Cisco Systems, Inc.(R)    Cisco | Profile | Contacts & Feedback | Help
Cisco SMB Support Assistant
Configure Thin-Client SSL VPN (WebVPN) on a Cisco Router with Security Device Manager
Home > Work With My Routers > Cisco Routers > Configure Thin-Client SSL VPN (WebVPN) on a Cisco Router with Security Device Manager  
 

Configure Thin-Client SSL VPN (WebVPN) on a Cisco Router with Security Device Manager




Introduction

This document explains how to configure the Thin-Client SSL VPN (WebVPN) on a Cisco router and it applies to Cisco 1800, 2800 and 3800 Integrated Services Routers.

Thin-Client SSL VPN technology is used to allow secure access for applications that uses static ports. The Thin-Client can be a user-driven, policy-driven, or both. Access can be configured on a user-by-user basis, or group policies can be created that include one or more users.

For example Internet Mail Access Protocol (IMAP) or Simple Mail Transfer Protocol (SMTP) servers requires workstations to run client applications in order to send and receive e-mail. The Thin-Client feature, also known as port forwarding, allows a small applet to be downloaded along with the portal so that a remote workstation can communicate with the intranet server.


Back to Top



Requirements

To perform the steps described in this document, you need to have these items:

  • You must have completed the Configure Your Router with Security Device Manager document.

  • You must have completed the Set Up Internet Security on a Cisco Router document.

  • Router which runs an advance image of Cisco IOS Software Release 12.4 (6) T or later and Security Device Manager (SDM) - version 2.3.1 or later

  • Completed worksheets from the Site Survey:

    1. Internet Worksheet

    2. LAN Addressing Worksheet

  • Requirements for Client computers:

    1. Remote clients must have a local administrative privileges. It is not required, but it is highly suggested.

    2. Remote clients must have Java Runtime Environment (JRE) Version 1.4 or higher.

    3. Remote client browsers: Internet Explorer 6.0, Netscape 7.1, Mozilla 1.7, Safari 1.2.2, or Firefox 1.0

    4. Cookies enabled and popup allowed on remote clients


Back to Top



Configure Thin-Client SSL VPN on a Router

Follow these steps to configure a Thin-Client SSL VPN on your router:

The SSL VPN gateway provides the IP address and the digital certificate for the SSL VPN contexts that use it. Follow these steps to configure the SSL VPN Gateway:

  1. Open a web browser and type http:// router-IP-address in the Address field. Use the IP address that you entered in field L6A of the LAN Addressing Worksheet. Press Enter to launch SDM. For more information about how to launch SDM, refer to Configure your Router with Security Device Manager.

  2. Click Configure.

    config_thinclient_SSLVPN_on_router_SDM_01.gif

  3. Click VPN.

    config_thinclient_SSLVPN_on_router_SDM_02.gif

  4. On the VPN Screen, click SSL VPN.

    config_thinclient_SSLVPN_on_router_SDM_03.gif

  5. On the Create SSL VPN screen under Prerequisite Tasks, click on EnableAAA link.

    config_thinclient_SSLVPN_on_router_SDM_04.gif

  6. On the Enable AAA warning window, click Yes.

    config_thinclient_SSLVPN_on_router_SDM_05.gif

  7. On the Commands Delivery Status window, click OK.

    config_thinclient_SSLVPN_on_router_SDM_06.gif

  8. Click OK in the Information window.

    config_thinclient_SSLVPN_on_router_SDM_07.gif

  9. On the Create SSL VPN screen, select the radio button next to Create a new SSL VPN and click on Launch the selected task box at the bottom of the screen.

    config_thinclient_SSLVPN_on_router_SDM_08.gif

  10. On the Welcome to the Create SSL VPN Wizard screen, click Next.

    config_thinclient_SSLVPN_on_router_SDM_09.gif

  11. On the IP address and Name wizard, enter these values:

    1. Next to IP Address field, enter the IP Address which the SSL VPN clients use to connect to the SSL VPN Gateway or portal page.

    2. Next to Name field, enter the descriptive name for the SSL VPN Gateway.

    3. In the Domain field, enter your domain name.

    4. Click Next.

    config_thinclient_SSLVPN_on_router_SDM_10.gif

  12. On the User Authentication screen, select the radio button Locally on this router and click Add to add a new user.

    Note: You can also use an External Authentication, Authorization, and Accounting (AAA) server. Contact SMB TAC for further assistance.

    config_thinclient_SSLVPN_on_router_SDM_11.gif

  13. In the Add an Account window, enter these values:

    1. Enter a user name in the Username field.

    2. Enter the password in the New Password field and re-enter the same in Confirm New Password field.

    3. Select the Privilege level for the user from the drop-down menu in the Privilege level field.

    4. Click OK.

    config_thinclient_SSLVPN_on_router_SDM_12.gif

  14. Click Next.

    config_thinclient_SSLVPN_on_router_SDM_13.gif

  15. On the Configure Intranet Websites screen, click Next.

    config_thinclient_SSLVPN_on_router_SDM_14.gif

  16. Uncheck Enable Full Tunnel. Click Next.

    config_thinclient_SSLVPN_on_router_SDM_15.gif

  17. Customize the appearance of the WebVPN portal page or accept the default appearance. Click Next.

    config_thinclient_SSLVPN_on_router_SDM_16.gif

  18. On the Summary of the Configuration screen, click Finish.

    config_thinclient_SSLVPN_on_router_SDM_17.gif

  19. On the Commands Delivery Status window, click OK.

    config_thinclient_SSLVPN_on_router_SDM_18.gif


Back to Top



Configure the Thin-Client ports

You have created a WebVPN Gateway and a WebVPN Context with a linked Group Policy.

Follow these steps to configure the Thin-Client ports, which are made available when clients connect to the WebVPN:

  1. Click Configure, and click VPN.

  2. Click on SSL VPN, and click the Create SSL VPN tab.

  3. On the Create SSL VPN screen, select the radio button next to Configure advance features for an existing SSL VPN and click on Launch the selected task box at the bottom of the screen.

    config_thinclient_SSLVPN_on_router_SDM_19.gif

  4. On the Welcome to the Advance SSL VPN Wizard screen, click Next.

    config_thinclient_SSLVPN_on_router_SDM_20.gif

  5. Choose the SSL VPN context name and user group name from the drop-down menus. Click Next.

    config_thinclient_SSLVPN_on_router_SDM_21.gif

  6. Choose Thin Client (Port Forwarding) and click Next.

    config_thinclient_SSLVPN_on_router_SDM_22.gif

  7. On the Thin Client (Port Forwarding) screen, click Add.

    config_thinclient_SSLVPN_on_router_SDM_23.gif

  8. In the Add Port Forwarding Server window, enter the resources that you want to make available through Port Forwarding. The service port must be a static port, but you can accept the default port on the client PC assigned by the Wizard.

    1. In the Server IP Address field, enter the IP Address Email Server

    2. In the Server port on which service is listening field, enter port number 25 for Email service.

    3. In the description field, enter the descriptive word for the Email service.

    4. Click OK.

    config_thinclient_SSLVPN_on_router_SDM_24.gif

  9. Click Next.

    config_thinclient_SSLVPN_on_router_SDM_25.gif

  10. On the Summary of the Configuration screen, click Finish.

    config_thinclient_SSLVPN_on_router_SDM_26.gif

  11. On the Commands Delivery Status window, click OK.

    config_thinclient_SSLVPN_on_router_SDM_27.gif

  12. Click Save, and click Yes to accept the changes.


Back to Top



Next Step

You have completed this procedure.

To make further changes to the router, refer to the Router Support Page.

To configure other devices in your network, refer to the Configuration Overview Page.


Back to Top



Troubleshoot the Procedure

This section provides information about common problems that you may encounter. If this information does not solve your problem, contact the SMB Technical Assistance Center (SMB TAC) for assistance.

Problem

Cause(s) and Suggested Solution(s)

You are unable to connect to the router with Security Device Manager (SDM).

Refer to Configure Your Router with Security Device Manager.


Back to Top



Related Information

Service Requests

  Open a service request
  Update a service request

Feedback

Please rate this site:
++ + +/- - --

Suggestions for improvement:




If Cisco may contact you for more details
or for future feedback opportunities,
please enter your contact information:

Full Name:
Email:



© 1992-2006 Cisco Systems, Inc. All rights reserved. Terms and Conditions, Privacy Statement, Cookie Policy and Trademarks of Cisco Systems, Inc.