Create an IPSEC VPN Additional tunnel using Internet Facing Interface with NAT-T enable :
Create Object-Group Network for Source Network :
object-group network MPLS_Host_to_BlueSource
description MPLS Sites-Host-Address
network-object host 172.16.0.95
Create Object-Group Network for Remote Network :
object-group network BLUESource_Network
description Blue Source private IP address
network-object 10.99.0.0 255.255.0.0
Create a Object-Group Service for TCP ports for remote traffic allowed through the IPSEC Tunnel :
object-group service BLUE_SOURCE_PORTS tcp
description Inbound Access
port-object eq 3389
port-object range 9998 9999
Create a Object-Group Service for ICMP traffic :
object-group icmp-type BLUE-SOURCE-ICMP-INBOUND
description Permit necessary inbound ICMP traffic
icmp-object echo
icmp-object echo-reply
icmp-object unreachable
icmp-object time-exceeded
NAT Traversal allows ESP packets to pass through one or more NAT devices.
When you enable NAT-T, the security appliance automatically opens port 4500 on all IPsec enabled interfaces.
isakmp nat-traversal 3600
Create a Rule to Disable NAT :
access-list MPLS_nat0_inbound extended permit ip object-group MPLS_Host_to_BlueSource object-group BLUESource_Network
Assign NAT Rule To Interface :
nat (MPLS) 0 access-list MPLS_nat0_inbound outside
Access-list from MPLS Host to BlueSource Network:
Allow only ICMP Traffic :
INBOUND Rule for traffic leaving the interface :
access-list MPLS_access_in extended permit tcp object-group MPLS_Host_to_BlueSource object-group BLUESource_Network object-group BLUE-SOURCE-ICMP-INBOUND
Access-list from Blue Source to MPLS Host :
OUTBOUND Rule for traffic coming into interface :
access-list MPLS_access_out extended permit tcp object-group BLUESource_Network object-group MPLS_Host_to_BlueSource object-group BLUE_SOURCE_PORTS
!
access-list MPLS_access_out extended permit icmp object-group BLUESource_Network object-group MPLS_Host_to_BlueSource object-group BLUE-SOURCE-ICMP-INBOUND
!
object-group BLUESource_Network
access-list MPLS_access_out extended deny ip object-group BLUESource_Network any
!
access-list MPLS_access_out extended permit ip any any
Assign ACL to Outbound of Interface :
access-group MPLS_access_out out interface MPLS
Assign Interface Crypto Map :
crypto map BlueSource_map interface PublicIP
crypto isakmp enable PublicIP
Create Access-List for Source Address to Remote Address :
Keep ACL naming convention to match Crypto Map sequence no.
access-list BlueSource_cryptomap_390 extended permit ip object-group MPLS_Host_to_BlueSource object-group BLUESource_Network
Create IPSEC Crypto map Statement + Sequence No :
crypto map BlueSource_map 390 match address BlueSource_cryptomap_390
crypto map BlueSource_map 390 set peer 113.112.208.128
crypto map BlueSource_map 390 set transform-set ESP-3DES-SHA
crypto map BlueSource_map 390 set security-association lifetime seconds 28800
crypto map BlueSource_map 390 set security-association lifetime kilobytes 4608000
Create Tunnel-Group for assigned Public Address of Peer and Pre-shared-key :
tunnel-group 113.112.208.128 type ipsec-l2l
tunnel-group 113.112.208.128 ipsec-attributes
pre-shared-key S1u350vd7
exit
Create ISAKMP Phase 1 Policy to match Transform-Set ESP-3DES-SHA
crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
!
crypto isakmp policy 40
authentication pre-share
encryption 3des
hash sha
group 2
lifetime 86400
Comments
(There are currently no comments for this post.)