Configuring the Cisco Router for IPSec VPNs Using CA Support

To configure the router for IPSec VPNs using CA support, you must complete five tasks. Each task contains several subtasks. As always, the most important component is thorough planning and meticulous implementation. Because of the complexity of this process, any error can prevent the VPN from functioning properly. The five tasks are as follows:

1. Select the IKE and IPSec parameters.

2. Configure the router CA support.

3. Configure IKE using RSA signatures.

4. Configure IPSec using RSA signatures.

5. Test and verify the configuration.

Step 1: Select the IKE and IPSec Parameters

Selecting the IKE and IPSec parameters is just the process of predetermining which settings will be used on both peers to ensure successful negotiation of the connection. Many of these items were covered in Chapter 17. This task is divided into six subtasks, as follows:

1. Plan for CA support.

Get the details of the CA server to include the server type, IP address, host name, URL, and server administrator contact information. Coordinate with the CA server administrator to ensure that your certificates are properly validated.

2. Define the IKE (phase 1) policy. See Chapter 17.

3. Define the IPSec policies. See Chapter 17.

4. Verify the current router configuration.

5. Verify connectivity. See Chapter 17.

6. Ensure compatible access lists. See Chapter 17.

Step 2: Configure the Router CA Support

To configure a router for CA support and verify that configuration, you must complete 11 different steps. These steps include configuring the router, generating keys, and communicating with the CA server.

Step 1 Configure the router host name and domain name. The host name and domain name are written to the key pairs. It is important that you have the correct identity information configured on the router before you generate the key pair. The syntax for these global configuration commands is as follows:

• hostname name sets the host name for the router.

• ip domain-name name sets the default domain name on the router, which is used to convert unqualified host names to fully qualified domain names (FQDN).

Example 18-1 shows the correct syntax for configuring the host name and domain name on the router in New York.

Example 18-1 Configuring the Host Name and Domain Name router#configure terminal router(config)#hostname NewYork router(config)#ip domain-name newyork.com

Step 2 Set the router date, time, and time zone. The time on the router must be accurate to enroll with the CA server. The clock set command is entered with the router in privileged EXEC mode, and the clock timezone command is entered in global configuration mode. The syntax for these commands is as follows:

• clock timezone sets the correct time zone on the router.

• clock set configures the date and time on the router.

Example 18-2 shows the correct syntax for entering the date, time, and time zone on the router in New York.

Example 18-2 Configuring the Date, Time, and Time Zone

NewYork#configure terminal NewYork(config)#clock timezone est -5 NewYork(config)#exit

NewYork#clock set 19:00:00 30 march 2003

The most accurate way to ensure the correct time on the router is to configure it to synchronize time with a network time server using the Network Time Protocol (NTP). Cisco products support both NTP and the Simple Network Time Protocol (SNTP). NTP maintains communication between the router and the NTP server via UDP port 123, and the router can then relay time to other systems on the network. SNTP is a protocol used mainly by low-end routers and acts as a client-only mode. SNTP maintains communication between the client and server using UDP port 580. To activate NTP, you must enable NTP while in the interface configuration mode. You should limit NTP to a specific interface and only allow the router to access time updates from specific NTP peers. The command for configuring NTP on the Cisco router is ntp access-group [query-only | serve-only | server | peer] access-list number. Table 18-2 lists the configuration options for the ntp access-group command.

Table 18-2 ntp access-group Command Options

Term

Definition

query-only

Allows NTP control queries only.

serve-only

Allows and serves NTP time requests only.

serve

Allows NTP time requests, but does not synchronize with the remote system.

peer

Allows NTP control queries and time requests. Also allows the router to synchronize time with the remote system.

Step 3 Add the CA server to the router host table. By adding the CA server IP address to the router host table, you define a static host name-to-IP address mapping and remove the requirement for using DNS. Removing the requirement for DNS increases the performance of the router because it is no longer affected by any delay of the DNS server.

• ip host name address1 [address2]

Example 18-3 shows the correct syntax for adding the CA server to the host table on the router in New York.

Example 18-3 Adding the CA Server to the Host Table NewYork#configure terminal

NewYork(config)#ip host CA-Server 192.168.242.42

Step 4 Generate the RSA key pair. The RSA keys are used to authenticate the router to its SA peer. The command syntax for key generation is crypto key generate rsa usage keys. The option usage keys enables you to generate two special-purpose key pairs (authentication pair and encryption pair for RSA-encrypted nonces). If you do not use the optional command, you will generate a single "general-purpose" public/private key pair. It is also possible to select the modulus length when generating keys. General-purpose keys are sufficient for standard authentication using RSA signatures. The available modulus lengths are 360, 512, 1024, and 2048 bits. The longer the modulus length, the longer it will take the router to generate the keys.

Step 5 Declare the CA. Configure the trusted CA on the router in the global configuration mode with the crypto ca identity name command. This identifies the trusted CA for the router and puts you in the ca-identity configuration mode.

A variety of commands are available in the ca-identity configuration mode:

• enrollment url—Specifies the URL for the CA.

• enrollment mode ra—Specifies the URL of your CA server that provides registration authority (RA). This command is only necessary if your CA also provides an RA.

• query url—If your CA server supports RA with LDAP, this command specifies the URL of the LDAP server. This command is only used if your CA provides RA and supports LDAP.

• enrollment retry period minutes—This optional command specifies the wait period between enrollment retries. The default retry period is 1 minute and the available range is from 1 to 60 minutes.

• enrollment retry count—This optional command specifies the number of enrollment attempts the router should make. The default setting is 0, which allows the router an unlimited number of retries. The available range is 1 to 100 retry attempts.

• crl optional—The CRL is a list of certificates that are no longer valid and have been revoked by the CA. If the peer certificate is found on the CRL, the router will not accept that certificate and cannot authenticate the router. The crl optional command is optional and allows the routers to accept peers' certificates if the CRL is not accessible.

Example 18-4 shows the correct syntax declaring the CA server as the CA on the router in New York.

Example 18-4 Declaring the CA

NewYork#configure terminal

NewYork(config)#crypto ca identity CA-Server

NewYork(cfg-ca-id)#enrollment url http://CS-Server/certserv/mscep/mscep.dll

NewYork(cfg-ca-id)#enrollment mode ra

Cisco IOS Software version 12.3 introduces a new command that replaced crypto ca identity. This command is crypto ca trustpoint. Using this command places you into the ca-trustpoint configuration mode. Example 18-5 shows the syntax for declaring a CA using Cisco IOS Software version 12.3

Example 18-5 Declaring the CA with Cisco IOS Software Version 12.3

NewYork(config)#crypto ca trustpoint CA_Server

NewYork(ca-trustpoint)#enrollment url http:// CS-Server/certserv/mscep/mscep.dll

NewYork(ca-trustpoint)#enrollment mode ra

Step 6 Authenticate the CA. The router authenticates the CA by retrieving the CA self-signed certificate and the CA's public key. The command for this action is crypto ca authenticate. This command initiates the authentication process with the CA by sending the CA/RA request to the CA. The CA generates the CA/RA certificate and returns it to the router. The router authenticates the CA/RA certificate using the CA/RA fingerprint. Example 18-6 shows the correct syntax for authenticating the CA on the router in New York.

Example 18-6 Authenticating the CA NewYork#configure terminal

NewYork(config)#crypto ca authenticate CA-Server

Step 7 Request your certificate. The router must request a certificate from the CA server with the crypto ca enroll command. This command requests certificates from the CA for all the router RSA key pairs. The router sends the key pairs to the CA server, which generates and signs the identity certificates.

Finally, the CA server sends the identity certificates back to the router and posts a copy in its public repository. Example 18-7 shows the correct syntax for requesting a certificate from the CA.

Example 18-7 Requesting a Certificate from the CA

NewYork#configure terminal NewYork(config)#crypto ca enroll CA-Server

% Start certificate enrollment...

% Create a challenge password. You need to verbally provide this password to the CA administrator to revoke your certificate. For security reasons, your password will not be saved in the configuration. Please make a note of it.

Password: <password> Re-enter password: <password>

% The subject name in the certificate will be: NewYork.newyork.com % Include the router serial number in the subject name? (yes/no): no % Include the IP address in the subject name? (yes/no): no Request certificate from CA? (yes/no) yes % Certificate request sent to certificate authority % The certificate request fingerprint will be displayed. % The show crypto ca certificate command will also show the fingerprint.

NewYork(config)#

Signing Certificate Request Fingerprint: 1D017C1F 9AE457BD 501BA5DF CF472D21

Encryption Certificate Request Fingerprint: 2FF054AB 01DC2A22 AB147620 05C5AB5F

Step 8 Save the configuration to the router. Ensure that the current configuration is saved. Write the configuration to memory using the COPY running-config startup-config command.

NOTE It is also a good idea to save the configuration to prevent certificate loss in the event of a system reboot and to back up the configuration in case of hardware failure.

Figure 18-2 depicts the communications between the router and the CA server that are required to complete the authentication, enrollment, and certificate-generation process.

Figure 18-2 Communication Between the Router and CA

New York

Figure 18-2 Communication Between the Router and CA

New York

Many of the steps shown in Figure 18-2 are completed automatically by SCEP.

Step 9 Manage key storage in NVRAM. Memory management is an option available to prevent the number of stored certificates and CRLs from occupying memory space.

Step 10 Manage the keys on the router. Key management is an option that enables you to delete keys and certificates from the router and to request a CRL from the CA.

Step 11 Verify the CA configuration. Three commands enable you to view the status of certificates and keys on the router, as follows:

• show crypto ca certificates displays certificates currently on the router. Example 18-8 shows the output from the show crypto ca certificates command.

Example 18-8 show crypto ca certificates Output

NewYork# show crypto ca certificates

Certificate Subject Name

Name: NewYork.newyork.com IP Address: 192.168.0.1 Status: Available

Certificate Serial Number: 428125BDA34196003F6C78316CD8FA95 Key Usage: Signature Certificate Subject Name

Name: NewYork.newyork.com IP Address: 192.168.0.1 Status: Available

Certificate Serial Number: AB352356AFCD0395E333CCFD7CD33897 Key Usage: Encryption CA Certificate Status: Available

Certificate Serial Number: 3051DF7123BEE31B8341DFE4B3A338E5F Key Usage: Not Set

• show crypto key mypubkey rsa displays public keys for the router. Example 18-9 shows the output from the show crypto key mypubkey rsa command.

Example 18-9 show crypto key mypubkey rsa Output

NewYork# show crypto key mypubkey rsa

% Key pair was generated at: 19:07:49 UTC Mar 30 2003

Key name: NewYork.newyork.com

Usage: Signature Key

Key Data:

005C300D 06092A86 4886F70D 01010105 00034B00

30480241

00C5E23B

55D6AB22

04AEF1BA A54028A6 9ACC01C5 129D99E4 64CAB820

847EDAD9

DF0B4E4C

73A05DD2

BD62A8A9 FA603DD2 E2A8A6F8 98F76E28 D58AD221

B583D7A4

71020301

0001

% Key pair was generated at: 19:07:50 UTC Mar 30 2003

Key name: NewYork.newyork.com

Usage: Encryption Key

Key Data:

00302017 4A7D385B 1234EF29 335FC973 2DD50A37

C4F4B0FD

9DADE748

429618D5

18242BA3 2EDFBDD3 4296142A DDF7D3D8 08407685

2F2190A0

0B43F1BD

9A8A26DB

07953829 791FCDE9 A98420F0 6A82045B 90288A26

DBC64468

7789F76E

EE21

• show crypto key pubkey-chain rsa displays the peer public keys on the router. Example 18-10 shows the output from the show crypto key pubkey-chain rsa command.

Example 18-10 show crypto key pubkey-chain rsa Output

NewYork# show crypto

key pubkey

chain rsa

Codes:

M - Manually

Configured,

C

Extracted from certificate

Code

Usage

IP-address

Name

C

Signature

192.168.20

l

Boston.boston.com

C

Encryption

192.168.20

1

Boston.boston.com

M

Signature

172.16.0.1

LA.losangeles.com

M

Encryption

172.16.0.1

LA.losangeles.com

C

General

192.168.10

3

atlanta.georgia.com

Step 3: Configure IKE Using RSA Signatures

Chapter 17 covered these configuration steps in great detail. For the purpose of this exercise, Figure 18-3 provides the configuration parameters for the VPN connection between New York and Boston.

Figure 18-3 IKE Configuration Parameters

Figure 18-3 IKE Configuration Parameters

Example 18-11 shows the commands used to configure IKE using RSA signatures on the router in New York.

Example 18-11 Configuring IKE Using RSA Signatures

NewYork# configure terminal

NewYork (config)# crypto isakmp policy 120

NewYork (config-isakmp)# authentication rsa-sig

NewYork (config-isakmp)# encryption 3des

NewYork (config-isakmp)# hash md5

NewYork (config-isakmp)# group 2

NewYork (config-isakmp)# lifetime 86400

Step 4: Configure IPSec

Chapter 17 also covered these configuration steps in great detail. For the purpose of this exercise, Figure 18-4 provides the configuration parameters for the VPN connection between New York and Boston.

Figure 18-4 IPSec Configuration Parameters

Figure 18-4 IPSec Configuration Parameters

Example 18-12 shows the commands used to configure the following IPSec parameters on the New York router:

1. Create the IPSec transform set.

2. Configure IPSec SA lifetimes.

3. Create the crypto access lists (ACLs).

4. Create the crypto map.

5. Apply the crypto maps.

Example 18-12 Configuring IPSec Parameters NewYork# configure terminal

NewYork (config)#crypto ipsec transform-set 20 esp-3des esp-md5-hmac

NewYork (cfg-crypto-trans)#exit

NewYork (config)#crypto ipsec security-association lifetime seconds 3600

NewYork (config)#access-list 105 permit ip 10.10.10.0 0.0.0.255 10.10.20.0 0.0.0.255

NewYork(config)#crypto map boston 120 ipsec-isakmp

NewYork(config-crypto-map)#match address 105 NewYork(config-crypto-map)#set peer 192.168.20.1 NewYork(config-crypto-map)#set pfs group2 NewYork(config-crypto-map)#set transform-set 20

NewYork(config-crypto-map)# set security-association lifetime seconds 86400

NewYork(config-crypto-map)#interface S0

NewYork(config-if)#crypto map boston

Step 5: Test and Verify the Configuration

The following three commands enable you to verify your configuration when working with CAs:

■ crypto ca identity—This command displays the CA that your router is configured to use.

■ debug crypto pki {callbacks, messages, transactions}—This command enables you to display the callbacks, transactions, or messages that occur between the router and the CA.

■ show crypto ca certificates—This command displays information about the certificate of your CA and any RAs.

Continue reading here: Describe the Easy VPN Server

Was this article helpful?

0 0