Configuring Siteto Site VPN

Users at the office in Atlanta need to securely access resources in the Raleigh office. The security administrator configures a site-to-site IPsec tunnel between the Cisco ASA in Raleigh and the Cisco IOS router in Atlanta.

The following are the steps that need to be completed to configure the Cisco IOS router in Atlanta to terminate a site-to-site IPsec tunnel with the Cisco ASA in Raleigh.

Step 1 Log in to the router using SDM.

Step 2 Navigate to Configure > VPN and choose Site-to-Site VPN, as illustrated in Figure 12-36.

Figure 12-36 Configuring a Site-to-Site VPN Using SDM

Figure 12-36 Configuring a Site-to-Site VPN Using SDM

Step 3 Click Create a Site to Site VPN and click the Launch the selected task button.

Step 4 The Site-to-Site VPN Wizard welcome screen is displayed, as illustrated in Figure 12-37. The Quick setup option allows you to easily configure a site-to-site VPN tunnel to another Cisco router with minimal interaction. In this case, the router will be creating a site-to-site VPN tunnel to a Cisco ASA, then the Step by step wizard is selected. This option lets you customize the configuration.

Step 5 Click Next.

Step 6 The screen shown in Figure 12-38 is displayed. Select the interface that will terminate the VPN tunnel. In this example, FastEthernet4 (the outside interface of the router) is selected.

Figure 12-37 SDMSite-to-Site VPN Wizard Welcome Screen

Figure 12-37 SDMSite-to-Site VPN Wizard Welcome Screen

Figure 12-38 Configuring the VPN Interface, Remote Peer, and Preshared Keys

Step 7 In this case, the VPN peer (Cisco ASA) is configured with a static IP

address. Choose Peer with static IP address from the drop-down menu and enter the IP address of the peer (209.165.200.225). Preshared keys are used in this example for tunnel authentication.

Step 8 Click Next.

Step 9 The next screen allows you to configure an Internet Key Exchange (IKE) (as illustrated in Figure 12-39). This policy must match the IKE policy on the Cisco ASA. Click Add to enter a new IKE policy.

Figure 12-39 Configuring the IKE Policy with SDM

Figure 12-39 Configuring the IKE Policy with SDM

Step 10 In this case, a new policy is configured to use preshared keys for authentication. The selected encryption protocol is Advanced Encryption Standard AES_256. Diffie-Hellman (DH) Group 2 is used. The IKE hashing algorithm is Secure Hash Algorithm SHA_1. The default 24-hour lifetime for IKE is selected.

Step 11 Click Next.

Step 12 The next screen enables you to configure the IPsec policies. Click Add to add a new transform-set (IPsec phase two policies).

Step 13 The dialog box illustrated in Figure 12-40 appears allowing you to configure the IPsec policies.

Figure 12-40 Configuring the IPsec Phase Two Policies with SDM

Add Transfo rm Set [ X |

Name: |tunnel-to-asa

17 Data integrity with encryption (ESP] Integrity Algarithm: |ESP_SHA_HMAC Encryption Algorithm: |ESP_AES_256 ^J

1

[ « Hide Advanced -r~ Data and address integrity with out encryption (AH)

Tunnel (Encrypt data and IP header) C Transport (Encrypt data only)

r IP Compression (COMP-LZS)

OK Cancel Help

Step 14 Enter a name for the new transform set. In this case, the name is tunnel-to-asa.

Step 15 The Encapsulation Security Payload (ESP) protocol is used in this example. The integrity algorithm used in this example is ESP_SHA_HMAC, and the encryption algorithm is ESP_AES_256. The Cisco ASA configuration must match these settings to establish the site-to-site IPsec VPN tunnel.

Step 16 Tunnel mode is used in this example to encrypt both the payload (data) and IP header.

Step 17 Click OK to add the new transform-set.

Step 18 Click Next.

Step 19 The screen shown in Figure 12-41 is displayed. It allows you to select the traffic you would like to protect.

Step 20 Click Protect all traffic between the following subnets.

Step 21 Configure the local and remote networks (the networks that will be able to communicate over the VPN tunnel). In this case, the local network is 10.100.10.0/24, and the remote network is 10.10.10.0/24.

Step 22 Click Next.

Figure 12-41 Traffic to Protect

Figure 12-41 Traffic to Protect

Step 23 A summary screen listing the configuration changes is displayed. Click Finish to apply the changes.

Step 24 Because NAT/PAT was configured on the router, SDM shows a warning message asking you if you would like to bypass NAT for the traffic over the VPN tunnel. The warning screen is shown in Figure 12-42.

Figure 12-42 SDM Warning Screen

Step 25 Click Yes to bypass NAT for the tunnel traffic.

Example 12-3 shows the CLI VPN configuration of the router.

Example 12-3 CLI VPN Configuration of the Router

!Phase 1 IKE policy crypto isakmp policy 2 encr aes 256

authentication pre-share group 2

crypto isakmp key cisco123 address 209.165.200.225 !

!Phase 2 policy crypto ipsec transform-set tunnel-to-asa esp-aes 256 esp-sha-hmac !

!crypto-map configuration for the Tunnel to the Cisco ASA crypto map SDM_CMAP_1 1 ipsec-isakmp description Tunnel to209.165.200.225 set peer 209.165.200.225 set transform-set tunnel-to-asa match address 102

!ACL defining tunnel traffic access-list 102 remark SDM_ACL Category=4 access-list 102 remark IPSec Rule access-list 102 permit ip 10.100.10.0 0.0.0.255 10.10.10.0 0.0.0.255 !

!Outside Interface Configuration interface FastEthernet4 description $FW_OUTSIDE$ ip address 209.165.200.231 255.255.255.0 ip nat outside crypto map SDM_CMAP_1 !

!NAT Configuration - bypassing NAT for tunnel traffic ip nat inside source route-map SDM_RMAP_1 interface FastEthernet4 overload !

route-map SDM_RMAP_1 permit 1 match ip address 105 access-list 105 remark SDM_ACL Category=2 access-list 105 remark IPSec Rule access-list 105 deny ip 10.100.10.0 0.0.0.255 10.10.10.0 0.0.0.255 access-list 105 permit ip 10.100.10.0 0.0.0.255 any

The next task is to configure the Cisco ASA in the Raleigh office to terminate the site-to-site VPN tunnel. Complete the following steps to complete this task.

Step 1 Log in to the Cisco ASA using ASDM.

Step 2 From the main ASDM menu, choose Wizards > IPsec VPN Wizard, as shown in Figure 12-43.

Step 3 The VPN Wizard starts by allowing you to select the tunnel type, as illustrated in Figure 12-44. Click Site-to-Site.

Step 4 Choose the outside interface as the VPN tunnel interface from the drop-down menu.

Figure 12-43 Launching the ASDMIPsec VPN Wizard

Figure 12-43 Launching the ASDMIPsec VPN Wizard

Figure 12-44 ASDM VPN Wizard—VPN Tunnel Type

Step 5 In this example, the Cisco ASA will be configured to allow inbound IPsec sessions to bypass all configured access control lists (ACL).

Step 6 Click Next.

Step 7 The screen shown in Figure 12-45 is displayed. Here you can enter the remote site peer information.

Figure 12-45 ASDM VPN Wizard—Remote Peer Information

Figure 12-45 ASDM VPN Wizard—Remote Peer Information

Step 8 Enter the peer IP address (209.165.200.231 in this example).

Step 9 Under Authentication Method, click Pre-shared key and enter the preshared key. In this example, the preshared key is 1qazXSW2.

Step 10 By default, the IP address of the remote peer is used as the tunnel group name. Leave the default configuration.

Step 11 Click Next.

Step 12 The screen shown in Figure 12-46 is displayed. Here you can enter the IKE policy information.

Step 13 The IKE policy parameters must match those configured in the router. In this case, the same encryption protocol, authentication hashing algorithm, and DH group are configured.

Step 14

Click Next.

Figure 12-46 ASDM VPN Wizard—IKE Policy

Figure 12-46 ASDM VPN Wizard—IKE Policy

Step 15 The screen shown in Figure 12-47 is displayed. Here you can enter the IPsec phase 2 information.

Figure 12-47 ASDM VPN Wizard—IPsec Encryption and Authentication

Figure 12-47 ASDM VPN Wizard—IPsec Encryption and Authentication

Step 16 The IPsec encryption and authentication protocol parameters must match those configured in the router, as shown in Figure 12-47.

Step 17 Click Next.

Step 18 The screen shown in Figure 12-48 is displayed. This screen allows you to enter the local and remote networks that will communicate over the IPsec site-to-site VPN tunnel.

Figure 12-48 ASDM VPN Wizard—Hosts and Networks

[t= VPN Wizard I X |

" VPN Wizard

Hosts and Networks (Step 5 oF 6)

S "**§

An IPsec tunnel protects data exchanged by selected hosts and networks at the local and remote sites. Please identify hosts and networks to be used in the IPsec tunnel.

Action: ® Protect Q Do noi Protect

Local Networks: |inside-network/24

Remote Networks: »3E5EB»AT-I [~|

sSfc

Z

V-;* 7

0 Exempt A5A side host/network From address translation? jinside v |

I

[ < Back ]| Next > ] Finish | Cancel ] [ Help ]

Step 19 Under Action, click Protect.

Step 20 Enter the local network information. In this case, the inside-network/24 is selected.

Step 21 Enter the remote network information. The 10.100.10.0/24, atlantaoffice remote network is selected in this example.

Step 22 Check the Exempt ASA side host/network from address translation option and choose the inside interface from the drop-down menu to bypass NAT for tunnel traffic.

Step 23 Click Next.

Step 24 The summary screen shown in Figure 12-49 is displayed. Step 25 Click Finish to apply the changes to the Cisco ASA.

Figure 12-49 ASDM VPN Wizard—Summary Screen

0* VPN Wizard I X |

r VPN Wiiard

Summary (Step 6 of 6)

Jk'f

You have created a 5ite-to-5ite VPN tunnel with the following attributes:

hfi f TrtT ' v*

VPN Tunnel Interface: outside Peer IP Address: 209.165.ZOQ.231 IP5sec authentication uses pre-shared key:dscolZ3 Tunnel Group Name: 209.165.200.231

IKE Policy Encryption / Authentication / DHGroup: AES-256 / SHA / Group 2 IPsec ESP Encryption / ESP Authentication: AES-256 / SHA Traffic Flow to be protected by this tunnel: (local) 10.10.10.0/24 (remote) DM_INLINE_NETWORK_l

*4

■

[ < Back j Next > [ Finish | [ Cancel | [ Help |

Example 12-4 shows the Cisco ASA CLI site-to-site VPN configuration.

Example 12-4 Cisco ASA CLI Site-to-Site VPN Configuration

!IKE Enabled on the outside interface crypto isakmp enable outside !

!IKE Policy (phase one policy) crypto isakmp policy 10 authentication pre-share encryption aes-256 hash sha group 2

lifetime 86400

!Phase 2 policy and crypto map configuration crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac crypto map outside_map 20 match address outside_20_cryptomap crypto map outside_map 20 set peer 209.165.200.231

crypto map outside_map 20 set transform-set ESP-AES-256-SHA !

!Crypto map is applied to the outside interface crypto map outside_map interface outside

Example 12-4 Cisco ASA CLI Site-to-Site VPN Configuration (Continued)

!ACL used by the crypto map to define the traffic that will be encrypted access-list outside_20_cryptomap extended permit ip 10.10.10.0 255.255.255. object-group atlanta-office

!Tunnel group configuration for the site-to-site tunnel tunnel-group 209.165.200.231 type ipsec-l2l tunnel-group 209.165.200.231 ipsec-attributes pre-shared-key *

!Bypassing NAT for the VPN tunnel traffic nat (inside) 0 access-list inside_nat0_outbound access-list inside_nat0_outbound extended permit ip 10.10.10.0 255.255.255. object-group atlanta-office

!Object Group defining the Atlanta office remote network object-group network atlanta-office network-object 10.100.10.0 255.255.255.0

Case Study of a Medium-Sized Enterprise

Company-B is a medium-sized software development company based in Chicago, Illinois. This organization has 1200 employees and 75 contractors at a call center in a partner office (Partner-A). Figure 12-50 illustrates a high-level overview of the Chicago office for Company-B.

Two routers (R1 and R2) reside at the Internet Edge followed by two Cisco ASAs with the Advanced Inspection and Prevention Security Services Module (AIP-SSM). The AIP-SSM provides intrusion prevention system (IPS) functionality. Web, e-mail, and DNS servers reside at a DMZ network. A Cisco Secure Monitoring, Analysis, and Response System (CS-MARS), a Cisco Secure Access Control Server (ACS), and a Simple Network Management Protocol (SNMP) server reside in the management network.

Company-B has three major user groups in the Chicago office:

• Engineering

Company-B's security manager has learned the techniques and methodologies discussed earlier on this book. The security manager develops a strategic plan to implement best practices to increase the security of their network infrastructure. The following sections include several tasks that the security manager of Company-B completes to increase the security of the network and its components.

Sales Engineering Finance

Continue reading here: Configuring the Aipssm on the Cisco ASA

Was this article helpful?

0 0