Networking-Blog

My WordPress Blog

ASA VPN LDAP Authentication + Group Membership Verification


!
!
!
!
!
!
!
!
!
!

Project Goal: The goal for this task is to authenticate VPN users via LDAP to the
Windows 2008 domain controllers. In addition to the simple AD authentication
requirement, the client wanted to match the user’s credentials against a VPN group
in the AD database, as a second layer of protection.

This second check against the AD group membership helps to ensure that the user
didn’t just obtain the VPN group password along with a user’s username and password.
In addition, it gives more control to the IT administrator to make sure that only approved
users have VPN access, not all users in the AD branch.

Requirements: In order to complete this task, the following items were needed:

1. Upgrade the ASA appliance to 8.0(4). At the time of the project, this version was
stable and allowed authentication directly to AD without the need for an additional
RADIUS services to be installed on the domain controllers.

2. A single user account with basic privileges in the AD database. For best results,
place this user in the root of the tree (Base DN).

I recommend building a test VPN group in parallel, test the authentication and then
change the production group’s authentication servers.

The first step is to create an attribute map called ASAMAP. In the map subcommands,
we match the well known Microsoft attribute
“memberOf” to a standard IETF Radius class,
which the ASA is familiar with.

The next line takes the newly created association to the path of the AD group,
in this example the group name is VPN_Users.

The final important note in this step is to notice the value being mapped to the already
existing VPN group called
ciscovpn. Now that the map name and value to be checked
has been created, it will later be associated with the VPN tunnel group.

ldap attribute-map ASAMAP
map-name memberOf IETF-Radius-Class
map-value memberOf “CN=VPN_Users,OU=Security                 Groups,OU=Groups,OU=CompanyXYZHQ,DC=companyxyz,DC=com” ciscovpn

Create the new AAA server(s) called LDAP-Auth2-AD (you can use any name you like).
In this case, these are the new 2008 servers. In addition, the communication protocol is
determined in this step. For our example, I use LDAP.

aaa-server LDAP-Auth2-AD protocol ldap

Now that we have identified the protocol as LDAP and created a new method,
we add each server independently. Just like anything else with the ASA, you must
tell it which interface to use in order to communicate with the server, in this case,
the (inside) interface. Larger clients might have their authentication servers in a DMZ.

After entering the following command, the rest of the commands are sub-commands.

aaa-server LDAP-Auth2-AD (inside) host 172.16.1.91

In this step we tell the ASA where the Base DN is for the AD tree.
This is basically the path to the root of the tree.

ldap-base-dn DC=CompanyXYZ,DC=com
ldap-scope subtree
ldap-naming-attribute sAMAccountName

As we continue with the sub commands, we provide a username and password for the
ASA to use in order to log into AD and make sure the user exists.
I usually let the Windows admin dictate the name.

In this example, the username is S_ASA_LDAP. In order to have a successful
implementation, you can use the following command to test the LDAP authentication:

“test aaa-server authentication LDAP-Auth2-AD host 172.16.1.91 username
S_ASA_LDAP password abc123“.

!

If the test fails, I recommend you stop and figure out the AD problems first.

use this command on a domain controller to find the full path of the ASAuser account:

dsquery user -samid ASAUser

Your login DN has to contain the complete location of the user ID you are using.
For example CN=ASAUser,OU=ServiceAccounts,DC=cisco,DC=com


!

ldap-login-password
ldap-login-dn CN=S_ASA_LDAP,OU=service accounts,OU=Users,
OU=CompanyXYZ HQ,DC=CompanyXYZ,DC=com
server-type Microsoft

Still in subcommands, we add our second layer of authentication by telling the ASA
to also check against the LDAP attribute created in step 1.

ldap-attribute-map ASAMAP

The next step is to point the existing production VPN tunnel group to the new
authentication servers created earlier.

First we enter the VPN group policy section, and then assign the appropriate
authentication method. Note, there are other attribute settings for this group,
however, we only care about the authentication method.

tunnel-group ciscovpn general-attributes
authentication-server-group LDAP-Auth2-AD

The ASA automatically defers to the default group policy if a user authentication
fails and no authentication method is specified, therefore, we need to make sure that
the built-in default policy is using the same authentication method.
The fiirst step is to change the default tunnel group defaultRAGroup to utilize the same
authentication method. Note: If you don’t perform these two steps, the authentication
will still work even if you remove the user from the AD group.

tunnel-group DefaultRAGroup general-attributes
authentication-server-group LDAP-Auth2-AD

Finally, the VPN default group policy attributes are basically disabled by changing
the simultaneous logins to zero.

group-policy DfltGrpPolicy attributes
vpn-simultaneous-logins 0

Now it is time to test. The ASA has a simple debug command to verify the results.

debug ldap 255

Here is a sample debug of the LDAP authentication. The only part we need for this
task is to make sure that the “memberOf” variable is being properly matched.
If the match is being performed properly, the rest depends on the users group
membership. Below we see a match with the “Users” group.

[20330] memberOf: value = CN=VPN_Users,OU=Security Groups,OU=Groups,
OU=CompanyXYZ HQ,DC=compnayxyz,DC=COM

[20330] mapped to IETF-Radius-Class: value = policy_1

In addition, the “debug ldap 255” command is very useful to see the Active Directly
Base DN path and what the server is expecting from the ASA.

In addition, this debug command can be very useful to find out where the authentication
maybe failing. For example, if the login fails, you can see if the issue was related to a
bad password, lack of communication with the server, or no group match.

Note: If you forget to disable the logins and authentication for the default VPN group,
you will see in the debug that the user is not a member of the VPN group,
yet authentication is still successful.

In conclusion, I have included a snippet from the actual running configuration:

ldap attribute-map ASAMAP
map-name memberOf IETF-Radius-Class
map-value memberOf “CN=VPN_Users,OU=Security Groups,OU=Groups,
OU=CompanyXYZ HQ,DC=CompanyXYZ,DC=com” ciscovpn
!
dynamic-access-policy-record DfltAccessPolicy
aaa-server LDAP-Auth2-AD protocol ldap
aaa-server LDAP-Auth2-AD (inside) host 172.16.1.91
ldap-base-dn DC=CompanyXYZ,DC=com
ldap-scope subtree
ldap-naming-attribute sAMAccountName
ldap-login-password *
ldap-login-dn CN=S_ASA_LDAP,OU=service accounts,OU=Users,
OU=CompanyXYZ HQ,DC=CompanyXYZ,DC=com
server-type microsoft
ldap-attribute-map ASAMAP
!
aaa-server LDAP-Auth2-AD (inside) host 172.16.1.92
ldap-base-dn DC=CompanyXYZ,DC=com
ldap-scope subtree
ldap-naming-attribute sAMAccountName
ldap-login-password *
ldap-login-dn CN=S_ASA_LDAP,OU=service accounts,OU=Users,
OU=CompanyXYZ HQ,DC=CompanyXYZ,DC=com
server-type microsoft
ldap-attribute-map ASAMAP
!
tunnel-group ciscovpn general-attributes
authentication-server-group LDAP-Auth2-AD
tunnel-group DefaultRAGroup general-attributes
authentication-server-group LDAP-Auth2-AD
group-policy DfltGrpPolicy attributes
vpn-simultaneous-logins 0

Cisco IP SLA

Senerio 1 : Sla Monitor with Route Map

ip sla monitor responder
ip sla monitor 1
type http operation get url http://www.cisco.com source-ipaddr 172.16.250.254
ip sla monitor schedule 1 life forever start-time now

!
!

track 1 rtr 1 reachability
delay down 180 up 180
!
ip local
policy route-map 1
!
route-map 1 permit 10
match ip address 150
set ip next-hop 192.168.50.250
!
ip route 0.0.0.0 0.0.0.0
192.168.50.250 track 1
ip route 0.0.0.0 0.0.0.0 172.16.18.10 10
!
access-list
150 permit ip host 172.16.250.254 any

!
!

Senerio 2 : IP SLA Monitor Static Floating Route :

ip sla 1
icmp-echo 10.1.1.1
timeout 1000
frequency 3
threshold 2

!

ip sla schedule 1 life forever start-time now
!
track 10 rtr 1 reachability

!
! Tagging the static route with the tracking object 10 and adjusting the AD of the
! floating static route to a higher value

!
ip route 0.0.0.0 0.0.0.0 172.16.1.1 track 10

!
ip route 0.0.0.0 0.0.0.0 172.16.1.5 254

!
!

Senerio 3 : IP SLA Monitor Ipsec Vpn :

In order to keep  Ipsec vpn active and always up with
crypto isakmp sa association.

Configured and Tested out on Cisco 850.

!

ip sla 1
icmp-echo 172.16.0.11 source-interface vlan 1
timeout 1000
frequency 3
threshold 2
!
ip sla schedule 1 life forever start-time now
!
!

ip sla 2
icmp-echo 172.18.192.10 source-interface vlan 1
timeout 1000
frequency 3
threshold 2
!
ip sla schedule 2 life forever start-time now
!
!
Senerio 4 : IP SLA DEFAULT ROUTE REDUNTANT…

ip sla monitor responder
ip sla monitor 10
http get
http://www.cisco.com source-ip 192.168.0.254
frequency 60
timeout 30
ip sla schedule 10 life forever start-time now

!
!
ip local policy route-map 1
!

route-map 1 permit 10
match ip address 99

set ip next-hop verify-availability 85.234.95.240 1 track 10
!
!

The first static route is only valid if the sla is successful. The second static route has an AD of 254
and will only make it into the routing table if no other matching route (default route – 85.234.95.240).

!
ip route 0.0.0.0 0.0.0.0 85.234.95.240 track 10
ip route 0.0.0.0 0.0.0.0 192.168.0.222 254
!
access-list 99 permit ip host 192.168.0.254 any

set ip next-hop verify-availability
Normally set ip next-hop will forward packets when the route-map is matched regardless
if the next hop is alive or not. Adding the verify-availability keyword, the router will check
the next hop availability via CDP before forwarding the packets, and when next-hop is dead,
the packets will be routed through the normal routing table
.


Show ip sla statistics

Cisco ASA Static Service Port NAT..

WAN INBOUND SERVICES NAT..

Dynamic Nat :

object-group network Public_IP_196
description Dynamic NaT Public_IP
network-object host 194.75.244.196
!
object network Private_Lan
Description Private Lan Network
subnet 172.16.0.0 255.255.0.0
nat (HQ_LAN,PUBLIC) dynamic interface

!
!

Service Port Translation (PAT) Configuration :

PORT 81

object-group network Public_IP_197
description Public_IP
network-object host 194.75.244.197
!
object network Private_IP_1.28_81
host 172.16.1.28
description Private IP Crystal Report
nat (HQ_LAN,PUBLIC) static Public_IP_197 service tcp 81 81
!
object-group service Obj-Service_81 tcp
port-object eq 81
!
!

Here you configure Inbound ACL :

access-list Public_access_in line 12 remark Crystal_Reports
access-list Public_access_in line 13 extended permit tcp any object Private_IP_1.28_81
object-group Obj-Service_81

!

Here you Configure a Static NaT with added reverse NaT
Translation
:

nat (HQ_LAN,PUBLIC)  source static Private_IP_1.28_81 Public_IP_197 destination static Public_IP_197 Private_IP_1.28_81

PORT 443

object network Private_IP_1.36_https
description Private IP SSL Front End Mail
host 172.16.1.36
nat (HQ_LAN,PUBLIC) static Public_IP_197 service tcp 443 443
!
object-group service Obj-Service_https tcp
port-object eq 443
!
access-list Public_access_in line 14 remark Front_End_Mail
access-list Public_access_in line 15 extended permit tcp any object Private_IP_1.36_https
object-group Obj-Service_https

!
nat (HQ_LAN,PUBLIC) source static Private_IP_1.36_https Public_IP_197 destination static Public_IP_197 Private_IP_1.36_https

PORT 80

object network Private_IP_1.20_http
description Private_IP IT Helpdesk
host 172.16.1.20
nat (HQ_LAN,PUBLIC) static Public_IP_197 service tcp 80 80

!
object-group service Obj-Service_http tcp
port-object eq 80
!
access-list Public_access_in line 16 remark Front_End_Mail
access-list Public_access_in line 17 extended permit tcp any object Private_IP_1.20_http
object-group Obj-Service_http
!
nat (HQ_LAN,PUBLIC) source static Private_IP_1.20_http Public_IP_197 destination static Public_IP_197 Private_IP_1.20_http

!
!

PORT 443

object-group network Public_IP_199
description Public_IP
network-object host 194.75.244.199
!
object network Private_IP_1.23_https
description Private_IP SSL Intranet
host 172.16.1.23
nat (HQ_LAN,PUBLIC) static Public_IP_199 service tcp 443 443
!
!
access-list Public_access_in line 18 remark SSL_Intranet
access-list Public_access_in line 19 extended permit tcp any object Private_IP_1.23_https
object-group Obj-Service_https
!
nat (HQ_LAN,PUBLIC) source static Private_IP_1.23_https Public_IP_199 destination static Public_IP_199 Private_IP_1.23_https

PORT 80

object network Private_IP_1.23_http
description Private_IP Intranet
host 172.16.1.23
nat (HQ_LAN,PUBLIC) static Public_IP_199 service tcp 80 80

!
!
access-list Public_access_in line 20 remark HTTP_Intranet
access-list Public_access_in line 21 extended permit tcp any object Private_IP_1.23_http
object-group Obj-Service_http

!
nat (HQ_LAN,PUBLIC) source static Private_IP_1.23_http Public_IP_199 destination static Public_IP_199 Private_IP_1.23_http

!
!

PORT 25

object-group network Public_IP_200
description Public_IP
network-object host 194.75.244.200
!

object network Private_IP_1.26_smtp
description Private_IP Sophos Mail Filter
host 172.16.1.26
nat (HQ_LAN,PUBLIC) static Public_IP_200 service tcp smtp smtp

!
object service Obj-Service_smtp
service tcp destination eq smtp
!

object-group service Obj-Service_sophos tcp
port-object eq smtp
port-object eq 143
port-object eq 110
port-object eq 80
!

access-list Public_access_in line 22 remark Sophos_Mail_Filter
access-list Public_access_in line 23 extended permit tcp any object Private_IP_1.26_smtp object-group Obj-Service_sophos

!
nat (HQ_LAN,PUBLIC) source dynamic Private_IP_1.26_smtp Public_IP_200 destination static Public_IP_200 Public_IP_200 service Obj-Service_smtp Obj-Service_smtp

PORT 80

object network Private_IP_1.26_http
description Private_IP Sophos Mail Filter
host 172.16.1.26
nat (HQ_LAN,PUBLIC) static Public_IP_200 service tcp 80 80

!
!

nat (HQ_LAN,PUBLIC) source static Private_IP_1.26_http Public_IP_200 destination static Public_IP_200 Private_IP_1.26_http

PORT 143

object network Private_IP_1.26_imap
description Private_IP Sophos Mail Filter
host 172.16.1.26
nat (HQ_LAN,PUBLIC) static Public_IP_200 service tcp 143 143

!
object-group service Obj-Service_imap tcp
port-object eq 143
!
!

nat (HQ_LAN,PUBLIC) source static Private_IP_1.26_imap Public_IP_200 destination static Public_IP_200 Private_IP_1.26_imap

PORT 110

object network Private_IP_1.26_pop3
description Private_IP Sophos Mail Filter
host 172.16.1.26
nat (HQ_LAN,PUBLIC) static Public_IP_200 service tcp 110 110

!
object-group service Obj-Service_pop3 tcp
port-object eq 110
!
!

nat (HQ_LAN,PUBLIC) source static Private_IP_1.26_pop3 Public_IP_200 destination static Public_IP_200 Private_IP_1.26_pop3

!
!

packet-tracer input HQ_LAN tcp 172.16.1.26 25 194.75.244.200 25

Cisco ASA v8 Policy Based NaT

Policy Based NaTing

object network obj-any
subnet 0.0.0.0 0.0.0.0
!
object service obj-icmp
service icmp
!
nat (outside,outside) source dynamic obj-any interface destination obj-any obj-any
service obj-icmp obj-icmp

!
!

So for example we want to NAT our internal (real) addresses to a public (mapped)
address only if they are destined for a particular destination
.

We begin by creating our first network object and enter our inside network addresses.

(config)# object network NAT_INSIDE_HOSTS
(config-network-object)#subnet 192.168.1.0 255.255.255.0

We then create a separate network object and specify our public (mapped) address.

(config)# object network NAT_PUBLIC
(config-network-object)#host 10.1.1.1

And then create a third object for our destination hosts our inside users will be accessing.

(config)# object network NAT_PUBLIC_HOSTS
(config-network-object)#host 172.31.1.1

We can now create our NAT rule using the three network objects above.

(config)#nat (inside,outside) source dynamic NAT_INSIDE_HOSTS NAT_PUBLIC
destination static NAT_PUBLIC_HOSTS NAT_PUBLIC_HOSTS


!
!

If we wanted to only NAT our inside hosts to our public address when they were
attempting to access the public hosts above on a specific port we use the second type
of object, the service object like so
.

(config)# object service DESTINATION_PORT
(config-network-object)#service tcp destination eq smtp
!
(config)#nat (inside,outside) source dynamic NAT_INSIDE_HOSTS NAT_PUBLIC
destination static NAT_PUBLIC_HOSTS NAT_PUBLIC_HOSTS service
DESTINATION_PORT DESTINATION_PORT

Now your probably wondering why I’ve entered the object group NAT_PUBLIC_HOSTS
twice in each of the NAT rules above, this is due to the behavior of identity NAT,
when entering the NAT
command after the ‘destination static’ keywords we are given the
option of specifying a ‘real’ address and a ‘mapped’ address,

which would come in handy if for example we wanted to NAT both the destination and
source addresses of traffic at the same time in one rule.

However for this example and for the majority of real life configuration scenarios you will
want to keep the original destination address as this is likely to be a public address on the
internet and you do this by configuring ‘Identity NAT’ by specifying the same address,

In this case 172.31.1.1, for both the real and mapped addresses, the same applies for the
services,  i.e. source and destination ports as shown in the final NAT rule above.

Traffic Rate Limiting on Cisco ASA 5510

We want to rate limit a local internal host when accessing a specific
external public server. The local host is 192.168.1.10 and the external
public server is 100.100.100.1.


We need to limit the traffic to 100kbps and burst size 8000
.

Configuration Snippet :

ASA(config)#access-list rate-limit-acl extended permit ip any any

ASA(config)#class-map rate-limit
ASA(config-cmap)#match access-list rate-limit-acl

ASA(config)#policy-map limit-policy
ASA(config-pmap)#class rate-limit
ASA(config-pmap-c)#police input 2000000 375000
ASA(config-pmap-c)#police output 2000000 375000

Assign to Interface :

ASA(config)#service-policy limit-policy interface outside

IPSEC VPN Redundancy / Failover, over Redundant ISP Links

A) Setup the VPN on the ASA to use primary and secondary ISP links
for VPN redundancy

B) Setup the remote VPN endpoints to use the headend ASA’s primary and
secondary ISP links as VPN peers (whichever is active)

C) Setup ISP redundancy with for example, SLA monitoring

Now given that we are using two interfaces “Primary” and “Secondary”,
we need to mention these as peer Ip addresses on the remote end, as shown below :

crypto map Outside_map 20 match address crypto-acl
crypto map Outside_map 20 set peer 10.10.10.1   20.20.20.1
(Which means, the primary set peer value is 10.10.10.1,
and if is down, device will try for
20.20.20.1 ip address for tunnel)

crypto map Outside_map 20 set transform-set ESP-3DES-MD5

After this, we need to setup pre-shared keys for ip addresses of both primary
and secondary ISP interfaces on the Headend ASA,

Since when a connection is needed to either primary or secondary interface
ip address, we should have a tunnel-group with matching pre-shared key to
complete the ISAKMP negotiation:

tunnel-group 172.16.10.1 type ipsec-l2l
tunnel-group 172.16.10.1 ipsec-attributes
pre-shared-key *

!
!

tunnel-group 172.16.20.1 type ipsec-l2l
tunnel-group 172.16.20.1 ipsec-attributes
pre-shared-key *

interface Ethernet0/0
nameif primary
security-level 0
ip address 172.16.10.1 255.255.255.0

!
interface Ethernet0/1
nameif backup
security-level 0
ip address 172.16.20.1 255.255.255.0
!
!

route primary  0.0.0.0 0.0.0.0 172.16.10.10 1
route backup   0.0.0.0 0.0.0.0 172.16.20.10 254

!
sla monitor 123
type echo protocol ipIcmpEcho 10.0.0.1 interface outside
num-packets 3
frequency 10
!
sla monitor schedule 123 life forever start-time now
!

track 1 rtr 123 reachability

Use-Cases:

===========================================

  1. Primary ISP is up and running, with this the VPN will be formed
    with the “Primary” interface, because the SLA monitoring refereed
    under Part 1 above, will put the route,

    “route Primary 0.0.0.0 0.0.0.0 172.16.10.10 1” into effect for routing
    packets, and the
    “crypto map VPN-map interface Primary”
    will be chosen.
  2. If the Primary ISP goes down, then the SLA monitoring will detect that
    the Primary ISP is down and the route

    “route Backup 0.0.0.0 0.0.0.0 172.16.20.10 254” will be chosen.
    With this the “crypto map VPN-map interface Backup” entry will take effect
    because this is the outgoing interface that will be chosen for VPN traffic.
  3. If the Primary ISP comes back up now, SLA tracking will detect this
    and the route
    “route Primary 0.0.0.0 0.0.0.0 172.16.10.10 1” &
    “crypto map VPN-map interface Primary” will be chosen and
    Primary ISP will be chosen for VPN tunnel negotiations.

CISCO ASA SLA Monitor

interface Ethernet0/0
nameif primary
security-level 0
ip address 172.16.10.1 255.255.255.0
!

interface Ethernet0/1
nameif backup
security-level 0
ip address 172.16.20.1 255.255.255.0

!
!
route primary  0.0.0.0 0.0.0.0 172.16.10.10 1

route backup   0.0.0.0 0.0.0.0 172.16.20.10 254
!
sla monitor 123
type echo protocol ipIcmpEcho 10.0.0.1 interface outside
num-packets 3
frequency 10

!
sla monitor schedule 123 life forever start-time now

!
track 1 rtr 123 reachability

CISCO ASA VER 8.0 Ipsec Base Configuration

CISCO ASA VER 8.0 Base Configuration :

ASA Version 8.0(2)
!
hostname ciscoasa
domain-name waves.uk.net
enable password 0 globalwave encrypted
names
dns-guard

!
interface Ethernet0/0
description WAN Interface
nameif Outside
security-level 0
ip address <<IP_ADDRESS><SUBNET_MASK>>

!
interface Ethernet0/1
description LAN Interface
nameif Inside
security-level 100
ip address
<<IP_ADDRESS><SUBNET_MASK>>
!
interface Ethernet0/2
description COLO Interface
nameif COLO
security-level 100
ip address
<<IP_ADDRESS><SUBNET_MASK>>
!
interface Ethernet0/3
nameif DMZ
security-level 100
ip address
<<IP_ADDRESS><SUBNET_MASK>>
!
interface Management0/0
nameif management
security-level 100
ip address
<<IP_ADDRESS><SUBNET_MASK>>
management-only
!

passwd 0 globalwave encrypted
boot system disk0:/asa802-k8.bin
clock timezone PST -8
clock summer-time PDT recurring 1 Sun Apr 2:00 last Sun Oct 2:00
dns domain-lookup Outside
dns server-group DefaultDNS
name-server 80.16.74.30
name-server 80.16.74.31
!
!

object network obj-local_ipsec_tunnel
subnet <<LOCAL_IP_ADDRESS><SUBNET_MASK>>
!

object network
obj-remote_ipsec_tunnel
subnet <<REMOTE_IP_ADDRESS><SUBNET_MASK>>
!
object network
obj-private_lan
subnet <<LOCAL_IP_ADDRESS><SUBNET_MASK>>
nat (inside,outside) dynamic <<INTERNET_IP_ADDRESS>
!
nat (inside,COLO)
source static obj-local_ipsec_tunnel obj-local_ipsec_tunnel destination static obj-remote_ipsec_tunnel obj-remote_ipsec_tunnel
!
access-list COLO_cryptomap_1 extended permit ip
<<LOCAL_IP_ADDRESS><SUBNET_MASK>> <<REMOTE_IP_ADDRESS><SUBNET_MASK>>
!
!
pager lines 24
logging enable
logging asdm informational
!
mtu outside 1500
mtu inside 1500
mtu COLO 1500
mtu management 1500
mtu DMZ 1500
!
!
no asdm history enable
arp timeout 14400
!
!
route outside 0.0.0.0 0.0.0.0
<<PUBLIC_IP_ADDRESS>
!
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout uauth 0:05:00 absolute
!
no http server enable
!
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
!
crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
!
crypto map Colo_map 1 match address COLO_cryptomap_1
crypto map Colo_map 1 set peer <<PEER_PUBLIC_IP_ADDRESS>
crypto map Colo_map 1 set transform-set ESP-AES-128-SHA
crypto map Colo_map 1 set security-association lifetime kilobytes 86400
crypto map Colo_map 1 set security-association lifetime kilobytes 9908000
!
crypto map Colo_map interface COLO
crypto isakmp enable COLO
!

!
crypto isakmp policy 10
authentication pre-share
encryption 3des
hash SHA
group 1
lifetime 86400
!
!
no crypto isakmp nat-traversal
!
telnet timeout 5
ssh timeout 5
console timeout 15
!
management-access Inside
!
threat-detection basic-threat
threat-detection statistics
!
class-map inspection_default
match default-inspection-traffic
!
!
policy-map global_policy
class inspection_default
inspect ftp
inspect h323 h225
inspect h323 ras
inspect rsh
inspect rtsp
inspect esmtp
inspect sqlnet
inspect skinny
inspect sunrpc
inspect xdmcp
inspect sip
inspect netbios
inspect tftp
inspect icmp
!
tunnel-group <PEER_PUBLIC_IP_ADDRESS> type ipsec-l2l
tunnel-group <PEER_PUBLIC_IP_ADDRESS> ipsec-attributes
pre-shared-key globalwave
!
!

Cisco ASA IOS Upgrade

How do I upgrade ASA to the latest version?

Once you’ve downloaded the necessary software, follow these steps :

1. Back up your current configuration file using TFTP. Alternatively,
you can just paste it into Notepad and save it on your hard drive.
Just make sure you have a copy somewhere in case something goes wrong.

2. Determine which version of ASA software you have now. Here’s an example :

ASA5510# sh ver

Cisco Adaptive Security Appliance Software Version 7.0(6)
Device Manager Version 5.0(6)

ASA5510# dir

Directory of disk0:/
5 -rw- 5474304 00:05:00 Jan 01 2003 asa706-k8.bin
675 -rw- 5823980 16:34:26 Nov 07 2006 asdm506.bin

255426560 bytes total (244064256 bytes free)

ASA5510#

3. You can use TFTP to move the image to the ASA. Here’s an example :

ASA5510# copy tftp disk0

Address or name of remote host []? 10.253.15.77
Source filename []? asa802-k8.bin
Destination filename [disk0]? disk0:asa802-k8.bin

Accessing tftp://10.253.15.77/asa802-k8.bin…!!!!!! (truncated)
Writing file disk0:/asa802-k8.bin… !!!!! (truncated)

14524416 bytes copied in 118.210 secs (123088 bytes/sec)

Cisco ASA Ver 8 Notes

Ip address and Security Level Assignment :

interface e0/0
nameif outside
security-level 0
ip address 10.10.10.1 255.255.255.248
!
!

Dynamic NAT/PAT :

object network obj-192.168.1.0
subnet 192.168.1.0 255.255.255.0
nat (inside,outside) dynamic 209.165.201.3
!
object network obj-10.1.1.0
subnet 10.1.1.0 255.255.255.0
nat (dmz,outside) dynamic 209.165.201.3

!
!

Static NAT/PAT :

object network obj-10.1.1.16
host 10.1.1.16
nat (inside,outside) static 10.1.2.45 service tcp 8080 www
!
object network obj_any
subnet 0.0.0.0 0.0.0.0
nat (inside,outside) dynamic interface
!
!

NAT Control :

Four interfaces : inside, outside, dmz, and mgmt

!

object network obj_any
subnet 0.0.0.0 0.0.0.0
nat (inside,outside) dynamic obj-0.0.0.0
!
object network obj-0.0.0.0
host 0.0.0.0
!
object network obj_any-01
subnet 0.0.0.0 0.0.0.0
nat (inside,mgmt) dynamic obj-0.0.0.0
!
object network obj_any-02
subnet 0.0.0.0 0.0.0.0
nat (inside,dmz) dynamic obj-0.0.0.0
!
object network obj_any-03
subnet 0.0.0.0 0.0.0.0
nat (mgmt,outside) dynamic obj-0.0.0.0
!
object network obj_any-04
subnet 0.0.0.0 0.0.0.0
nat (dmz,outside) dynamic obj-0.0.0.0
!
object network obj_any-05
subnet 0.0.0.0 0.0.0.0
nat (dmz,mgmt) dynamic obj-0.0.0.0

!
!

DNS Rewrite :

object network obj-192.168.100.10
host 192.168.100.10
nat (inside,outside) static 172.20.1.10 dns

!
!

Static : PAT (Port Forwarding)

access-list inbound extended permit tcp any object obj-192.168.1.10-01 eq smtp
access-list inbound extended permit tcp any object obj-192.168.1.10 eq www
!
!
object network obj-192.168.1.10
host 192.168.1.10
!
object network obj-192.168.1.10-01
host 192.168.1.10
!
!
object network obj-192.168.1.10
nat (inside,outside) static interface service tcp www www
!
object network obj-192.168.1.10-01
nat (inside,outside) static interface service tcp smtp smtp
!
!

No NAT :

object network obj-192.168.1.10
subnet 192.168.1.10 255.255.255.0
!
object network obj-66.67.70.0
subnet 66.67.70.0 255.255.255.0
!
nat (inside,any) source static obj-192.168.1.10.0 obj-192.168.1.10.0 destination static obj-66.67.70.0 obj-66.67.70.0
!
!

Access Lists :

access-list inbound extended permit tcp any object obj-10.254.254.5
!
access-group inbound in interface outside
!
!
object network obj-10.254.254.5
host 10.254.254.5
!
!
nat (inside,outside) static 123.123.123.123 service tcp www www