To configure an IPsec profile
- In the Cisco ADSM console, do the following:
- On the toolbar, click Configuration.
- In the left pane, click Remote Access VPN.
- In the left pane, expand the Network (Client) Access node to select the IPsec Connection Profiles node.
- In the right pane, under Connection Profiles, select an existing profile or add a new profile.
- Modify the selected or created profile (click the Edit button): In the User Authentication area, from the Server Group drop-down list, select the AAA server group you created in Step 1: Create an AAA server group, add Defender Security Server.
To configure Defender, you need to complete these steps:
To configure an Access Node
- On the computer where the Defender Administration Console is installed, open the Active Directory Users and Computers tool (dsa.msc).
- In the left pane, expand the appropriate domain node, and then expand the Defender node
- In the left pane, right-click Access Nodes, from the shortcut menu, select New | Defender Access Node.
- Complete the wizard to configure the Defender Access Node.
- On the Enter a name and description for this Access Node page, type a descriptive name and description for the Access Node.
- On the Select the node type and user ID type for this Access Node page, use the following options:
Node Type From this list, select Radius Agent. This enables the RADIUS protocol for communications between Cisco ACS devices and Defender. Note that the RADIUS protocol is transmitted over UDP and uses port 1645 or 1812.
User ID From this list, select the user ID type you want to use.
- On the Enter the connection details for this Access Node page, use the following options:
IP Address or DNS Name Specify the Cisco AAA Server by entering its IP address or DNS name.
In this step, you specify the users or groups who will use the configured Access Node to authenticate via Defender.
To specify users or groups for the Access Node
- On the computer where the Defender Administration Console is installed, open the Active Directory Users and Computers tool (dsa.msc).
- Open the properties of the Access Node you have configured:
- In the left pane, expand the domain node, expand the Defender node, and then click to select Access Nodes.
- In the right pane, double-click the Access Node.
- In the dialog box that opens, use the Members tab to add the users or groups to the Members list.
- When you are finished, click OK.