Networking-Blog

My WordPress Blog

CISCO IOS SPOKE – IPSEC ISAKMP vs IPSEC ISAKMP PROFILE

IPSEC ISAKMP : CISCO REMOTE SITE :


crypto isakmp policy 1

encr aes
hash md5
authentication pre-share
group 2
lifetime 3600
!
crypto isakmp key t35t1n5!!! address 85.234.92.94
crypto isakmp keepalive 10
crypto isakmp nat keepalive 10
!
!
crypto ipsec transform-set 3G_IPSEC esp-3des esp-sha-hmac
!
!
!
!
crypto map mapping 1 ipsec-isakmp
set peer 85.234.92.94
set security-association lifetime seconds 86400
set security-association idle-time 86400
set transform-set 3G_IPSEC
set pfs group2
match address VPN
!
interface Dialer0
crypto map mapping
!
!
ip access-list extended VPN
permit ip 192.168.0.0 0.0.0.255 any
!
!

IPSEC ISAKMP PROFILE :

crypto isakmp policy 10
encr aes
hash md5
authentication pre-share
group 2
lifetime 3600
!
crypto keyring TEST_VPN
local-address dialer0
pre-shared-key address 85.234.92.94 key t35t1n5!!!
!
crypto isakmp profile TEST_VPN
keyring TEST_VPN
match identity address 85.234.92.94
local-address dialer0
!
crypto ipsec transform-set 3G_IPSEC esp-3des esp-sha-hmac
mode tunnel
!
crypto map 3G-1 10 ipsec-isakmp
set security-association lifetime seconds 900
set peer 85.234.92.94
set pfs group2
set transform-set 3G_IPSEC
set isakmp-profile TEST_VPN
match address TEST_VPN
!
!
ip access-list extended TEST_VPN
permit ip 192.168.0.0 0.0.0.255 any
!
interface Dialer0
crypto map 3G-1

Cisco Traversing a NAT device

 

Using NAT Traversal

Network Address Translation (NAT) and Port Address Translation (PAT) are implemented in many networks where IPSec is also used, but the number of incompatibilities that prevent IPSec packets from successfully traversing a NAT device.

PIX Firewall Version 6.3 provides a feature called “Nat Traversal,” as described by Version 2 and Version 3 of the draft IETF standard, UDP Encapsulation of IPsec Packets,” which is available at the following URL:

http://www.ietf.org/html.charters/ipsec-charter.html

NAT Traversal allows ESP packets to pass through one or more NAT devices. This feature is disabled by default.

Note NAT Traversal is supported for both dynamic and static crypto maps.

To enable NAT traversal, enter the following command:

isakmp nat-traversal [natkeepalive]
isakmp nat-traversal 20

Valid values for natkeepalive are 10 to 3600 seconds; the default is 20 seconds.

 

Enabling IPsec over NAT-T

NAT-T lets IPsec peers establish a connection through a NAT device. It does this by encapsulating IPsec traffic in UDP datagrams, using port 4500, thereby providing NAT devices with port information. NAT-T auto-detects any NAT devices, and only encapsulates IPsec traffic when necessary. This feature is disabled by default.

• The security appliance can simultaneously support standard IPsec, IPsec over TCP, NAT-T, and IPsec over UDP, depending on the client with which it is exchanging data.

• When both NAT-T and IPsec over UDP are enabled, NAT-T takes precedence.
• When enabled, IPsec over TCP takes precedence over all other connection methods.
• When you enable NAT-T, the security appliance automatically opens port 4500 on all IPsec enabled interfaces.

The security appliance supports multiple IPsec peers behind a single NAT/PAT device operating in one of the following networks, but not both:

• LAN-to-LAN
• Remote access

In a mixed environment, the remote access tunnels fail the negotiation because all peers appear to be coming from the same public IP address, that of the NAT device. Also, remote access tunnels fail in a mixed environment because they often use the same name as the LAN-to-LAN tunnel group (that is, the IP address of the NAT device).
This match can cause negotiation failures among multiple peers in a mixed LAN-to-LAN and remote access network of peers behind the NAT device.

Cisco/PIX/ASA ISAKMP States

Details on the various connection states shown in the output from commands show isakmp sa or show crypto isakmp sa executed on a Cisco PIX or ASA firewall appliance.

MM_SA_SETUP

Policy parameters have been successfully negotiated

MM_NO_STATE

Phase 1 has failed, policy parameters have not been successfully negotiated.

  • Check there is a matching crypto policy configured on both peers
  • Check you have applied and activated the relevant crypto map/policy on both peers, on the correct interface

AG_NO_STATE

As above but displayed for agressive mode connections

MM_KEY_EXCH

Peers are authenticating. If phase 1 fails here, authentication of a peer device has failed

  • Check the pre-shared key matches at both ends
  • Check the time on each peer is reasonably close to the others
  • If using certificates, confirm they are valid and have not been revoked

AG_INIT_EXCH

As above but displayed for agressive mode connections

MM_KEY_AUTH

Authentication of the peer devices has been successful, expect the state to transition to QM_IDLE or MM_ACTIVE shortly

AG_AUTH

As above but displayed for agressive mode connections

QM_IDLE

Phase 1 completed successfully



Cisco sysopt

Allow packets from an IPsec tunnel and their payloads to bypass interface ACLs on the security appliance.
IPsec tunnels that are terminated on the security appliance are likely to fail if one of these commands is not enabled.

sysopt connection permit-ipsec
sysopt connection permit-vpn

Additional Commands :

show sysopt
show running-config sysopt