Networking-Blog

My WordPress Blog

CISCO ASA DYNAMIC IPSEC VPN

Dynamic IPSEC :

object-group network Eyre_Remote_Private_nonat
network-object 192.168.3.0 255.255.255.0
!
object-group network Eyre_HQ_Private_nonat
network-object 172.16.0.0 255.255.0.0
!
!
nat (DC_LAN,PUBLIC) source static Eyre_HQ_Private_nonat Eyre_HQ_Private_nonat destination static Eyre_Remote_Private_nonat Eyre_Remote_Private_nonat
!
!
crypto ipsec security-association lifetime seconds 86400
crypto ipsec security-association lifetime kilobytes 9908000
!
crypto dynamic-map draytech_map 5 set ikev1 transform-set ESP-3DES-MD5
crypto dynamic-map draytech_map 5 set reverse-route
!
crypto map Public_map 10 ipsec-isakmp dynamic draytech_map
!
crypto map Public_map interface outside
!
crypto isakmp identity address
crypto isakmp nat-traversal 10
crypto ikev1 enable outside
sysopt connection permit-ipsec
!
crypto ikev1 policy 1
authentication pre-share
encryption 3des
hash md5
group 2
lifetime 86400
!
tunnel-group DefaultL2LGroup type ipsec-l2l
tunnel-group DefaultL2LGroup ipsec-attributes
ikev1 pre-shared-key PASSWORD
isakmp keepalive threshold 20 retry 5

 

If all traffic is to be pushed down the tunnel from remote site, we need to make sure both ends
Access-list policies match :

eg :

ASA 5520 V8.3 :

name 10.171.53.0 ee053
! 
object-group network Remote_Private_Range
description Remote Summarisation of Private IP Address
network-object ee053 255.255.255.0
!
object network Eyre_HQ_Private_nonat
description HQ site private range
subnet 0.0.0.0 0.0.0.0
!
access-list Colo_cryptomap_5 extended permit ip any object-group Remote_Private_Range
!
!
nat (DC_LAN,PUBLIC) source static Eyre_HQ_Private_nonat Eyre_HQ_Private_nonat destination static Eyre_Remote_Private_nonat Eyre_Remote_Private_nonat
!
nat (PUBLIC,DC_LAN) source static Eyre_Remote_Private_nonat Eyre_Remote_Private_nonat destination static Eyre_HQ_Private_nonat Eyre_HQ_Private_nonat
!
crypto dynamic-map draytech_map 5 match address Colo_cryptomap_5


Remote Site Cisco :

ip access-list extended VPN
permit ip 10.171.53.0 0.0.0.255 any

 

 

 

Cisco Linux ipsec VPN Hostname Identity Configuration

Defines the identity the router uses when participating in the IKE protocol.

hostname comms30
!

ip domain name commsgroup.ww
!

crypto isakmp policy 1
encr 3des
hash md5
authentication pre-share
group 2
crypto isakmp key commsr3m0t3 address 2.2.2.2

crypto isakmp identity hostname
crypto isakmp keepalive 15 10
!
crypto ipsec transform-set secure esp-3des esp-md5-hmac
!

crypto map mapping 1 ipsec-isakmp
set peer 2.2.2.2
set transform-set secure
match address VPN
!
ip nat inside source route-map NAT interface dialer0 overload
!
ip access-list extended NAT_ACL
deny ip 10.10.38.0 0.0.0.255 10.10.0.0 0.0.255.255
permit ip 10.10.38.0 0.0.0.255 any
!
ip access-list extended VPN
permit ip 10.10.38.0 0.0.0.255 10.10.0.0 0.0.255.255
!
route-map NAT permit 10
match ip address name NAT_ACL

Defines the identity the router uses when participating in the IKE protocol.
In order to use crypto isakmp identity hostname command : Configure the following :

hostname comms30
ip domain name commsgroup.ww
crypto isakmp identity hostname

On Linux peer address vpn config:

conn comms30
left=2.2.2.2
leftsubnet=10.10.0.0/16
right=0.0.0.0
rightid=@comms30.commsgroup.ww
rightsubnet=10.10.38.0/24
authby=secret
keyexchange=ike
aggrmode=no
ikelifetime=24h
keylife=8h
keyingtries=3
rekey=no
auto=start
esp=3des-md5-96
pfs=no

Linux Shared Key config:

ipsec.secrets config :

%any 2.2.2.2 : PSK “commsr3m0t3″
or
2.2.2.2 %any : PSK “commsr3m0t3″

If the remote user is behind a NAT-T Router / Firewall  and further connected
via a point-to-point link and remote user has a default-gateway of a private
LAN address
:

Scenerio :

So you have an internet facing Layer3 Router connected to another Layer3 Router,
behind this we have our remote user vpn router “cisco 857“.

NAT Traversal performs two tasks: it detects if both ends support NAT-T and
NAT-Discovery that detects NAT devices along the transmission path.
NAT-T encapsulate IPSec packets in UDP packets with port 4500
NAT-traversal encapsulates the ESP packets in UDP packets.

Internet Key Exchange (IKE) – User Datagram Protocol (UDP) port 500
Encapsulating Security Payload (ESP) – IP protocol number 50
IPsec NAT-T – UDP port 4500

eg :

Host Lan :
192.168.4.0/24

Default-Gateway :
192.168.2.127/30

Router/Firewall :
81.174.141.198

Remote Host Router is configured with :

Hostname
Domain-Name
Crypto Isakmp Hostname Identity

We know the remote NAT-T Firewall Router also there private lan default-gateway.
Here is the Linux ipsec configuration :

conn comms30
left=2.2.2.2
leftsubnet=10.10.0.0/16
right=0.0.0.0
rightid=@comms30.commsgroup.ww
rightnexthop=192.168.2.127
rightsubnet=192.168.4.0/24
rightsourceip=81.174.141.198
authby=secret
keyexchange=ike
aggrmode=no
ikelifetime=24h
keylife=8h
keyingtries=3
rekey=no
auto=start
esp=3des-md5-96
pfs=no
dpddelay=30
dpdtimeout=120
dpdaction=clear