Configure IP addresses for VPN clients
You can assign IP addresses to remote access VPN users by using IP address pools. You can source these IP addresses from a AAA server, a DHCP server, or local IP address pools. If you select multiple sources, addresses are assigned in this order: AAA server, DHCP server, and then local IP address pools. IP address pools defined in a connection profile are used only when no pools are defined in the associated group policy or in the default group policy DfltGrpPolicy.
Before you begin
Note | When you configure both a DHCP server and a local IP address pool for address assignment, automatic fallback to the local pool (if the DHCP server is unavailable) works only for SSL-based remote access VPN connections. For IPsec-based remote access VPN connections, this fallback may not complete in time if the DHCP server is unreachable, which can cause the connection to fail. |
To avoid connection issues with IPsec-based remote access VPN, do one of the following:
-
Make sure the DHCP server is reachable, or
-
Use only a local IP address pool for address assignment.
Procedure
Step 1 | Choose . | ||
Step 2 | Click the edit icon next to the remote access VPN policy. | ||
Step 3 | Click the edit icon next to the connection profile. | ||
Step 4 | Click the Client Address Assignment tab. | ||
Step 5 | Click + next to Address Pools: | ||
Step 6 | Click + next to DHCP Servers to add DHCP servers for address assignment.
| ||
Step 7 | Click Save. |
What to do next
To define the IP address assignment policy, click the Advanced tab, and from the left pane, choose Address Assignment Policy.