Cisco Catalyst SD-WAN Remote Access Configuration Guide, Releases 26.x and Later

PDF

Cisco Catalyst SD-WAN Remote Access Configuration Guide, Releases 26.x and Later

Configure Cisco Catalyst SD-WAN remote access using a configuration group

Want to summarize with AI?

Log in

Configure Cisco SD-WAN remote access using the remote access feature in a configuration group.


Configure remote access capabilities for Cisco SD-WAN using configuration groups to enable secure connectivity for remote users.

Remote access configuration allows users to securely connect to the SD-WAN network from remote locations. This task uses configuration groups to deploy the Remote Access feature across multiple devices.

Before you begin

On the Configuration > Configuration Groups page, choose SD-WAN as the solution type.

Follow these steps to configure Cisco Catalyst SD-WAN Remote Access using a configuration group:

Procedure

  1. From the Cisco SD-WAN Manager menu, choose Configuration > Configuration Groups.

  2. Create and configure a remote access feature in a system profile.

    1. Configure remote access.

      Table 1. Remote Access Settings

      Field

      Description

      Type

      Choose Remote Access feature from the drop-down list.

      Feature Name*

      Enter a name for the feature.

      Description

      Enter a description of the feature. The description can contain any characters and spaces.

      Connection Type

      Choose the connection type from the following:

      • IPsec

      • SSL-VPN

      By default, IPsec is selected. We recommend using IPsec mode. SSL-VPN mode is supported only on Cisco Catalyst 8000v Edge Software with limited features.

    2. Configure authentication.

      Table 2. Authentication

      Field

      Description

      Radius Group Name

      Choose an existing RADIUS group or create a new RADIUS group.

      Click Add Radius Group to add a RADIUS server and group to the AAA feature profile in the System Profile.

      Pre-Shared Key (PSK) Authentication

      Enable Pre-Shared Key (PSK) authentication.

      • AAA-based-PSK: Choose this option to fetch the pre-shared keys from the RADIUS server. This option allows configuring a pre-shared key on the RADIUS server that is unique per remote access client or a group of remote access clients.

      • Groups PSK: Choose this option to configure a common pre-shared key for all remote access clients connecting to a device.

      Note

      Pre-Shared Key (PSK) Authentication is applicable only for connection-type IPsec and not for SSL-VPN.

      CA Server Setup

      Choose a CA server for certificate-based authentication. The certificate from the selected CA is used by the device to authenticate the remote access clients.

      Before choosing a CA server, configure the CA server from Configuration > Certificate Authority.

      User Authentication

      Choose the user authentication option for AnyConnect Extensible Authentication Protocol (EAP) authentication used by remote access client.

      Note

      The User Authentication setting is applicable only for the IPsec connection type and not for SSL-VPN.

      User & Device Authentication

      Choose the user and device authentication option for AnyConnect EAP authentication used by remote access client.

      The User & Device Authentication setting is applicable only for the IPsec connection type and not for SSL-VPN.

      Enable Profile Download

      Enable download of an AnyConnect profile XML file to Cisco AnyConnect clients from the remote access headend devices.

      In the Upload Profile XML File pane, choose an XML file or drag and drop to upload. The maximum file size is 20 KB.

    3. Configure AAA policy.

      Table 3. AAA Policy

      Field

      Description

      Specify Name

      Choose this option to specify the name of the policy to look up on the RADIUS server.

      In the Policy Name field, which appears only for the Specify Name option, enter the name of the policy.

      Derive Name from Peer Identity

      Choose this option to use the identity of the peer as the name of the policy to lookup on the RADIUS server.

      Note

      This setting is applicable only for the IPsec connection type and not for SSL-VPN.

      Derive Name from Peer Identity Domain

      Choose this option to use the domain portion of the identity of the peer as the name of the policy to look up on the RADIUS server.

      Note

      This setting is applicable only for the IPsec connection type and not for SSL-VPN.

      Policy Password

      Enter the policy password.

      Enable Accounting

      Enable accounting.

    4. Configure private IP-Pool.

      Table 4. Private IP-Pool

      Field

      Description

      Maximum Number of Clients

      Enter the maximum number of remote access clients that can connect to a remote access headend device. This number determines the size of the IPv4 pool allocated to the device.

      If a global IPv6 pool is defined for remote access in the network hierarchy, each SD-WAN RA headend device will be allocated an IPv6 pool sufficient for the maximum number of remote access clients (8000).

    5. Configure IKEv2 and IPsec settings.

      Table 5. IKEv2 and IPsec settings

      Field

      Description

      Local IKE Identity Type

      Enter the local IKEv2 identity type. The options are:

      • IPv4 Address or IPv6 Address

      • Email

      • FQDN

      • Key-ID

      Local IKE Identity Value*

      Enter the value of the local IKEv2 identity based on the identity type selected.

      Security Association (SA) Lifetime

      Enter the lifetime in seconds for the IKEv2 security association.

      The range is from 3600 to 86400. The default lifetime is 86400 seconds.

      Enable Anti - Denial of Service (DOS) Check

      Enable an Anti-Denial of Service (DOS) check.

      Anti-DOS Threshold

      Enter the Anti-DOS threshold value.

      Range: 10 to 1000.

      Default: 100.

The Remote Access feature is configured in the System Profile. Remote users can now securely connect to the SD-WAN network using the configured authentication and security settings.

What to do next

Also see Deploy a configuration group.