The following scenarios and questions are designed to draw together the content of the chapter and exercise your understanding of the concepts. There might be more than one correct answer. The thought process and practice in manipulating each concept in the scenario are the goals of this section.
Users at one of your small branch facilities dial in to your corporate access server for access to the Internet, e-mail, and other network services. This four-user group is one of your research and development teams, and each of the four users dials in to the access server using 56-kbps modems for network services. Their work is considered top secret by upper management. Because of the sensitive nature of their communications, you want to establish a VPN for them using IPSec.
At the same time, other users at other branch sitesyour sales staff and other key personnelfrequently use laptops and home computers to connect to the corporate network through the Internet or through the access server. These users discuss sales figures and development projects and also require IPSec protection on their MS Exchange messaging and MS SQL database traffic.
You had considered using your router as a VPN server, but decided to use a Cisco VPN Concentrator because of its ability to authenticate users internally. You don't anticipate ever having more than 50 VPN clients active in your user community at any given time, and your employee base is stable.
As the senior security architect for your organization, how would you answer these questions?
Which VPN 3000 Concentrator would you purchase and install?
Would you use preshared keys or digital certificates for device authentication?
Would you depend on the internal authentication services of the VPN device, or would you use some other user authentication method?
How would you assign VPN addresses?
Would you permit split tunneling?
Would you use multiple IPSec groups? If so, why?
Which IPSec protocol would you use?
Which encryption protocol would you use?
Would you allow unrestricted access hours?
What would you set for idle timeout and maximum connect time?
Your company sells donuts and has 60 shops located in a three-state area. These shops are each connected to the Internet using DSL circuits. You want to establish IPSec VPN connections from each shop through the Internet to the corporate network for sending/receiving e-mail, reporting sales, and ordering supplies.
You will be using a Cisco VPN 3030 Concentrator with no SEP modules. Device authentication is accomplished using preshared keys. User authentication is done through the NT Domain. The IP addresses of the DNS servers are 192.168.44.20 and 192.168.63.20. The IP addresses of the WINS servers are 192.168.44.25 and 18.104.22.168. No changes have been made to the default Base Group.
Create a group for the shops called DonutShops.
Indicate the settings that you would make on the group's General tab for each of the following attributes, and specify whether you would uncheck the Inherit? box.
- Access Hours
- Simultaneous Logins
- Minimum Password Length
- Allow Alphabetic-Only Passwords
- Idle Timeout
- Maximum Connect Time
- Primary DNS
- Secondary DNS
- Primary WINS
- Secondary WINS
- SEP Card Assignment
- Tunneling Protocols
- Strip Realm
Indicate the settings that you would make on the group's IPSec tab for each of the following attributes, and specify whether you would uncheck the Inherit? box.
- IPSec SA
- IKE Peer Identity Validation
- IKE Keepalives
- Reauthentication on Rekey
- Tunnel Type
- Group Lock
- Mode Configuration