Prerequisites for remote access VPN
Review these prerequisites for configuring a remote access VPN policy.
General prerequisites
-
You must have an administrator role to configure a remote access VPN policy.
-
Configure a certificate enrollment object to obtain the identity certificate for each Firewall Threat Defense device that acts as a remote access VPN gateway.
-
Create a security zone or interface group so that remote users can access the network interfaces for VPN connections.
-
Ensure IKE ports (500, 4500), and SSL port 443 are not in use by existing services, NAT, or PAT rules. The Firewall Threat Defense device cannot start VPN services on ports that are already active.
-
Configure DNS on each device in a remote access VPN policy to resolve AAA server names, named URLs, and CA servers with FQDNs or hostnames.
To configure DNS settings, choose , edit a policy. From the left pane, click DNS.
AAA server prerequisites
-
Before migrating a Firewall Threat Defense device with a remote access VPN policy, preconfigure the realm (LDAP, AD or local) used in the policy on Cloud-Delivered Firewall Management Center.
-
Ensure that the AAA server is reachable from the Firewall Threat Defense device. Configure routing to ensure connectivity to the AAA servers (, click the Edit icon, and from the left pane, choose Routing).
For remote access VPN double authentication, ensure that both the primary and secondary authentication servers are reachable from the Firewall Threat Defense device.
-
Before using an AD or LDAP server as an authentication server for your remote access VPN policies, ensure that you configure these parameters:
-
AD or LDAP realms
-
LDAP attribute map
-
Secure Client prerequisites
-
Download the latest Secure Client image files from Cisco Software Download Center.
Choose to add the Secure Client image files.
-
Download the Secure Client Profile Editor from Cisco Software Download Center to create the Secure Client profile. Use the standalone profile editor to create a new Secure Client profile or modify one.