Home > Security Tips > > Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys


Written by John Roland and Mark Newcomb; Published by Cisco Press
06.09.2003
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


The following excerpt is from chapter four, Configuring Cisco VPN 3000 for Remote Access Using Preshared Keys, of CCSP Cisco Secure VPN Exam Certification Guide (CCSP Self-Study), written by John Roland and Mark Newcomb, and published by Cisco Press.


Using VPNs for remote access with preshared keys

For site-to-site VPN connections, peer devices must authenticate one another before IPSec communications can occur. In addition to requiring device authentication, remote access VPN connections require user authentication to make certain that the user is permitted to use the applications that are protected by the IPSec connection.

User authentication can be handled in a variety of ways. You can configure Remote Authentication Dial-In User Service (RADIUS), NT Domain, and Security Dynamics International (SDI) authentication on most Cisco devices, and the VPN 3000 Concentrators have the additional ability to authenticate users through an internal database.

If you want to use internal authentication, create a username and password for each user and assign the users to the group that is to be used for IPSec device authentication. Once the devices have established the IPSec tunnel, the user is prompted to enter a username and password to continue. Failure to authenticate causes the tunnel to drop. A similar login prompt is displayed if you are using RADIUS, NT Domain, or SDI authentication.

You can establish device authentication by using either preshared keys or digital certificates. (For more information, see Chapter 5, "Configuring Cisco VPN 3000 for Remote Access Using Digital Certificates.") With preshared keys, the system administrator chooses the key and then shares that key with users or other system administrators. Combining a preshared key with some other metric establishes three different uses for preshared keys, as follows:

  • Unique
  • Group
  • Wildcard

The following sections describe each type of preshared key in more detail.

Unique preshared keys

When a preshared key is tied to a specific IP address, the combination makes the preshared key unique. Only the peer with the correct IP address can establish an IPSec session using this key. Ideal for site-to-site VPNs where the identity of the peer devices is always known, unique preshared keys are not recommended for remote access VPNs. Unique preshared keys scale particularly poorly because each new user requires a new key and the administrative burden that entails.

While this type of preshared key is the most secure of the three types, it is not practical for remote access applications, where users are typically connecting through a commercial Internet service provider (ISP). Most users are not willing to pay for the luxury of a permanently assigned IP address from their ISP and are assigned an IP address from an available pool of addresses when they connect to the service. If you had a large installed base of VPN users, keeping up with these dynamically assigned IP addresses to provide this level of security would be a maintenance nightmare.

Group preshared keys

If you begin using unique preshared keys, at some point you can decide to just use the same password for discrete groups of users. If you decide to do that, and shed the association with the IP address, you have begun to use the next type of preshared key, the group preshared key. A group preshared key is simply a shared key that is associated with a specific group. In a VPN 3000 Concentrator configuration, the group can be the Base Group or any other group that you define.

A group preshared key is well suited for remote access VPNs and is the method used by Cisco VPN 3000 Concentrators. It is good practice to use groups to establish Internet Key Exchange (IKE) and IPSec settings and to provide other capabilities that are unique to a specific set of users. If you choose to use the Cisco VPN 3000 Concentrator's internal database for user authentication, you can assign your users to specific groups, making the process of managing preshared keys much easier.

Wildcard preshared keys

The final type of preshared key classification is the wildcard preshared key. This type of key does not have an IP address or group assigned to it and can be used by any device holding the key to establish an IPSec connection with your VPN concentrator. When you set up your concentrator to use wildcard preshared keys, every device connecting to the concentrator must also use preshared keys. If any device is compromised, you must change the key for all the devices in your network. This type of key is also open to man-in-the-middle attacks and should not be used for site-to-site applications.


Read the rest of this chapter.

Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Secure VPN Setup and Configuration,   Enterprise Network Security,   IPsec VPN Security,   NAC and Endpoint Security Management,   Secure Remote Access,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
IPsec VPN Security
Best Remote Access Products
How to set up a split-tunnel VPN in Windows Vista
What is the difference between a VPN and remote control?
A short enterprise VPN deployment guide
From the ground up: Creating secure WLANs
Can S/MIME, XML and IPsec operate in one protocol layer?
How to create a secure network through a shared Internet connection
What firewall controls should be placed on the VPN?
VoIP tools, attacks could increase threat
Best practices for processing financial data through remote servers
IPsec VPN Security Research

Secure Remote Access
Endpoint protection best practices manual: Combating issues, problems
Best Mobile Data Security Products
Perimeter defense in the era of the perimeterless network
Securing the intranet with remote access VPN security
What security software should be installed on Internet café computers?
Information security book excerpts and reviews
Diverse mobile devices changing security paradigm
Cisco warns of security appliance flaws
How to configure NAP for Windows Server 2008
Can home PCs provide a way for viruses and spyware to enter a corporate LAN?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Internet Key Exchange  (SearchSecurity.com)
network encryption  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts