cc/td/doc/product/vpn/vpn3002/4-1
hometocprevnextglossaryfeedbacksearchhelp
PDF

Table of Contents

Using the VPN 3002 Hardware Client Manager
VPN 3002 Hardware Client Browser Requirements
Connecting to the VPN 3002 Using HTTP
Installing the SSL Certificate in Your Browser
Connecting to the VPN 3002 Using HTTPS
Configuring HTTP, HTTPS, and SSL Parameters
Logging into the VPN 3002 Hardware Client Manager
Interactive Hardware Client and Individual User Authentication
Logging In With Interactive Hardware Client and Individual User Authentication
Understanding the VPN 3002 Hardware Client Manager Window
Organization of the VPN 3002 Hardware Client Manager
Navigating the VPN 3002 Hardware Client Manager

Using the VPN 3002 Hardware Client Manager


The VPN 3002 Hardware Client Manager is an HTML-based interface that lets you configure, administer, monitor, and manage the VPN 3002 with a standard web browser. To use it, you connect to the VPN 3002, using a PC and browser on the same private network with the VPN 3002.

The Manager uses the standard web client / server protocol, HTTP (Hypertext Transfer Protocol), which is a cleartext protocol. However, you can also use the Manager in a secure, encrypted HTTP connection over SSL (Secure Sockets Layer) protocol, known as HTTPS.

When the SSL certificate is installed, you can connect directly using HTTPS; see "Connecting to the VPN 3002 Using HTTPS."

VPN 3002 Hardware Client Browser Requirements

The VPN 3002 Hardware Client Manager requires either Microsoft Internet Explorer version 4.0 or higher, or Netscape Navigator version 4.5-4.7. For best results, we recommend Internet Explorer. Whatever browser and version you use, install the latest patches and service packs for it.


Note   You cannot use the Live Event Log feature with Netscape Navigator version 4.0

JavaScript and Cookies

Be sure JavaScript and Cookies are enabled in the browser. Refer to the documentation for your browser for instructions.

Navigation Toolbar

Do not use the browser navigation toolbar buttons Back, Forward, or Refresh/Reload with the VPN 3002 Hardware Client Manager unless instructed to do so. To protect access security, clicking Refresh/Reload automatically logs out the Manager session. Clicking Back or Forward might display stale Manager screens with incorrect data or settings.

We recommend that you hide the browser navigation toolbar to prevent mistakes while using the
VPN 3002 Hardware Client Manager.

Recommended PC Monitor/Display Settings

For optimal use, we recommend setting your monitor or display:

Connecting to the VPN 3002 Using HTTP

When your system administration tasks and network permit a cleartext connection between the VPN 3002 and your browser, you can use the standard HTTP protocol to connect to the system.

Even if you plan to use HTTPS, you use HTTP at first to install an SSL certificate in your browser.


Step 1   Bring up the browser.

Step 2   In the browser Address or Location field, you can just enter the VPN 3002 private interface IP address; for example, 10.10.147.2. The browser automatically assumes and supplies an http:// prefix.

The browser displays the VPN 3002 Hardware Client Manager login screen.




Figure 1-1   VPN 3002 Hardware Client Manager Login Screen


To continue using HTTP for the whole session, skip to "Logging into the VPN 3002 Hardware Client Manager."

Installing the SSL Certificate in Your Browser

The Manager provides the option of using HTTP over SSL with the browser. SSL creates a secure session between your browser (VPN 3002 hardware client) and the VPN Concentrator (server). This protocol is known as HTTPS, and uses the https:// prefix to connect to the server. The browser first authenticates the server, then encrypts all data passed during the session.

HTTPS is often confused with a similar protocol, S-HTTP (Secure HTTP), which encrypts only HTTP application-level data. SSL encrypts all data between client and server at the IP socket level, and is thus more secure.

SSL uses digital certificates for authentication. The VPN 3002 creates a self-signed SSL server certificate when it boots, and this certificate must be installed in the browser. Once the certificate is installed, you can connect using HTTPS. You need to install the certificate from a given VPN 3002 only once.

Managing the VPN 3002 is the same with or without SSL. Manager screens might take slightly longer to load with SSL because of encryption/decryption processing. When connected via SSL, the browser shows a locked-padlock icon on its status bar. Both Microsoft Internet Explorer and Netscape Navigator support SSL.

For HTTPS to work on the public interface, you must enable HTTPS on the VPN 3002 through the command-line interface or from an HTTP session on the private interface first.

Follow these steps to install and use the SSL certificate for the first time. We provide separate instructions for Internet Explorer and Netscape Navigator when they diverge.


Step 1   Connect to the VPN 3002 using HTTP as above.

Step 2   On the login screen, click the Install SSL Certificate link.

The Manager displays the Install SSL Certificate screen and automatically begins to download and install its SSL certificate in your browser.




Figure 1-2   Install SSL Certificate Screen


The installation sequence now differs depending on the browser. Continue below for Internet Explorer, or skip to "Installing the SSL Certificate with Netscape."

Installing the SSL certificate with Internet Explorer

This section describes SSL certificate installation using Microsoft Internet Explorer 5.0. (With Internet Explorer 4.0, some dialog boxes are different but the process is similar.)

You need to install the SSL certificate from a given VPN 3002 only once. If you do reinstall it, the browser repeats all these steps each time.

A few seconds after the VPN 3002 Hardware Client Manager SSL screen appears, Internet Explorer displays a File Download dialog box that identifies the certificate filename and source, and asks whether to Open or Save the certificate. To immediately install the certificate in the browser, select Open. If you Save the file, the browser prompts for a location; you must then double-click the file to install it.


Figure 1-3   Internet Explorer File Download Dialog Box



Step 1   Click the Open this file from its current location radio button, then click OK.

The browser displays the Certificate dialog box with information about the certificate. You must now install the certificate.


Figure 1-4   Internet Explorer Certificate Dialog Box


Step 2   Click Install Certificate.

The browser starts a wizard to install the certificate. The certificate store is where such certificates are stored in Internet Explorer.


Figure 1-5   Internet Explorer Certificate Manager Import Wizard Dialog Box


Step 3   Click Next to continue.

The wizard opens the next dialog box asking you to select a certificate store.


Figure 1-6   Internet Explorer Certificate Manager Import Wizard Dialog Box


Step 4   Let the wizard Automatically select the certificate store, and click Next.

The wizard opens a dialog box to complete the installation.


Figure 1-7   Internet Explorer Certificate Manager Import Wizard Dialog Box


Step 5   Click Finish.

The wizard opens the Root Certificate Store dialog box asking you to confirm the installation.


Figure 1-8   Internet Explorer Root Certificate Store Dialog Box


Step 6   To install the certificate, click Yes. This dialog box closes, and a final wizard confirmation dialog box opens.


Figure 1-9   Internet Explorer Certificate Manager Import Wizard Final Dialog Box


Step 7   Click OK to close this dialog box, and click OK on the Certificate dialog box (Figure 1-4) to close it.

You can now connect to the VPN 3002 using HTTP over SSL (HTTPS).

Step 8   On the Manager SSL screen (Figure 1-2), click the link that says After installing the SSL certificate, click here to connect to the VPN 3002 Hardware Client using SSL.

Depending on how your browser is configured, you might see a Security Alert dialog box.


Figure 1-10   Internet Explorer Security Alert Dialog Box


Step 9   Click OK.

The VPN 3002 Hardware Client displays the HTTPS version of the Manager login screen.


Figure 1-11   VPN 3002 Hardware Client Manager Login Screen Using HTTPS (Internet Explorer)


The browser maintains the HTTPS state until you close it or access an unsecured site; in the latter case you might see a Security Alert screen.

Proceed to Logging into the VPN 3002 Hardware Client Manager to log in as usual.



Viewing Certificates with Internet Explorer

There are (at least) two ways to examine certificates stored in Internet Explorer.

First, note the padlock icon on the browser status bar in Figure 1-11. If you double-click the icon, the browser opens a Certificate Properties screen showing details of the specific certificate in use.


Figure 1-12   Internet Explorer 4.0 Certificate Properties Screen


Click any of the Field items to see Details. Click Close when finished.

Second, you can view all the certificates that are stored in Internet Explorer 4.0. Click the browser View menu and select Internet Options. Click the Content tab, then click Authorities in the Certificates section.

In Internet Explorer 5.0, click the browser Tools menu and select Internet Options. Click the Content tab, then click Certificates in the Certificates section. On the Certificate Manager, click the Trusted Root Certification Authorities tab.

The VPN 3002 Hardware Client SSL certificate name is its Ethernet 1 (private) IP address.


Figure 1-13   Internet Explorer 4.0 Certificate Authorities List


Select a certificate, then click View Certificate. The browser displays the Certificate Properties screen, as in Figure 1-12 above.

Installing the SSL Certificate with Netscape

This section describes SSL certificate installation using Netscape Navigator / Communicator 4.5.

Reinstallation

You need to install the SSL certificate from a given VPN 3002 only once. If you try to reinstall it, Netscape displays the note in Figure 1-14. Click OK and just connect to the VPN 3002 using SSL (see Step 7 in this section.


Figure 1-14   Netscape Reinstallation Note


First-time Installation

The instructions below follow from Step 2 in "Installing the SSL Certificate in Your Browser," and describe first-time certificate installation.

A few seconds after the VPN 3002 Hardware Client Manager SSL screen appears, Netscape displays a New Certificate Authority screen.


Figure 1-15   Netscape New Certificate Authority Screen 1



Step 1   Click Next> to proceed.

Netscape displays the next New Certificate Authority screen, which further explains the process.


Figure 1-16   Netscape New Certificate Authority Screen 2


Step 2   Click Next> to proceed.

Netscape displays the next New Certificate Authority screen, which lets you examine details of the VPN 3002 Hardware Client SSL certificate.


Figure 1-17   Netscape New Certificate Authority Screen 3


Step 3   Click Next> to proceed.

Netscape displays the next New Certificate Authority screen, with choices for using the certificate. No choices are checked by default.


Figure 1-18   Netscape New Certificate Authority Screen 4


Step 4   You must check at least the first box, Accept this Certificate Authority for Certifying network sites. Click Next> to proceed.

Netscape displays the next New Certificate Authority screen, which lets you choose to have the browser warn you about sending data to the VPN 3002.


Figure 1-19   Netscape New Certificate Authority Screen 5


Step 5   Checking the box is optional. Doing so means that you get a warning whenever you apply settings on a Manager screen, so it is probably less intrusive to manage the VPN 3002 without those warnings. Click Next> to proceed.

Netscape displays the final New Certificate Authority screen, which asks you to name the certificate.


Figure 1-20   Netscape New Certificate Authority Screen 6


Step 6   In the Nickname field, enter a descriptive name for this certificate. "Nickname" is something of a misnomer. We suggest you use a clearly descriptive name such as Cisco VPN 3002 10.10.147.2. This name appears in the list of installed certificates; see "Viewing Certificates with Netscape," below.

Click Finish.

You can now connect to the VPN 3002 using HTTP over SSL (HTTPS).

Step 7   On the Manager SSL screen (Figure 1-2), click the link that says After installing the SSL certificate, click here to connect to the VPN 3002 Hardware Client using SSL.

Depending on how your browser is configured, you might see a Security Information Alert dialog box.


Figure 1-21   Netscape Security Information Alert Dialog Box


Step 8   Click Continue.

The VPN 3002 displays the HTTPS version of the Manager login screen.


Figure 1-22   VPN 3002 Hardware Client Manager Login Screen Using HTTPS (Netscape)

The browser maintains the HTTPS state until you close it or access an unsecured site; in the latter case, you might see a Security Information Alert dialog box.

Proceed to the section, "Logging into the VPN 3002 Hardware Client Manager," to log in as usual.



Viewing Certificates with Netscape

There are (at least) two ways to examine certificates stored in Netscape Navigator / Communicator 4.5.

First, note the locked-padlock icon on the bottom status bar in Figure 1-22. If you click the icon, Netscape opens a Security Info window. (You can also open this window by clicking Security on the Navigator Toolbar at the top of the Netscape window.)


Figure 1-23   Netscape Security Info Window


Click View Certificate to see details of the specific certificate in use.


Figure 1-24   Netscape View Certificate Screen


Click OK when finished.

Second, you can view all the certificates that are stored in Netscape. On the Security Info window, select Certificates, then Signers. The "nickname" you entered in Step 6 in the section, "First-time Installation," identifies the VPN 3002 Hardware Client SSL certificate.


Figure 1-25   Netscape Certificates Signers List


Select a certificate, then click Edit, Verify, or Delete. Click OK when finished.

Connecting to the VPN 3002 Using HTTPS

When you have installed the SSL certificate in the browser, you can connect directly using HTTPS.


Step 1   Bring up the browser.

Step 2   In the browser Address or Location field, enter https:// plus the VPN 3002 private interface IP address; for example, https://10.10.147.2.

The browser displays the VPN 3002 Hardware Client Manager HTTPS login screen.

A locked-padlock icon on the browser status bar indicates an HTTPS session. Also, this login screen does not include the Install SSL Certificate link.



Configuring HTTP, HTTPS, and SSL Parameters

HTTP, HTTPS, and SSL are enabled by default on the VPN 3002, and they are configured with recommended parameters that should suit most administration tasks and security requirements.

To configure HTTP and HTTPS parameters, see the Configuration | System | Management Protocols | HTTP/HTTPS screen.

To configure SSL parameters, see the Configuration | System | Management Protocols | SSL screen.


Figure 1-26   VPN Hardware Client Manager HTTPS Login Screen


Logging into the VPN 3002 Hardware Client Manager

Logging into the VPN 3002 Hardware Client Manager is the same for both types of connections, cleartext HTTP or secure HTTPS.

Entries are case-sensitive. With Microsoft Internet Explorer, you can select the Tab key to move from field to field; other browsers might work differently. If you make a mistake, click the Clear button and start over.

The following entries are the factory-supplied default entries. If you have changed them, use your entries.


Step 1   Click in the Login field and type admin. (Do not press Enter.)

Step 2   Click in the Password field and type admin. (The field shows *****.)

Step 3   Click the Login button.

The Manager displays the main welcome screen (Figure 1-33).

From here you can navigate the Manager using either the table of contents in the left frame, or the Manager toolbar in the top frame.

Interactive Hardware Client and Individual User Authentication

Interactive hardware client and individual user authentication provide security by requiring manual entry of usernames and passwords prior to connection. You configure these features on the VPN Concentrator to which this VPN 3002 connects, and the VPN Concentrator pushes the policies you set to the VPN 3002. You can use interactive hardware client authentication and individual user authentication in combination or separately.

For complete configuration information refer to the section on the Hardware Client tab in the User Management chapter of the VPN 3000 Series Concentrator Reference Volume 1: Configuration.

Interactive Hardware Client Authentication

When you enable interactive hardware client authentication, the VPN 3002 does not use a saved username and password. Instead, to connect you must manually enter a valid username and password for the VPN 3002 when prompted. When the VPN 3002 initiates the tunnel, it sends the username and password to the VPN Concentrator to which it connects. The VPN Concentrator facilitates authentication, on either the internal or an external server. If the username and password are valid, the tunnel is established.

Individual User Authentication

Individual user authentication protects the central site from access by unauthorized persons on the same LAN as the VPN 3002.

When you enable individual user authentication, each user that connects through a VPN 3002 must open a web browser and manually enter a valid username and password to access the network behind the VPN Concentrator, even though the tunnel already exists.

Logging In With Interactive Hardware Client and Individual User Authentication

You access the interactive hardware client authentication and individual user authentication login screens from the VPN 3002 Hardware Client Manager login screen. The sequence in the login example that follows assumes that both interactive hardware client authentication and individual user authentication are required for this VPN 3002 to connect.


Figure 1-27   VPN 3002 Hardware Client Manager Login Screen



Step 1   Click the Connection Login Status button.

The Connection/Login Status screen displays




Figure 1-28   Connection Login Status Screen

.


Step 1   Click the Connect Now button.

The VPN 3002 Interactive Authentication screen displays.




Figure 1-29   VPN 3002 Interactive Authentication Screen



Step 1   Enter the username and password for the VPN 3002.

Step 2   Click Connect.

If you have entered the valid username and password, the Connect Login Status screen displays the message that the VPN 3002 is connected. Next you authenticate the user.




Figure 1-30   Connection Login Status Screen



Step 1   To authenticate an individual user, click Log In Now.

The Individual User Authentication screen displays.




Figure 1-31   Individual User Authentication Screen



Step 1   Enter the username and password for this VPN 3002 user.

Step 2   Click Login. If the username and password you entered are valid, the Connection/Login Status window displays information about the connection.




Figure 1-32   Connection/Login Status Screen


The user behind the VPN 3002 is connected to the VPN Concentrator at the central site.

Click Go back to the VPN 3002 administrative login page to return to the VPN 3002 Hardware Client Manager login screen and access other features and functions of the VPN 3002.

Understanding the VPN 3002 Hardware Client Manager Window

The VPN 3002 Hardware Client Manager window on your browser consists of three frames—top, left, and main—and it provides helpful messages and tips as you move the mouse pointer over window items. The title bar and status bar also provide useful information


Figure 1-33   VPN 3002 Hardware Client Manager Window.

Title bar

The title bar at the top of the browser window includes the VPN 3002 device name or IP address in brackets, for example, [10.10.4.6].

Status bar

The status bar at the bottom of the browser window displays Manager activity and explanatory messages for some items.

Mouse pointer and tips

As you move the mouse pointer over an active area, the pointer changes shape and icons change color. A description also appears in the status bar area. If you momentarily rest the pointer on an icon, a descriptive tip appears for that icon.

Top frame
(Manager toolbar)

The Manager toolbar in the top frame provides quick access to Manager features. These include the following icons:


Click on the Main tab to go to the main Manager screen, and to close all subordinate sections and titles in the left frame.


Click on the Help tab to open context-sensitive online help. Help opens in a separate browser window that yo can move or resize as you want. Close the help window when you are finished.


Click on the Support tab to open a Manager screen with links to Cisco support and documentation resources.


Click on the Logout tab to log out of the Manager and return to the login screen.

Logged in: [username]

The administrator username you used to log in to this Manager session.


Click on the Configuration tab to go to the main Configuration screen, to open the first level of subordinate Configuration pages in the left frame if they are not already open, and to close any open Administration or Monitoring pages in the left frame.


Click on the Administration tab to go to the main Administration screen, to open the first level of subordinate Administration pages in the left frame if they are not already open, and to close any open Configuration or Monitoring pages in the left frame.


Click on the Monitoring tab to go to the main Monitoring screen, to open the first level of subordinate Monitoring pages in the left frame if they are not already open, and to close any open Configuration or Administration pages in the left frame.

Save

Click on the Save icon to save the active configuration and make it the boot configuration. In this state, the reminder indicates that the active configuration is the same as the boot configuration, but you can save it anyway. When you change the configuration, the reminder changes to Save Needed.

Save Needed

This reminder indicates that yo have changed the active configuration. Click on the Save Needed icon to save the active configuration and make it the boot configuration. As you make configuration entries, they take effect immediately and are included in the active, or running, configuration. However, if you reboot the VPN 3002 without saving the active configuration, and configuration changes are lost. Clicking on this reminder saves the active configuration as the boot configuration and restores the Save reminder.

Refresh

Click on the Refresh icon to refresh (update) the screen contents on screens where it appears (mostly in the Monitoring section). The date and time above this reminder indicate when the screen was last updated.

Reset

Click on the Reset icon to reset, or start anew, the screen contents on screens where it appears (mostly in the Monitoring section).

Restore

Click on the Restore icon to restore the screen contents to their status prior to when you last clicked the Reset icon.


Click on the Cisco Systems logo to open a browser and go to the Cisco.com web site, www.cisco.com

Left frame
(Table of Contents)

On Manager screens, the left frame provides a table of contents. The table of contents uses the familiar Windows Explorer metaphor of collapsed and expanded entries.

Main section titles (Configuration, Administration, Monitoring

Click on a title to open subordinate sections and titles, and to go to that Manager screen in the main frame.

Closed or collapsed

Click on the closed/collapsed icon to open subordinate sections and titles. Clicking on this icon does not change the screen in the main frame.

Open or expanded

Click on the open/expanded icon to close subordinate sections and titles. Clicking on this icon does not change the screen in the main frame.

Main frame
(Manager screen)

The main frame displays the current VPN 3002 Manager screen.

Many screens include a bullet list of links and descriptions of subordinate sections and titles. you can click on a link to go to that Manager screen, and open subordinate sections and titles in the table of contents.

Organization of the VPN 3002 Hardware Client Manager

The VPN 3002 Hardware Client Manager consists of three major sections and many subsections:

This manual covers all these topics. For Quick Configuration, refer to the VPN 3002 Hardware Client Getting Started guide.

Navigating the VPN 3002 Hardware Client Manager

Your primary tool for navigating the VPN 3002 Hardware Client Manager is the table of contents in the left frame. Figure 1-34 shows all its entries, completely expanded. (The figure shows the frame in multiple columns, but the actual frame is a single column. Use the scroll controls to move up and down the frame.)


Figure 1-34   Manager Table of Contents




hometocprevnextglossaryfeedbacksearchhelp
Posted: Wed Feb 4 11:06:38 PST 2004
All contents are Copyright © 1992--2004 Cisco Systems, Inc. All rights reserved.
Important Notices and Privacy Statement.