VPN 3000 Series Concentrator Reference Volume II: Administration and Monitoring Release 3.6 August 2002
Total Page:16
File Type:pdf, Size:1020Kb
VPN 3000 Series Concentrator Reference Volume II: Administration and Monitoring Release 3.6 August 2002 Corporate Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387) Fax: 408 526-4100 Customer Order Number: DOC-7814742= Text Part Number: 78-14742-01 THE SPECIFICATIONS AND INFORMATION REGARDING THE PRODUCTS IN THIS MANUAL ARE SUBJECT TO CHANGE WITHOUT NOTICE. ALL STATEMENTS, INFORMATION, AND RECOMMENDATIONS IN THIS MANUAL ARE BELIEVED TO BE ACCURATE BUT ARE PRESENTED WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. USERS MUST TAKE FULL RESPONSIBILITY FOR THEIR APPLICATION OF ANY PRODUCTS. THE SOFTWARE LICENSE AND LIMITED WARRANTY FOR THE ACCOMPANYING PRODUCT ARE SET FORTH IN THE INFORMATION PACKET THAT SHIPPED WITH THE PRODUCT AND ARE INCORPORATED HEREIN BY THIS REFERENCE. IF YOU ARE UNABLE TO LOCATE THE SOFTWARE LICENSE OR LIMITED WARRANTY, CONTACT YOUR CISCO REPRESENTATIVE FOR A COPY. The Cisco implementation of TCP header compression is an adaptation of a program developed by the University of California, Berkeley (UCB) as part of UCB’s public domain version of the UNIX operating system. All rights reserved. Copyright © 1981, Regents of the University of California. NOTWITHSTANDING ANY OTHER WARRANTY HEREIN, ALL DOCUMENT FILES AND SOFTWARE OF THESE SUPPLIERS ARE PROVIDED “AS IS” WITH ALL FAULTS. CISCO AND THE ABOVE-NAMED SUPPLIERS DISCLAIM ALL WARRANTIES, EXPRESSED OR IMPLIED, INCLUDING, WITHOUT LIMITATION, THOSE OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OR ARISING FROM A COURSE OF DEALING, USAGE, OR TRADE PRACTICE. IN NO EVENT SHALL CISCO OR ITS SUPPLIERS BE LIABLE FOR ANY INDIRECT, SPECIAL, CONSEQUENTIAL, OR INCIDENTAL DAMAGES, INCLUDING, WITHOUT LIMITATION, LOST PROFITS OR LOSS OR DAMAGE TO DATA ARISING OUT OF THE USE OR INABILITY TO USE THIS MANUAL, EVEN IF CISCO OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. CCIP, the Cisco Arrow logo, the Cisco Powered Network mark, the Cisco Systems Verified logo, Cisco Unity, Follow Me Browsing, FormShare, Internet Quotient, iQ Breakthrough, iQ Expertise, iQ FastTrack, the iQ Logo, iQ Net Readiness Scorecard, Networking Academy, ScriptShare, SMARTnet, TransPath, and Voice LAN are trademarks of Cisco Systems, Inc.; Changing the Way We Work, Live, Play, and Learn, Discover All That’s Possible, The Fastest Way to Increase Your Internet Quotient, and iQuick Study are service marks of Cisco Systems, Inc.; and Aironet, ASIST, BPX, Catalyst, CCDA, CCDP, CCIE, CCNA, CCNP, Cisco, the Cisco Certified Internetwork Expert logo, Cisco IOS, the Cisco IOS logo, Cisco Press, Cisco Systems, Cisco Systems Capital, the Cisco Systems logo, Empowering the Internet Generation, Enterprise/Solver, EtherChannel, EtherSwitch, Fast Step, GigaStack, IOS, IP/TV, LightStream, MGX, MICA, the Networkers logo, Network Registrar, Packet, PIX, Post-Routing, Pre-Routing, RateMUX, Registrar, SlideCast, StrataView Plus, Stratm, SwitchProbe, TeleRouter, and VCO are registered trademarks of Cisco Systems, Inc. and/or its affiliates in the U.S. and certain other countries. All other trademarks mentioned in this document or Web site are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (0206R) VPN 3000 Series Concentrator Reference Volume II: Administration Copyright © 2002, Cisco Systems, Inc. All rights reserved. CONTENTS Preface ix Audience ix Prerequisites x Organization x Related Documentation xii Conventions xiv Obtaining Documentation xvi Obtaining Technical Assistance xvii PART 1 Administration CHAPTER 1 Administration 1-1 Administration 1-1 CHAPTER 2 Administer Sessions 2-1 Administer Sessions 2-1 Administer Sessions | Detail 2-8 Administer Sessions | Detail Parameters 2-9 CHAPTER 3 Software Update 3-1 Software Update 3-1 Software Update | Concentrator 3-2 Software Update | Clients 3-5 CHAPTER 4 System Reboot 4-1 System Reboot 4-1 CHAPTER 5 Ping 5-1 Ping 5-1 CHAPTER 6 Monitoring Refresh 6-1 Monitoring Refresh 6-1 VPN 3000 Series Concentrator Reference Volume II: Administration and Monitoring 78-14742-01 iii Contents CHAPTER 7 Access Rights 7-1 Access Rights 7-1 Access Rights | Administrators 7-2 Access Rights | Administrators | Modify Properties 7-4 Access Rights | Access Control List 7-7 Access Rights | Access Control List | Add or Modify 7-9 Access Rights | Access Settings 7-11 Access Rights | AAA Servers 7-13 Access Rights | AAA Servers | Authentication 7-14 Access Rights | AAA Servers | Authentication | Add or Modify 7-16 Access Rights | AAA Servers | Test 7-18 CHAPTER 8 File Management 8-1 File Management 8-1 File Management | Swap Configuration Files 8-4 File Management | TFTP Transfer 8-5 File Management | File Upload 8-8 File Management | XML Export 8-11 CHAPTER 9 Certificate Management 9-1 Enrolling and Installing Digital Certificates 9-2 Enabling CRL Checking and Caching 9-6 Enrolling and Installing Identity Certificates 9-8 Obtaining SSL Certificates 9-16 Enabling Digital Certificates on the VPN Concentrator 9-17 Deleting Digital Certificates 9-26 Certificate Management 9-27 Certificate Management | Enroll 9-33 Certificate Management | Enroll | Certificate Type 9-34 Certificate Management | Enroll | Certificate Type | PKCS10 9-35 Certificate Management | Enrollment or Renewal | Request Generated 9-36 Certificate Management | Enroll | Identity Certificate | SCEP 9-38 Certificate Management | Enroll | SSL Certificate | SCEP 9-39 Certificate Management | Install 9-41 Certificate Management | Install | Certificate Obtained via Enrollment 9-42 Certificate Management | Install | Certificate Type 9-43 VPN 3000 Series Concentrator Reference Volume II: Administration and Monitoring iv 78-14742-01 Contents Certificate Management | Install | CA Certificate | SCEP 9-44 Certificate Management | Install | Certificate Type | Cut and Paste Text 9-45 Certificate Management | Install | Certificate Type | Upload File from Workstation 9-46 Certificate Management | Configure SCEP 9-47 Certificate Management | View CRL Cache 9-48 Certificate Management | View 9-50 Certificate Management | Configure CA Certificate 9-53 Certificate Management | Renewal 9-58 Certificate Management | Activate or Re-Submit | Status 9-60 Certificate Management | Delete 9-61 Certificate Management | View Enrollment Request 9-63 Certificate Management | Cancel Enrollment Request 9-65 Certificate Management | Delete Enrollment Request 9-66 PART 2 Monitoring CHAPTER 10 Monitoring 10-1 Monitoring 10-1 CHAPTER 11 Routing Table 11-1 Routing Table 11-1 CHAPTER 12 Filterable Event Log 12-1 Filterable Event Log 12-1 Live Event Log 12-6 CHAPTER 13 System Status 13-1 System Status 13-1 System Status | Ethernet Interface 13-5 System Status | Power 13-8 System Status | SEP 13-10 System Status | LED Status 13-16 VPN 3000 Series Concentrator Reference Volume II: Administration and Monitoring 78-14742-01 v Contents CHAPTER 14 Sessions 14-1 Sessions 14-1 Sessions | Detail 14-7 Sessions | Protocols 14-11 Sessions | SEPs 14-14 Sessions | Encryption 14-16 Sessions | Top Ten Lists 14-18 Sessions | Top Ten Lists | Data 14-19 Sessions | Top Ten Lists | Duration 14-22 Sessions | Top Ten Lists | Throughput 14-25 CHAPTER 15 Statistics 15-1 Statistics 15-1 Statistics | Accounting 15-3 Statistics | Address Pools 15-5 Statistics | Administrative AAA 15-7 Statistics | Authentication 15-9 Statistics | Authentication | Replicas 15-12 Statistics | Bandwidth Management 15-14 Statistics | Compression 15-16 Statistics | DHCP 15-20 Statistics | DNS 15-22 Statistics | Events 15-24 Statistics | Filtering 15-26 Statistics | HTTP 15-28 Statistics | IPSec 15-31 Statistics | L2TP 15-38 Statistics | Load Balancing 15-42 Statistics | NAT 15-44 Statistics | PPTP 15-47 Statistics | SSH 15-51 Statistics | SSL 15-52 Statistics | Telnet 15-54 Statistics | VRRP 15-56 Statistics | MIB-II 15-59 VPN 3000 Series Concentrator Reference Volume II: Administration and Monitoring vi 78-14742-01 Contents Statistics | MIB-II | Interfaces 15-60 Statistics | MIB-II | TCP/UDP 15-62 Statistics | MIB-II | IP 15-65 Statistics | MIB-II | RIP 15-68 Statistics | MIB-II | OSPF 15-70 Statistics | MIB-II | ICMP 15-76 Statistics | MIB-II | ARP Table 15-79 Statistics | MIB-II | Ethernet 15-81 Statistics | MIB-II | SNMP 15-84 APPENDIX A Using the Command-Line Interface A-1 Accessing the CLI A-2 Starting the CLI A-4 Using the CLI A-5 CLI Menu Reference A-10 APPENDIX B Troubleshooting and System Errors B-1 Files for Troubleshooting B-1 VPN Concentrator Manager Errors B-2 Command-Line Interface Errors B-5 LED Indicators B-6 APPENDIX C Copyrights, Licenses, and Notices C-1 Software License Agreement of Cisco Systems, Inc. C-1 Other Licenses C-3 Regulatory Standards Compliance C-10 I NDEX VPN 3000 Series Concentrator Reference Volume II: Administration and Monitoring 78-14742-01 vii Contents VPN 3000 Series Concentrator Reference Volume II: Administration and Monitoring viii 78-14742-01 Preface The VPN Concentrator provides an HTML-based graphic interface, called the VPN Concentrator Manager, that allows you to configure, administer, and monitor your device easily. The VPN Concentrator Manager has three sets of screens that correspond to these tasks: Configuration screens, Administration screens, and Monitoring screens. VPN 3000 Series Concentrator Reference Volume II: Administration and Monitoring is the second in the two volume VPN 3000 Series Concentrator Reference. Together, both