Cisco ASA Ipsec Vpn Tweaks
!
!
disable :
Disables IKE keepalive processing, which is enabled by default.
retryseconds :
Specifies the interval in seconds between retries after a keepalive response has not been received.
The range is 2-10 seconds. The default is 2 seconds.
thresholdseconds :
Specifies the number of seconds the peer can idle before beginning keepalive monitoring.
The range is 10-3600 seconds. The default is 10 seconds for a LAN-to-LAN group, and 300 second for a
remote access group.
eg :
establishes a threshold of 15, and specifies a retry interval of 10 for the IPSec LAN-to-LAN tunnel group
with the IP address 209.165.200.225 :
!
hostname(config)# tunnel-group 209.165.200.225 type IPSec_L2L
hostname(config)# tunnel-group 209.165.200.225 ipsec-attributes
hostname(config-tunnel-ipsec)# isakmp keepalive threshold 15 retry 10
!
NAT traversal enables ESP packets to pass through one or more NAT devices.
To disable in a crypto-map entry, use the crypto map set nat-t-disable
crypto map VPN_MAP 10 set nat-t-disable
To enable inbound aggressive mode connections :
no isakmp am-disable
To disable inbound aggressive mode connections :
isakmp am-disable
To enable in a crypto-map entry,
enable PFS – Without PFS, the Cisco ASA uses Phase 1 keys during the Phase 2 negotiations
crypto map VPN_MAP 10 set pfs group1
To enable disconnect notification to peers, use the :
crypto isakmp disconnect-notify
!
!
show crypto isakmp sa
show crypto isakmp sa nat
show crypto IPsec sa
show crypto engine connections active
show crypto engine connections dropped-packet
show crypto engine connections flow
show crypto engine qos
show crypto isakmp policy
show running-config isakmp – Displays all the active configuration.
clear-configure tunnel-group – Clears all configured tunnel groups.
show running-config tunnel-group – Shows the tunnel group configuration for all tunnel groups
or for a particular tunnel group.
ISAKMP Negotiations States
These are the possible ISAKMP negotiation states on an ASA firewall. ISAKMP stands for:
The Internet Security Association and Key Management Protocol
ASA ISAKMP STATES
- MM_WAIT_MSG2
Initial DH public key sent to responder. Awaiting initial contact reply from other side.
If stuck here it usually means the other end is not responding. This could be due to
no route to the far end or the far end does not have ISAKMP enabled on the outside
or the far end is down.
- MM_WAIT_MSG3
Both peers have agreed on the ISAKMP policies. Awaiting exchange of keyring
information. Hang up’s here may be due to mismatch device vendors, a router
with a firewall in the way, or even ASA version mismatches.
- MM_WAIT_MSG4
In this step the pre-share key hashes are exchanged. They are not compared or
checked, only sent. If one side sends a key and does not receive a key back,
this is where the tunnel will fail.
I have seen the tunnel fail at this step due to the remote side having the wrong
Peer IP address. Hang up’s here may also be due to mismatch device vendors, a
router with a firewall in the way, or even ASA version mismatches.
- MM_WAIT_MSG5
This step is where the devices exchange pre-shared keys.
If the pre-shared keys do not match it will stay at this MSG. I have also seen the
tunnel stop here when NAT Traversal was on when it needed to be turned off.
- MM_WAIT_MSG6
This step is where the devices exchange pre-shared keys.
If the pre-shared keys do not match it will stay at this MSG. I have also seen the
tunnel stop here when NAT Traversal was on when it needed to be turned off. However,
if the state goes to MSG6 then the ISAKMP gets reset that means phase 1 finished but
phase 2 failed. Check that IPSEC settings match in phase 2 to get the tunnel to MM_ACTIVE.
- AM_ACTIVE / MM_ACTIVE
The ISAKMP negotiations are complete. Phase 1 has successfully completed.
Link to Configuring a FireBox X Edge WatchGuard to ASA :