Networking-Blog

My WordPress Blog

Simplify Linux PPTP Server Configuration

yum install pptpd
apt-get pptpd

At this point, you should have a working pptp daemon.
This is a matter of personal preference, but I like to go ahead and start pptpd just to
make sure that the service is functioning and that it opens up the

PPTP port (1723) on the machine:

[user@hostname ~]# /etc/init.d/pptpd start
Starting pptpd:                                            [  OK  ]
!
[user@hostname ~]# telnet localhost 1723
Trying 127.0.0.1…
Connected to localhost.
Escape character is ‘^]’.

3 configuration files we need to worrry about.  They are :

/etc/pptpd.conf
/etc/ppp/options.pptpd

/etc/sysctl.conf

!

Let’s start with /etc/pptpd.conf

edit file :
nano /etc/pptpd.conf

# Currently using Microsoft Client Profile:
option /etc/ppp/MSpptpd-options

# Use linux client profile:
#option /etc/ppp/LXpptpd-options

#       Turns on (more) debugging to syslog
#debug
logwtmp
speed 57600

# Specifies the local and remote IP address ranges.
localip 10.20.254.254
# listen 10.20.254.254
# remoteip 10.10.10.249-253

!

Now, on to /etc/ppp/options.pptpd

As stated previously, options.pptpd is concered with how the VPN will authenticate
and encrypt.  Below are the options that you actually care about
:

name pptpd
require-mschap-v2
require-mppe-128
ms-dns 192.168.1.73
lock
nobsdcomp
auth
require-mppe
noipx ## you don’t need IPX
mtu 1490 ## may help your linux client from disconnecting
mru 1490
## may help your linux client from disconnecting

!

Lastly, /etc/sysctl.conf :

Edit this file and make sure the net.ipv4.ip_forward is set to 1.
This enables ip packet forwarding on the LAN which is required if you expect your
VPN users to be able to access any other resources on the network besides the
VPN server itself.

net.ipv4.ip_forward = 1

Setting up Users :

The chap-secrets file in the /etc/ppp/ directory.
vi /etc/ppp/chap-secrets

# client        server secret           IP addresses
rich              pptpd         apassword     80.40.0.0/13
geoff             pptpd         apassword     212.219.0.0/14

Test and Troubleshoot
:

/etc/init.d/pptpd stop
/etc/init.d/pptpd start

Sumarize Firewall Rules :

1. Allow GRE-47/pptp-1723 on internet facing router.
2. Configure a port forward for pptp-1723 to internal lan server ip address.
3. Allow GRE traffic out from pptp server.
4. Allow pptp tcp port 1723 out from pptp server with a source nat of 1723 to remote host or any
.

Cisco ASA Track Backup Route

interface Ethernet0
nameif outside
security-level 0
ip address 10.200.159.2 255.255.255.248
!
interface Ethernet1
nameif backup

!— The interface attached to the Secondary ISP.
!— “backup” was chosen here, but any name can be assigned.

security-level 0
ip address 10.250.250.2 255.255.255.248
!

interface Ethernet2
nameif inside
security-level 100
ip address 172.16.1.163 255.255.255.0
!
!

global (outside) 1 interface
global (backup) 1 interface

nat (inside) 1 172.16.1.0 255.255.255.0

!— NAT Configuration for Outside and Backup


route outside 0.0.0.0 0.0.0.0 10.200.159.1 1 track 1


!— Enter this command in order to track a static route.
!— This is the static route to be installed in the routing
!— table while the tracked object is reachable.  The value after
!— the keyword “track” is a tracking ID you specify.


route backup 0.0.0.0 0.0.0.0 10.250.250.1 254


!— Define the backup route to use when the tracked object is unavailable.
!— The administrative distance of the backup route must be greater than
!— the administrative distance of the tracked route.
!— If the primary gateway is unreachable, that route is removed
!— and the backup route is installed in the routing table
!— instead of the tracked route.

!
!

sla monitor 123
type echo protocol ipIcmpEcho 10.0.0.1 interface outside
num-packets 3
frequency 10

!— Configure a new monitoring process with the ID 123.  Specify the
!— monitoring protocol and the target network object whose availability the tracking
!— process monitors.  Specify the number of packets to be sent with each poll.
!— Specify the rate at which the monitor process repeats (in seconds).

sla monitor schedule 123 life forever start-time now

!— Schedule the monitoring process.  In this case the lifetime
!— of the process is specified to be forever.  The process is scheduled to begin
!— at the time this command is entered.  As configured, this command allows the
!— monitoring configuration specified above to determine how often the testing
!— occurs.  However, you can schedule this monitoring process to begin in the
!— future and to only occur at specified times.

!
track 1 rtr 123 reachability

!— Associate a tracked static route with the SLA monitoring process.
!— The track ID corresponds to the track ID given to the static route to monitor:
!— route outside 0.0.0.0 0.0.0.0 10.0.0.2 1 track 1
!— “rtr” = Response Time Reporter entry.  123 is the ID of the SLA process
!— defined above.

!
!

VERIFY

Displays the SLA commands in the configuration
:

show running-config sla monitor

sla monitor 123
type echo protocol ipIcmpEcho 10.0.0.1 interface outside
num-packets 3
frequency 10
sla monitor schedule 123 life forever start-time now

Displays the current configuration settings of the operation :

show sla monitor configuration

pix# show sla monitor configuration 123
IP SLA Monitor, Infrastructure Engine-II.
Entry number: 123
Owner:
Tag:
Type of operation to perform: echo
Target address: 10.0.0.1
Interface: outside
Number of packets: 3
Request size (ARR data portion): 28
Operation timeout (milliseconds): 5000
Type Of Service parameters: 0x0
Verify data: No
Operation frequency (seconds): 10
Next Scheduled Start Time: Start Time already passed
Group Scheduled : FALSE
Life (seconds): Forever
Entry Ageout (seconds): never
Recurring (Starting Everyday): FALSE
Status of entry (SNMP RowStatus): Active
Enhanced History:


Displays the operational statistics of the SLA operation
:

show sla monitor operational-state

Before the primary ISP fails, this is the operational state:

show sla monitor operational-state 123
Entry number: 123
Modification time: 13:59:37.824 UTC Thu Oct 12 2006
Number of Octets Used by this Entry: 1480
Number of operations attempted: 367
Number of operations skipped: 0
Current seconds left in Life: Forever
Operational state of entry: Active
Last time this entry was reset: Never
Connection loss occurred: FALSE
Timeout occurred: FALSE
Over thresholds occurred: FALSE
Latest RTT (milliseconds): 1
Latest operation start time: 15:00:37.825 UTC Thu Oct 12 2006
Latest operation return code: OK
RTT Values:
RTTAvg: 1       RTTMin: 1       RTTMax: 1
NumOfRTT: 3     RTTSum: 3       RTTSum2: 3

After the primary ISP fails (and the ICMP echos time out), this is the operational state:

show sla monitor operational-state

Entry number: 123
Modification time: 13:59:37.825 UTC Thu Oct 12 2006
Number of Octets Used by this Entry: 1480
Number of operations attempted: 385
Number of operations skipped: 0
Current seconds left in Life: Forever
Operational state of entry: Active
Last time this entry was reset: Never
Connection loss occurred: FALSE
Timeout occurred: TRUE
Over thresholds occurred: FALSE
Latest RTT (milliseconds): NoConnection/Busy/Timeout
Latest operation start time: 15:03:27.825 UTC Thu Oct 12 2006
Latest operation return code: Timeout
RTT Values:
RTTAvg: 0       RTTMin: 0       RTTMax: 0
NumOfRTT: 0     RTTSum: 0       RTTSum2: 0

Confirm the Backup Route is Installed (CLI Method)

Use the show route command to determine when the backup route is installed.
Before the primary ISP fails, this is the routing table:

show route

Gateway of last resort is 10.200.159.1 to network 0.0.0.0

S    64.101.0.0 255.255.0.0 [1/0] via 172.22.1.1, inside
C    172.22.1.0 255.255.255.0 is directly connected, inside
C    10.250.250.0 255.255.255.248 is directly connected, backup
C    10.200.159.0 255.255.255.248 is directly connected, outside
S*   0.0.0.0 0.0.0.0 [1/0] via 10.200.159.1, outside


After the primary ISP fails, the static route is removed,
and the backup route is installed, this is the routing table:

show route

Gateway of last resort is 10.250.250.1 to network 0.0.0.0

S    64.101.0.0 255.255.0.0 [1/0] via 172.22.1.1, inside
C    172.22.1.0 255.255.255.0 is directly connected, inside
C    10.250.250.0 255.255.255.248 is directly connected, backup
C    10.200.159.0 255.255.255.248 is directly connected, outside
S*   0.0.0.0 0.0.0.0 [254/0] via 10.250.250.1, backup

Troubleshoot

Debug Commands

Displays progress of the echo operation :

debug sla monitor
trace

The tracked object (primary ISP gateway) is up, and ICMP echos succeed.
The tracked object (primary ISP gateway) is down, and ICMP echos fail.

Displays errors that the SLA monitor process encounters :

debug sla monitor error

The tracked object (primary ISP gateway) is up, and ICMP succeeds.
The tracked object (primary ISP gateway) is down, and the tracked route is removed.

!— 10.0.0.1 is unreachable, so the route to the Primary ISP is removed.

Tracked Route is Removed Unnecessarily

If the tracked route is removed unnecessarily, ensure that your monitoring target
is always available to receive echo requests. In addition, ensure that the state
of your monitoring target (that is, whether or not the target is reachable) is
closely tied to the state of the primary ISP connection.


If you choose a monitoring target that is farther away than the ISP gateway,
another link along that route may fail or another device may interfere.
This configuration may cause the SLA monitor to conclude that the connection
to the primary ISP has failed and cause the security appliance to unnecessarily
fail over to the secondary ISP link.

For example, if you choose a branch office router as your monitoring target,
the ISP connection to your branch office could fail, as well as any other link
along the way. Once the ICMP echos that are sent by the monitoring operation fail,
the primary tracked route is removed, even though the primary ISP link is still active.

In this example, the primary ISP gateway that is used as the monitoring target is
managed by the ISP and is located on the other side of the ISP link.
This configuration ensures that if the ICMP echos that are sent by the monitoring
operation fail, the ISP link is almost surely down.

SLA Monitoring on ASA

Problem:

SLA monitoring does not work after the ASA is upgrade to version 8.0.

Solution:

The problem is possibly be due to the IP Reverse-Path command configured in the
OUTSIDE interface.
Remove the command in ASA and try to check the SLA Monitoring.


ASA Ipsec VPN Object-Group

Create an IPSEC VPN Additional tunnel using Internet Facing Interface with NAT-T enable :

Create Object-Group Network for Source Network :

object-group network MPLS_Host_to_BlueSource
description MPLS Sites-Host-Address
network-object host 172.16.0.95

Create Object-Group Network for Remote Network :

object-group network BLUESource_Network
description Blue Source private IP address
network-object 10.99.0.0 255.255.0.0

Create a Object-Group Service for TCP ports for remote traffic allowed through the IPSEC Tunnel :

object-group service BLUE_SOURCE_PORTS tcp
description Inbound Access
port-object eq 3389
port-object range 9998 9999

Create a Object-Group Service for ICMP traffic :

object-group icmp-type BLUE-SOURCE-ICMP-INBOUND
description Permit necessary inbound ICMP traffic
icmp-object echo
icmp-object echo-reply
icmp-object unreachable
icmp-object time-exceeded

NAT Traversal allows ESP packets to pass through one or more NAT devices.
When you enable NAT-T, the security appliance automatically opens port 4500 on all IPsec enabled interfaces.

isakmp nat-traversal 3600

Create a Rule to Disable NAT :

access-list MPLS_nat0_inbound extended permit ip object-group MPLS_Host_to_BlueSource object-group BLUESource_Network

Assign NAT Rule To Interface :

nat (MPLS) 0 access-list MPLS_nat0_inbound outside

Access-list from MPLS Host to BlueSource Network:

Allow only ICMP Traffic :

INBOUND Rule for traffic leaving the interface  :

access-list MPLS_access_in extended permit tcp object-group MPLS_Host_to_BlueSource object-group BLUESource_Network object-group BLUE-SOURCE-ICMP-INBOUND

Access-list from Blue Source to MPLS Host :

OUTBOUND Rule for traffic coming into interface  :

access-list MPLS_access_out extended permit tcp object-group BLUESource_Network object-group MPLS_Host_to_BlueSource object-group BLUE_SOURCE_PORTS
!
access-list MPLS_access_out extended permit icmp object-group BLUESource_Network object-group MPLS_Host_to_BlueSource object-group BLUE-SOURCE-ICMP-INBOUND
!
object-group BLUESource_Network
access-list MPLS_access_out extended deny ip object-group BLUESource_Network any
!
access-list MPLS_access_out extended permit ip any any

Assign ACL to Outbound of Interface :

access-group MPLS_access_out out interface MPLS

Assign Interface Crypto Map :

crypto map BlueSource_map interface PublicIP
crypto isakmp enable PublicIP

Create Access-List for Source Address to Remote Address :
Keep ACL  naming convention to match Crypto Map sequence no.

access-list BlueSource_cryptomap_390 extended permit ip object-group MPLS_Host_to_BlueSource object-group BLUESource_Network

Create IPSEC Crypto map Statement + Sequence No :

crypto map BlueSource_map 390 match address BlueSource_cryptomap_390
crypto map BlueSource_map 390 set peer 113.112.208.128
crypto map BlueSource_map 390 set transform-set ESP-3DES-SHA
crypto map BlueSource_map 390 set security-association lifetime seconds 28800
crypto map BlueSource_map 390 set security-association lifetime kilobytes 4608000

Create Tunnel-Group for assigned Public Address of Peer and Pre-shared-key :

tunnel-group 113.112.208.128  type ipsec-l2l
tunnel-group 113.112.208.128   ipsec-attributes
pre-shared-key S1u350vd7
exit

Create ISAKMP Phase 1 Policy to match Transform-Set ESP-3DES-SHA

crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
!

crypto isakmp policy 40
authentication pre-share
encryption 3des
hash sha
group 2
lifetime 86400

Cisco ASA Create Sub-Interface

interface GigabitEthernet0/2
speed 100
duplex full
no nameif
no security-level
no ip address
!
interface GigabitEthernet0/2.15
vlan 15
nameif MPLS
security-level 99
ip address 172.18.192.251 255.255.255.0 standby 172.18.192.250
!
interface GigabitEthernet0/2.19
vlan 19
nameif Xrio
security-level 50
ip address 192.168.10.1 255.255.255.0

Create Static Routes :

route Xrio 10.2.103.0 255.255.255.0 192.168.10.2 1
route Xrio 10.2.180.0 255.255.255.0 192.168.10.2 1
route Xrio 10.2.250.0 255.255.255.0 192.168.10.2 1

Troubleshoot Connections through the PIX and ASA

Make sure logging is enabled. The logging level needs to be set to debug. Logging can be sent to various locations.
This example uses the ASA log buffer. You might need an external logging server in production environments.

ciscoasa(config)#logging enable
ciscoasa(config)#logging buffered debugging

The user pings the inside interface of the ASA (ping 192.168.1.1). This output is displayed.

ciscoasa#show logging

!— Output is suppressed.

%ASA-6-302020: Built ICMP connection for faddr 192.168.1.50/512
gaddr 192.168.1.1/0 laddr 192.168.1.1/0
%ASA-6-302021: Teardown ICMP connection for faddr 192.168.1.50/512
gaddr 192.168.1.1/0 laddr 192.168.1.1/0

!— The user IP address is 192.168.1.50.

ASA Capture Feature

The administrator needs to create an access-list that defines what traffic the ASA needs to capture. After the access-list is defined, the capture command incorporates the access-list and applies it to an interface.

ciscoasa(config)#access-list inside_test permit icmp any host 192.168.1.1
ciscoasa(config)#capture inside_interface access-list inside_test interface inside

The user pings the inside interface of the ASA (ping 192.168.1.1). This output is displayed.

ciscoasa#show capture inside_interface
1: 13:04:06.284897 192.168.1.50 > 192.168.1.1: icmp: echo request

!— The user IP address is 192.168.1.50.

Note: In order to download the capture file to a system such as ethereal, you can do it as this output shows.

!— Open an Internet Explorer and browse with this https link format:

https://[<pix_ip>/<asa_ip>]/capture/<capture name>/pcap

Refer to ASA/PIX: Packet Capturing using CLI and ASDM Configuration Example in order to know more about Packet Capturing in ASA.

Debug

The debug icmp trace command is used to capture the ICMP traffic of the user.

ciscoasa#debug icmp trace

The user pings the inside interface of the ASA (ping 192.168.1.1). This output is displayed on the console.

ciscoasa#

!— Output is suppressed.

ICMP echo request from 192.168.1.50 to 192.168.1.1 ID=512 seq=5120 len=32
ICMP echo reply from 192.168.1.1 to 192.168.1.50 ID=512 seq=5120 len=32

!— The user IP address is 192.168.1.50.

In order to disable debug icmp trace, use one of these commands:

no debug icmp trace
undebug icmp trace

undebug all

Monitor syslog messages.

Search for the source IP address of the user that you located in Step 1. The user initiates application X.
The ASA administrator issues the show logging command and views the output.

ciscoasa#show logging

!— Output is suppressed.

%ASA-7-609001: Built local-host inside:192.168.1.50
%ASA-6-305011: Built dynamic TCP translation from inside:192.168.1.50/1107
to outside:172.22.1.254/1025
%ASA-6-302013: Built outbound TCP connection 90 for outside:172.22.1.1/80
(172.22.1.1/80) to inside:192.168.1.50/1107 (172.22.1.254/1025)

The logs reveal that the destination IP address is 172.22.1.1,
the protocol is TCP, the destination port is HTTP/80, and that traffic is sent to the outside interface.

Modify the capture filters.

The access-list inside_test command was previously used and is used here.

ciscoasa(config)#access-list inside_test permit ip host 192.168.1.50 any

!— This ACL line captures all traffic from 192.168.1.50
!— that goes to or through the ASA.

ciscoasa(config)#access-list inside_test permit ip any host 192.168.1.50 any

!— This ACL line captures all traffic that leaves
!— the ASA and goes to 192.168.1.50.

ciscoasa(config)#no access-list inside_test permit icmp any host 192.168.1.1
ciscoasa(config)#clear capture inside_interface

!— Clears the previously logged data.
!— The no capture inside_interface removes/deletes the capture.

The user initiates application X. The ASA administrator then issues the show capture inside_interface command and views the output.

ciscoasa(config)#show capture inside_interface
1: 15:59:42.749152 192.168.1.50.1107 > 172.22.1.1.80:
S 3820777746:3820777746(0) win 65535 <mss 1460,nop,nop,sackOK>
2: 15:59:45.659145 192.168.1.50.1107 > 172.22.1.1.80:
S 3820777746:3820777746(0) win 65535 <mss 1460,nop,nop,sackOK>
3: 15:59:51.668742 192.168.1.50.1107 > 172.22.1.1.80:
S 3820777746:3820777746(0) win 65535 <mss 1460,nop,nop,sackOK>

Cisco PIX Port forward

BTNET router is Internet facing and have a Cisco Pix connected to the inside Lan.
Need to port forward LDAP traffic to a Server sitting behind the Pix on the inside interface.

btnet:

ip nat inside source static udp 195.99.246.3 389 interface Serial1/0:0.1 389
ip nat inside source static tcp 195.99.246.3 389 interface Serial1/0:0.1 389
!
Extended IP access list 101
4 permit udp any any eq 389
5 permit udp any any eq 389
!

pix:

Interface ip Addresses:

ip address outside 195.99.246.3 255.255.255.240
ip address inside 172.16.2.253 255.255.255.0
!

name 172.16.2.50 MailServer
!
access-list outside_access_in permit udp any interface outside eq 389
access-list outside_access_in permit tcp any interface outside eq ldap
!

Static Port Forward:

static (inside,outside) tcp interface 389 MailServer 389 netmask 255.255.255.255 0 0
static (inside,outside) udp interface 389 MailServer 389 netmask 255.255.255.255 0 0
!

Diagnostics testing:

from external source internet:
!
telnet 195.99.246.3 389

On Pix:

show access-list outside_access_in
!
access-list outside_access_in line 14 permit udp any interface outside eq 389 (hitcnt=0)
access-list outside_access_in line 15 permit tcp any interface outside eq ldap (hitcnt=6)

B00m…counter hits…(hitcnt=6)

How to configure a firewall for domains and trusts

epmap           Port 135 TCP         DCE endpoint resolution
epmap           Port 135 UDP         DCE endpoint resolution
profile         Port 136 TCP         PROFILE Naming System
profile         Port 136 UDP         PROFILE Naming System
netbios-ns      Port 137 TCP         NETBIOS Name Service
netbios-ns      Port 137 UDP         NETBIOS Name Service
netbios-dgm     Port 138 TCP         NETBIOS Datagram Service
netbios-dgm     Port 138 UDP         NETBIOS Datagram Service
netbios-ssn     Port 139 TCP         NETBIOS Session Service
netbios-ssn     Port 139 UDP         NETBIOS Session Service

To establish a domain trust or a security channel across a firewall, the following ports must be opened. Be aware that there may be hosts functioning with both client and server roles on both sides of the firewall. Therefore, ports rules may have to be mirrored.

Windows NT

In this environment, one side of the trust is a Windows NT 4.0 trust, or the trust was created by using the NetBIOS names.

Collapse this tableExpand this table
Client Port(s) Server Port Service
137/UDP 137/UDP NetBIOS Name
138/UDP 138/UDP NetBIOS Netlogon and Browsing
1024-65535/TCP 139/TCP NetBIOS Session
1024-65535/TCP 42/TCP WINS Replication

Windows Server 2003 and Windows 2000 Server

For a mixed-mode domain that uses either Windows NT domain controllers or legacy clients, trust relationships between Windows Server 2003-based domain controllers and Windows 2000 Server-based domain controllers may necessitate that all the ports for Windows NT that are listed in the previous table be opened in addition to the following ports.

Note The two domain controllers are both in the same forest, or the two domain controllers are both in a separate forest. Also, the trusts in the forest are Windows Server 2003 trusts or later version trusts.

Client Port(s) Server Port Service
1024-65535/TCP 135/TCP RPC
1024-65535/TCP 1024-65535/TCP LSA RPC Services (*)
1024-65535/TCP/UDP 389/TCP/UDP LDAP
1024-65535/TCP 636/TCP LDAP SSL
1024-65535/TCP 3268/TCP LDAP GC
1024-65535/TCP 3269/TCP LDAP GC SSL
53,1024-65535/TCP/UDP 53/TCP/UDP DNS
1024-65535/TCP/UDP 88/TCP/UDP Kerberos
1024-65535/TCP 445/TCP SMB

Windows Server 2008/Windows Server 2008 R2

In a mixed-mode domain that consists of Windows Server 2003 domain controllers, Windows 2000 Server-based domain controllers, or legacy clients, the default dynamic port range is 1025 through 5000. Windows Server 2008 and Windows Server 2008 R2, in compliance with Internet Assigned Numbers Authority (IANA) recommendations, has increased the dynamic client port range for outgoing connections. The new default start port is 49152, and the default end port is 65535. Therefore, you must increase the RPC port range in your firewalls.

Client Port(s) Server Port Service
49152 -65535/UDP 123/UDP W32Time
49152 -65535/TCP 135/TCP RPC-EPMAP
49152 -65535/TCP 138/UDP Netbios
49152 -65535/TCP 49152 -65535/TCP RPC
49152 -65535/TCP/UDP 389/TCP/UDP LDAP
49152 -65535/TCP 636/TCP LDAP SSL
49152 -65535/TCP 3268/TCP LDAP GC
49152 -65535/TCP 3269/TCP LDAP GC SSL
53, 49152 -65535/TCP/UDP 53/TCP/UDP DNS
49152 -65535/TCP 135, 49152 -65535/TCP RPC DNS
49152 -65535/TCP/UDP 88/TCP/UDP Kerberos
49152 -65535/TCP/UDP 445/NP-TCP/NP-UDP SAM/LSA

Active Directory

For Active Directory to function correctly through a firewall, the Internet Control Message Protocol (ICMP) protocol must be allowed through the firewall from the clients to the domain controllers so that the clients can receive Group Policy information.

ICMP is used to determine whether the link is a slow link or a fast link. ICMP is a legitimate protocol that Active Directory uses for Group Policy detection and for Maximum Transfer Unit (MTU) detection. The Windows Redirector also uses ICMP to verify that a server IP is resolved by the DNS service before a connection is made.

Cisco: Stop Site-to-Site VPN Drop

By default, site-to-site VPNs timeout after 30 minutes of idle time. This is a pain for me when I first try to access a site and have the first few packets of my Remote Desktop session or ping or whatever drop. (Yes – those 3 seconds of my life are EXTREMELY valuable). Here’s the secret, straight from Cisco:
PIX/ASA 7.x and later

Enter the vpn-idle-timeout command in group-policy configuration mode or in username configuration mode in order to configure the user timeout period:

hostname(config)#group-policy DfltGrpPolicy attributes
hostname(config-group-policy)#vpn-idle-timeout none

Configure a maximum amount of time for VPN connections with the vpn-session-timeout command in group-policy configuration mode or in username configuration mode:

hostname(config)#group-policy DfltGrpPolicy attributes
hostname(config-group-policy)#vpn-session-timeout none

Cisco IOS Router

Use the crypto ipsec security-association idle-time command in global configuration mode or crypto map configuration mode in order to configure the IPsec SA idle timer. By default IPsec SA idle timers are disabled.

crypto ipsec security-association idle-time 
seconds 

Time is in seconds, which the idle timer allows an inactive peer to maintain an SA. Valid values for the seconds argument range from 60 to 86400.

Cisco Traversing a NAT device

 

Using NAT Traversal

Network Address Translation (NAT) and Port Address Translation (PAT) are implemented in many networks where IPSec is also used, but the number of incompatibilities that prevent IPSec packets from successfully traversing a NAT device.

PIX Firewall Version 6.3 provides a feature called “Nat Traversal,” as described by Version 2 and Version 3 of the draft IETF standard, UDP Encapsulation of IPsec Packets,” which is available at the following URL:

http://www.ietf.org/html.charters/ipsec-charter.html

NAT Traversal allows ESP packets to pass through one or more NAT devices. This feature is disabled by default.

Note NAT Traversal is supported for both dynamic and static crypto maps.

To enable NAT traversal, enter the following command:

isakmp nat-traversal [natkeepalive]
isakmp nat-traversal 20

Valid values for natkeepalive are 10 to 3600 seconds; the default is 20 seconds.

 

Enabling IPsec over NAT-T

NAT-T lets IPsec peers establish a connection through a NAT device. It does this by encapsulating IPsec traffic in UDP datagrams, using port 4500, thereby providing NAT devices with port information. NAT-T auto-detects any NAT devices, and only encapsulates IPsec traffic when necessary. This feature is disabled by default.

• The security appliance can simultaneously support standard IPsec, IPsec over TCP, NAT-T, and IPsec over UDP, depending on the client with which it is exchanging data.

• When both NAT-T and IPsec over UDP are enabled, NAT-T takes precedence.
• When enabled, IPsec over TCP takes precedence over all other connection methods.
• When you enable NAT-T, the security appliance automatically opens port 4500 on all IPsec enabled interfaces.

The security appliance supports multiple IPsec peers behind a single NAT/PAT device operating in one of the following networks, but not both:

• LAN-to-LAN
• Remote access

In a mixed environment, the remote access tunnels fail the negotiation because all peers appear to be coming from the same public IP address, that of the NAT device. Also, remote access tunnels fail in a mixed environment because they often use the same name as the LAN-to-LAN tunnel group (that is, the IP address of the NAT device).
This match can cause negotiation failures among multiple peers in a mixed LAN-to-LAN and remote access network of peers behind the NAT device.