.1.1.1 255.255.255.0
!
interface Ethernet0/1
nameif inside
security-level 100
ip address 172.30.1.97 255.255.255.0
!
ip local pool ssl-user 192.168.12.1-192.168.12.254
!
access-list go-vpn extended permit ip 172.30.1.0 255.255.255.0 192.168.12.0 255.255.255.0
!
global (outside) 1 interface
nat (inside) 0 access-list go-vpn
nat (inside) 1 172.30.1.0 255.255.255.0
route outside 0.0.0.0 0.0.0.0 198.1.1.2 1
!
username wanglinlin password kc0imQBKBLfYhNFb encrypted
!
group-policy mysslvpn-group-policy internal
group-policy mysslvpn-group-policy attributes
vpn-tunnel-protocol webvpn
webvpn
svc enable
!
tunnel-group mysslvpn-group type webvpn
tunnel-group mysslvpn-group general-attributes
address-pool ssl-user
default-group-policy mysslvpn-group-policy
tunnel-group mysslvpn-group webvpn-attributes
group-alias mysslvpn enable
!
webvpn
enable outside
svc image disk0:/sslclient-win-1.1.1.164.pkg 1
svc enable
tunnel-group-list enable
2、开启隧道分离
access-list split-ssl extended permit ip 172.30.1.0 255.255.255.0 any
!
group-policy mysslvpn-group-policy attributes
split-tunnel-policy tunnelspecified
split-tunnel-network-list value split-ssl
手记:这个实验花了我半天时间,隧道分离总起不来,万分无奈之下只有将ssl vpn client升级,结果居然成功了!原本使用的SVC版本为:sslclient-win-1.1.0.154.pkg
下面放出SSL VPN Client的用户界面
file:///C:/Users/ADMINI~1/AppData/Local/Temp/ksohtml/wps_clip_image-26474.png
file:///C:/Users/ADMINI~1/AppData/Local/Temp/ksohtml/wps_clip_image-13811.png
该贴已经同步到 小乔的微博 |