Configure Cisco SD-WAN remote access using the remote access feature in a configuration group.
Remote access configuration allows users to securely connect to the SD-WAN network from remote locations. This task uses configuration groups to deploy the Remote Access feature across multiple devices.
Before you begin
On the page, choose SD-WAN as the solution type.
Follow these steps to configure Cisco Catalyst SD-WAN Remote Access using a configuration group:
Procedure
|
1. |
From the Cisco SD-WAN Manager menu, choose . |
|
2. |
Create and configure a remote access feature in a system profile.
-
Configure remote access.
Table 1.
Remote Access Settings
| Field |
Description |
| Type |
Choose Remote Access feature from the drop-down list. |
| Feature Name* |
Enter a name for the feature. |
| Description |
Enter a description of the feature. The description can contain any characters and spaces. |
| Connection Type |
Choose the connection type from the following:
By default, IPsec is selected. We recommend using IPsec mode. SSL-VPN mode is supported only on Cisco Catalyst 8000v Edge Software with limited features. |
-
Configure authentication.
Table 2.
Authentication
| Field |
Description |
| Radius Group Name |
Choose an existing RADIUS group or create a new RADIUS group. Click Add Radius Group to add a RADIUS server and group to the AAA feature profile in the System Profile. |
| Pre-Shared Key (PSK) Authentication |
Enable Pre-Shared Key (PSK) authentication.
-
AAA-based-PSK: Choose this option to fetch the pre-shared keys from the RADIUS server. This option allows configuring a pre-shared key on the RADIUS server that is unique per remote access client or a group of remote access clients.
-
Groups PSK: Choose this option to configure a common pre-shared key for all remote access clients connecting to a device.
Note
Pre-Shared Key (PSK) Authentication is applicable only for connection-type IPsec and not for SSL-VPN.
|
| CA Server Setup |
Choose a CA server for certificate-based authentication. The certificate from the selected CA is used by the device to authenticate the remote access clients. Before choosing a CA server, configure the CA server from . |
| User Authentication |
Choose the user authentication option for AnyConnect Extensible Authentication Protocol (EAP) authentication used by remote access client.
Note
The User Authentication setting is applicable only for the IPsec connection type and not for SSL-VPN.
|
| User & Device Authentication |
Choose the user and device authentication option for AnyConnect EAP authentication used by remote access client. The User & Device Authentication setting is applicable only for the IPsec connection type and not for SSL-VPN. |
| Enable Profile Download |
Enable download of an AnyConnect profile XML file to Cisco AnyConnect clients from the remote access headend devices. In the Upload Profile XML File pane, choose an XML file or drag and drop to upload. The maximum file size is 20 KB. |
-
Configure AAA policy.
Table 3.
AAA Policy
| Field |
Description |
| Specify Name |
Choose this option to specify the name of the policy to look up on the RADIUS server. In the Policy Name field, which appears only for the Specify Name option, enter the name of the policy. |
| Derive Name from Peer Identity |
Choose this option to use the identity of the peer as the name of the policy to lookup on the RADIUS server.
Note
This setting is applicable only for the IPsec connection type and not for SSL-VPN.
|
| Derive Name from Peer Identity Domain |
Choose this option to use the domain portion of the identity of the peer as the name of the policy to look up on the RADIUS server.
Note
This setting is applicable only for the IPsec connection type and not for SSL-VPN.
|
| Policy Password |
Enter the policy password. |
| Enable Accounting |
Enable accounting. |
-
Configure private IP-Pool.
Table 4.
Private IP-Pool
| Field |
Description |
| Maximum Number of Clients |
Enter the maximum number of remote access clients that can connect to a remote access headend device. This number determines the size of the IPv4 pool allocated to the device. If a global IPv6 pool is defined for remote access in the network hierarchy, each SD-WAN RA headend device will be allocated an IPv6 pool sufficient for the maximum number of remote access clients (8000). |
-
Configure IKEv2 and IPsec settings.
|