Cisco ASA Ipsec Vpn Tweaks

isakmp keepalive
!
To configure IKE DPD, use the isakmp keepalive command in tunnel-group ipsec-attributes
configuration mode. In every tunnel group, IKE keepalives are enabled by default with default
threshold and retry values.
!
Disable DPD keep-alives on ASA
“isakmp keepalive disable” under the Tunnel Group Configuration.

disable :
Disables IKE keepalive processing, which is enabled by default.
retryseconds :
Specifies the interval in seconds between retries after a keepalive response has not been received.
The range is 2-10 seconds. The default is 2 seconds.
thresholdseconds :
Specifies the number of seconds the peer can idle before beginning keepalive monitoring.
The range is 10-3600 seconds. The default is 10 seconds for a LAN-to-LAN group, and 300 second for a
remote access group.

eg :

The following example entered in config-ipsec configuration mode, configures IKE DPD,
establishes a threshold of 15, and specifies a retry interval of 10 for the IPSec LAN-to-LAN tunnel group
with the IP address 209.165.200.225 :

!
hostname(config)# tunnel-group 209.165.200.225 type IPSec_L2L
hostname(config)# tunnel-group 209.165.200.225 ipsec-attributes
hostname(config-tunnel-ipsec)# isakmp keepalive threshold 15 retry 10
!
NAT traversal enables ESP packets to pass through one or more NAT devices.

To disable in a crypto-map entry, use the crypto map set nat-t-disable
crypto map VPN_MAP 10 set nat-t-disable

To enable inbound aggressive mode connections :
no isakmp am-disable

To disable inbound aggressive mode connections :
isakmp am-disable


To enable in a crypto-map entry,
e
nable PFS
– Without PFS, the Cisco ASA uses Phase 1 keys during the Phase 2 negotiations
crypto map VPN_MAP 10 set pfs group1

To enable disconnect notification to peers, use the :
crypto isakmp disconnect-notify

!

Troubleshooting Command’s :
!
show crypto isakmp sa
show crypto isakmp sa nat
show crypto IPsec sa
show crypto engine connections active
show crypto engine connections dropped-packet
show crypto engine connections flow
show crypto engine qos
show crypto isakmp policy

!
show running-config isakmp                  – Displays all the active configuration.
clear-configure tunnel-group                 – Clears all configured tunnel groups.
show running-config tunnel-group      –
Shows the tunnel group configuration for all tunnel groups
or for a particular tunnel group
.

ISAKMP Negotiations States

These are the possible ISAKMP negotiation states on an ASA firewall. ISAKMP stands for:
The Internet Security Association and Key Management Protocol

ASA ISAKMP STATES

  • MM_WAIT_MSG2
    Initial DH public key sent to responder. Awaiting initial contact reply from other side.

    If stuck here it usually means the other end is not responding. This could be due to
    no route to the far end or the far end does not have ISAKMP enabled on the outside
    or the far end is down.
  • MM_WAIT_MSG3
    Both peers have agreed on the ISAKMP policies. Awaiting exchange of keyring
    information.
    Hang up’s here may be due to mismatch device vendors, a router
    with a firewall in the way, or even ASA version mismatches.
  • MM_WAIT_MSG4
    In this step the pre-share key hashes are exchanged. They are not compared or
    checked, only sent. If one side sends a key and does not receive a key back,
    this is where the tunnel will fail.

    I have seen the tunnel fail at this step due to the remote side having the wrong
    Peer IP address. Hang up’s here may also be due to mismatch device vendors, a
    router with a firewall in the way, or even ASA version mismatches.
  • MM_WAIT_MSG5
    This step is where the devices exchange pre-shared keys.
    If the pre-shared keys do not match it will stay at this MSG. I have also seen the
    tunnel stop here when NAT Traversal was on when it needed to be turned off.
  • MM_WAIT_MSG6
    This step is where the devices exchange pre-shared keys.
    If the pre-shared keys do not match it will stay at this MSG. I have also seen the
    tunnel stop here when NAT Traversal was on when it needed to be turned off. However,
    if the state goes to MSG6 then the ISAKMP gets reset that means phase 1 finished but
    phase 2 failed. Check that IPSEC settings match in phase 2 to get the tunnel to MM_ACTIVE.
  • AM_ACTIVE / MM_ACTIVE
    The ISAKMP negotiations are complete. Phase 1 has successfully completed.

Link to Configuring a FireBox X Edge WatchGuard to ASA :

http://www.watchguard.com/help/docs/edge/10/en-US/index_Left.html#CSHID=en-US%2Fbovpn%2Fmanual%2Fmanual_bovpn_edge_cisco.html|StartTopic=Content%2Fen-US%2Fbovpn%2Fmanual%2Fmanual_bovpn_edge_cisco.html|SkinName=Edge (en-US)