Cisco ASA VPN Add
config t
name 10.2.135.0 test123
object-group network Comms_Remote_PrivateIP_Range
network-object 10.2.135.0 255.255.255.0
exit
access-list Colo_nat0_outbound extended permit ip object-group Comms_Remote_PrivateIP_Range 10.2.135.0 255.255.255.0
!
access-list Colo_cryptomap_1 extended permit ip object-group Comms_Remote_PrivateIP_Range 10.2.135.0 255.255.255.0
!
crypto map Colo_map 1 match address Colo_cryptomap_1
crypto map Colo_map 1 set peer 1.1.1.1
crypto map Colo_map 1 set security-association lifetime seconds 86400
crypto map Colo_map 1 set security-association lifetime kilobytes 9908000
crypto map Colo_map 1 set transform-set ESP-AES-128-SHA
tunnel-group 1.1.1.1 type ipsec-l2l
tunnel-group 1.1.1.1 ipsec-attributes
pre-shared-key passw0rd
exit
route Colo 1.1.1.1 255.255.255.255 217.1.1.1 (Wan Default Gateway)
!
crypto map Colo_map interface Colo
crypto isakmp enable Colo
!
Configure isakmp Policy :
crypto isakmp policy 10
authentication pre-share
encryption des
hash md5
group 2
lifetime 86400
!
crypto isakmp policy 20
authentication pre-share
encryption aes
hash sha
group 2
lifetime 86400
!
crypto isakmp policy 30
authentication pre-share
encryption 3des
hash md5
group 2
lifetime 86400
2 types of encryptions :
transform-set ESP-DES-MD5
transform-set ESP-AES-128-SHA
Must be using same type of encryption on both ends of the vpn tunnel