Cisco Catalyst SD-WAN Remote Access Configuration Guide, Releases 26.x and Later

PDF

Cisco Catalyst SD-WAN Remote Access Configuration Guide, Releases 26.x and Later

Configure Cisco Catalyst SD-WAN remote access using a configuration group

Want to summarize with AI?

Log in

Configure Cisco SD-WAN remote access using the remote access feature in a configuration group.


Configure remote access capabilities for Cisco SD-WAN using configuration groups to enable secure connectivity for remote users.

Remote access configuration allows users to securely connect to the SD-WAN network from remote locations. This task uses configuration groups to deploy the Remote Access feature across multiple devices.

Before you begin

On the Configuration > Configuration Groups page, choose SD-WAN as the solution type.

Follow these steps to configure Cisco Catalyst SD-WAN Remote Access using a configuration group:

Procedure

1.

From the Cisco SD-WAN Manager menu, choose Configuration > Configuration Groups.

2.

Create and configure a remote access feature in a system profile.

  1. Configure remote access.

    Table 1. Remote Access Settings

    Field

    Description

    Type

    Choose Remote Access feature from the drop-down list.

    Feature Name*

    Enter a name for the feature.

    Description

    Enter a description of the feature. The description can contain any characters and spaces.

    Connection Type

    Choose the connection type from the following:

    • IPsec

    • SSL-VPN

    By default, IPsec is selected. We recommend using IPsec mode. SSL-VPN mode is supported only on Cisco Catalyst 8000v Edge Software with limited features.

  2. Configure authentication.

    Table 2. Authentication

    Field

    Description

    Radius Group Name

    Choose an existing RADIUS group or create a new RADIUS group.

    Click Add Radius Group to add a RADIUS server and group to the AAA feature profile in the System Profile.

    Pre-Shared Key (PSK) Authentication

    Enable Pre-Shared Key (PSK) authentication.

    • AAA-based-PSK: Choose this option to fetch the pre-shared keys from the RADIUS server. This option allows configuring a pre-shared key on the RADIUS server that is unique per remote access client or a group of remote access clients.

    • Groups PSK: Choose this option to configure a common pre-shared key for all remote access clients connecting to a device.

    Note

    Pre-Shared Key (PSK) Authentication is applicable only for connection-type IPsec and not for SSL-VPN.

    CA Server Setup

    Choose a CA server for certificate-based authentication. The certificate from the selected CA is used by the device to authenticate the remote access clients.

    Before choosing a CA server, configure the CA server from Configuration > Certificate Authority.

    User Authentication

    Choose the user authentication option for AnyConnect Extensible Authentication Protocol (EAP) authentication used by remote access client.

    Note

    The User Authentication setting is applicable only for the IPsec connection type and not for SSL-VPN.

    User & Device Authentication

    Choose the user and device authentication option for AnyConnect EAP authentication used by remote access client.

    The User & Device Authentication setting is applicable only for the IPsec connection type and not for SSL-VPN.

    Enable Profile Download

    Enable download of an AnyConnect profile XML file to Cisco AnyConnect clients from the remote access headend devices.

    In the Upload Profile XML File pane, choose an XML file or drag and drop to upload. The maximum file size is 20 KB.

  3. Configure AAA policy.

    Table 3. AAA Policy

    Field

    Description

    Specify Name

    Choose this option to specify the name of the policy to look up on the RADIUS server.

    In the Policy Name field, which appears only for the Specify Name option, enter the name of the policy.

    Derive Name from Peer Identity

    Choose this option to use the identity of the peer as the name of the policy to lookup on the RADIUS server.

    Note

    This setting is applicable only for the IPsec connection type and not for SSL-VPN.

    Derive Name from Peer Identity Domain

    Choose this option to use the domain portion of the identity of the peer as the name of the policy to look up on the RADIUS server.

    Note

    This setting is applicable only for the IPsec connection type and not for SSL-VPN.

    Policy Password

    Enter the policy password.

    Enable Accounting

    Enable accounting.

  4. Configure private IP-Pool.

    Table 4. Private IP-Pool

    Field

    Description

    Maximum Number of Clients

    Enter the maximum number of remote access clients that can connect to a remote access headend device. This number determines the size of the IPv4 pool allocated to the device.

    If a global IPv6 pool is defined for remote access in the network hierarchy, each SD-WAN RA headend device will be allocated an IPv6 pool sufficient for the maximum number of remote access clients (8000).

  5. Configure IKEv2 and IPsec settings.

    Table 5. IKEv2 and IPsec settings

    Field

    Description

    Local IKE Identity Type

    Enter the local IKEv2 identity type. The options are:

    • IPv4 Address or IPv6 Address

    • Email

    • FQDN

    • Key-ID

    Local IKE Identity Value*

    Enter the value of the local IKEv2 identity based on the identity type selected.

    Security Association (SA) Lifetime

    Enter the lifetime in seconds for the IKEv2 security association.

    The range is from 3600 to 86400. The default lifetime is 86400 seconds.

    Enable Anti - Denial of Service (DOS) Check

    Enable an Anti-Denial of Service (DOS) check.

    Anti-DOS Threshold

    Enter the Anti-DOS threshold value.

    Range: 10 to 1000.

    Default: 100.

The Remote Access feature is configured in the System Profile. Remote users can now securely connect to the SD-WAN network using the configured authentication and security settings.

What to do next

Also see Deploy a configuration group.