Sections:
Resources:
Overview:
Meraki Client VPN Features
L2TP/IPsec Protocol
Cloud Management
User Authentication
Split Tunneling
Access Control & Permissions
High Availability
Encryption
Meraki Client VPN Benefits
Easy Setup
Cross-Platform Compatibility
Cloud Managed Infrastructure
Scalability
Lab Topology
Overview:
Meraki ClientVPN Configuration
Menu to configure ClientVPN
AnyConnect Parameters
AnyConnect Client VPN
Hostname
AnyConnect Port
Log-in Banner
Profile Update
Server Certificate Generation Method
Authentication Type
Certificate Authentication
AnyConnect VPN subnet
DNS nameservers
Client Routing
Dynamic Client Routing
Session Timeout
Default Group Policy
User Management
Windows ClientVPN Configuration
Overview:
AnyConnect Preference Options
Enable Local LAN Access
Disable Captive Portal Detection
Block Connections to Untrusted Servers
Connecting to the Meraki VPN server using the DDNS hostname
Authentication Credentials to authenticate to the VPN server
Triggered Log-in Banner upon successful authentication to the VPN server
VPN subnet verification defined in the AnyConnect settings in the Meraki Dashboard
Verification of the Full tunneling method defined in the AnyConnect settings in the Meraki Dashboard
Full tunneling verification by analyzing a traceroute towards the Internet. All traffic is directed towards the VPN
ClientVPN verification by testing connectivity to devices reachable through the VPN tunnel
IOS ClientVPN Configuration
Overview:
Verification of the clientVPN working with full tunneling configured through the Meraki Dashboard
Port Forwarding for Downstream NAT Devices
Overview:
ClientVPN Topology:
Networking Fundamentals:
My Lab Use Case:
Eero Router
Raspberry Pi
ClientVPN Authentication Types
Overview:
Meraki Cloud Authentication
Active Directory
RADIUS
SAML
Active Directory Authentication Configuration
Overview:
Windows Server Active Directory Verification
IP Address of AD Server - 172.16.5.15
Active Directory Users
Configuration
Active Directory Required Options
Short Domain
Server IP
Domain Admin
Password
Active Directory server and Authentication Type defined in the Client VPN section under Cisco AnyConnect
Testing Client VPN Authentication using Cisco AnyConnect Client via Windows
Testing Client VPN Authentication using Cisco AnyConnect Client via IOS