ASA Version 7.0(4)
!
hostname ASA5520-704
enable password 8Ry2YjIyt7RRXU24 encrypted
names
!
!— Configure the outside and inside interfaces.
interface GigabitEthernet0/0
nameif outside
security-level 0
ip address 10.20.20.1 255.255.255.0
!
interface GigabitEthernet0/1
nameif inside
security-level 100
ip address 172.22.1.1 255.255.255.0
!
interface GigabitEthernet0/2
shutdown
no nameif
no security-level
no ip address
!
interface GigabitEthernet0/3
shutdown
no nameif
no security-level
no ip address
!
interface Management0/0
shutdown
no nameif
no security-level
no ip address
!
passwd 2KFQnbNIdI.2KYOU encrypted
ftp mode passive
!
ip local pool remoteuserspool 172.22.1.10-172.22.1.20 mask 255.255.255.0
!
!— This access list is used for a nat zero command that prevents
!— traffic which matches the access list from undergoing
!— network address translation (NAT).
access-list no-nat extended permit ip 172.22.1.0 255.255.255.0
172.16.1.0 255.255.255.0
!..ASA V8 nonat configuration changes:
object-group network obj-local_ipsec_tunnel
network-object 172.16.0.0 255.255.0.0
!
object-group network obj-remote_ipsec_tunnel
network-object 172.16.20.0 255.255.255.0
!
nat (inside,outside) source static obj-local_ipsec_tunnel
obj-local_ipsec_tunnel destination static obj-remote_ipsec_tunnel
obj-remote_ipsec_tunnel
!— This access list is used to define the traffic
!— that should pass through the tunnel.
!— It is bound to the group policy which defines
!— a dynamic crypto map.
access-list split_tunnel extended permit ip 172.22.1.0 255.255.255.0
!
pager lines 24
mtu outside 1500
mtu inside 1500
no failover
icmp permit any echo-reply outside
icmp permit any inside
no asdm history enable
arp timeout 14400
!— Specify the NAT configuration.
!— NAT 0 prevents NAT for the ACL defined in this configuration.
!— The nat 1 command specifies NAT for all other traffic.
global (outside) 1 interface
nat (inside) 0 access-list no-nat
nat (inside) 1 0.0.0.0 0.0.0.0
route outside 0.0.0.0 0.0.0.0 10.20.20.2 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00
timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute
!…ASA V8 Nat configuration changes :
object network Private_Lan
subnet 172.16.0.0 255.255.0.0
nat (inside,outside) dynamic interface
!— This defines the group policy you use with EasyVPN.
!— Specify the networks
!— that should pass through the tunnel and that you want to
!— use network extension mode.
group-policy myGROUP internal
group-policy myGROUP attributes
dns-server value 172.22.1.1,172.22.1.2
vpn-tunnel-protocol IPSec
password-storage enable
split-tunnel-policy tunnelspecified
split-tunnel-network-list value split_tunnel
default-domain value stknetwork.local
nem enable
!
!— Here the username and password associated with
!— this VPN connection are defined. You
!— can also use AAA for this function.
username cisco password 3USUcOPFUiMCO4Jk encrypted
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
!— PHASE 2 CONFIGURATION —!
!— The encryption types for Phase 2 are defined here.
!— A single DES encryption with !— the md5 hash algorithm is used.
crypto ipsec transform-set mySET esp-des esp-md5-hmac
!— Defines a dynamic crypto map with !— the specified encryption settings.
crypto dynamic-map myDYN-MAP 10 set transform-set mySET
!—– Configuring the IPsec Security Association Idle Timers feature increases the
!—– availability of resources by deleting SAs associated with idle peers.
crypto dynamic-map myDYN-MAP 10 set security-association lifetime seconds 86400
crypto dynamic-map myDYN-MAP 10 set security-association lifetime kilobytes 9908000
!— Enable Reverse Route Injection (RRI), which allows the Security Appliance
!— to learn routing information for connected clients.
crypto dynamic-map myDYN-MAP 10 set reverse-route
!— Binds the dynamic map to the IPsec/ISAKMP process.
crypto dynamic-map myMAP 10 ipsec-isakmp dynamic myDYN-MAP
!— Specifies the interface to be used with
!— the settings defined in this configuration.
crypto map myMAP interface outside
!— PHASE 1 CONFIGURATION —!
!— This configuration uses isakmp policy 1.
!— Policy 65535 is included in the default
!— configuration. The configuration commands here define the Phase
!— 1 policies that are used.
isakmp enable outside
isakmp policy 1 authentication pre-share
isakmp policy 1 encryption des
isakmp policy 1 hash md5
isakmp policy 1 group 2
isakmp policy 1 lifetime 86400
!
isakmp policy 65535 authentication pre-share
isakmp policy 65535 encryption 3des
isakmp policy 65535 hash sha
isakmp policy 65535 group 2
isakmp policy 65535 lifetime 86400
!— The tunnel-group commands bind the configurations
!— defined in this configuration to the tunnel that is
!— used for EasyVPN. This tunnel name is the one specified on the remote side.
tunnel-group mytunnel type ipsec-ra
tunnel-group mytunnel general-attributes
address-pool remoteuserspool
authentication-server-group LOCAL
default-group-policy myGROUP
tunnel-group mytunnel ipsec-attributes
!— The pre-shared-key used here is “cisco”.
pre-shared-key *
!
telnet timeout 5 ssh
timeout 5 console timeout 0
!
class-map inspection_default
match default-inspection-traffic
!
!
policy-map global_policy
class inspection_default
inspect dns maximum-length 512
inspect ftp
inspect h323 h225
inspect h323 ras
inspect netbios
inspect rsh
inspect rtsp
inspect skinny
inspect esmtp
inspect sqlnet
inspect sunrpc
inspect tftp
inspect sip
inspect xdmcp
!
service-policy global_policy global
Summary :
username test1 password password1 encrypted privilege 0
!
ip local pool remoteuserspool 192.168.10.160-192.168.10.161 mask 255.255.255.0
!
access-list no-nat extended permit ip 172.22.1.0 255.255.255.0172.16.1.0 255.255.255.0
!..ASA V8 nonat configuration changes :
object-group network obj-local_ipsec_tunnel
network-object 172.16.0.0 255.255.0.0
!
object-group network obj-remote_ipsec_tunnel
network-object 172.16.20.0 255.255.255.0
!
nat (inside,outside) source static obj-local_ipsec_tunnel
obj-local_ipsec_tunnel destination static obj-remote_ipsec_tunnel
obj-remote_ipsec_tunnel
!
access-list split_tunnel extended permit ip 172.22.1.0 255.255.255.0
!
global (outside) 1 interface
nat (inside) 0 access-list no-nat
nat (inside) 1 0.0.0.0 0.0.0.0
route outside 0.0.0.0 0.0.0.0 10.20.20.2 1
!…ASA V8 Nat configuration changes :
object network Private_Lan
subnet 172.16.0.0 255.255.0.0
nat (inside,outside) dynamic interface
!
!
group-policy myGROUP internal
group-policy myGROUP attributes
dns-server value 172.22.1.1,172.22.1.2
vpn-tunnel-protocol IPSec
password-storage enable
split-tunnel-policy tunnelspecified
split-tunnel-network-list value split_tunnel
default-domain value stknetwork.local
nem enable
!
!— PHASE 1 CONFIGURATION —
!
isakmp policy 1 authentication pre-share
isakmp policy 1 encryption des
isakmp policy 1 hash md5
isakmp policy 1 group 2
isakmp policy 1 lifetime 86400
!— PHASE 2 CONFIGURATION —
!
crypto ipsec transform-set mySET esp-des esp-md5-hmac
crypto dynamic-map dynmap 10 set transform-set mySET
dynamic-map dynmap 10 set security-association lifetime seconds 86400
crypto dynamic-map dynmap 10 set security-association lifetime kilobytes 9908000
crypto dynamic-map dynmap 10 set reverse-route
crypto map myMAP 10 ipsec-isakmp dynamic dynmap
!
crypto map myMAP interface outside
isakmp enable outside
!— Tunnel-Group CONFIGURATION —
!
tunnel-group mytunnel type ipsec-ra
tunnel-group mytunnel general-attributes
address-pool remoteuserspool
authentication-server-group LOCAL
default-group-policy myGROUP
tunnel-group mytunnel ipsec-attributes
pre-shared-key *
!
Option Configuration without creating a ” remoteuserspool” address :
vpn-group-policy myGROUP
vpn-tunnel-protocol IPSec
vpn-framed-ip-address 192.168.10.160 255.255.255.0
!
Option Configuration without creating a LOCAL DATABASE user account for Authentication :
!
vpn-group-policy myGROUP
username user1 password pass1 encrypted privilege 0 username user1
attributes
Comments
(There are currently no comments for this post.)