Validating IPsec Configuration

The following enable mode commands are useful for validating the IPsec configuration show crypto isakmp policy returns the router's active IKE transform sets (policies) in order of priority. show crypto isakmp sa displays the status of the router's IKE SAs. A state of QM_IDLE means the IKE SA is up and functioning properly. Recall that both IKE and IPsec SAs are built only when they are needed and are triggered by traffic that matches a crypto map. show crypto map displays the crypto maps...

Enable Debugging and Clearing Existing SAs

To get more detailed information and observe IKE and IPsec negotiations, enable debugging with these commands RTA debug crypto isakmp RTAtfdebug crypto ipsec With debugging enabled, the router displays the status of IKE and IPsec events in detail. See the following section Messages for IKE Negotiation and CA Servers. To debug CA events, issue these additional commands RTA debug crypto pki messages RTAtfdebug crypto pki transactions To observe IKE negotiation, you might want to clear any...

Configuring IKE with RSA Encryption

A router using IKE with RSA encryption (RSA public key cryptography) is configured with the non-secret, public keys of its peers. This makes the exchanging of keys less problematic than authentication with secret, pre-shared keys. However, a device must be manually configured with the public key of every peer with which it builds an IKE SA. This means RSA encryption does not scale well in large networks. Also, RSA encryption lacks the nonrcpudiation that is available when using digital...

Configuring IPsec SA Lifetimes

The following commands modify the lifetimes associated with IPsec SAs RTA(config) crypto map MAP-TO NY 20 ipsec-isakmp RTA(config crypto-map) set security-association lifetime seconds 2700 RTA(config-crypto-map) set security association lifetime kilobytes 2000000 The command set security-association lifetime seconds 2700 sets the lifetime of IPsec SAs created by this crypto map entry to 2700 seconds (45 minutes). The default is 3600 seconds (60 minutes). The command set security-association...

Configuring Dynamic Crypto Maps

When a router has numerous remote peers, configuring a crypto map entry for every peer can be laborious. This is especially true when remote access users dial into a central router Manually configuring each user as a peer in the router's crypto map is impractical. Remote users typically have dynamically assigned IP addresses, so there's no way to predict a remote peer's address and program that into a crypto map. Dynamic crypto maps simplify large peering configurations by providing templates...

Tunnel Endpoint Discovery

Tunnel Endpoint Discovery (TED) is a Cisco feature that improves the scalability and availability of IPsec VPNs by extending the capabilities of dynamic crypto maps. As mentioned in the preceding section, Configuring Dynamic Crypto Maps, dynamic crypto maps greatly reduce your work by eliminating the configuration of specific IPsec peers. However, dynamic crypto maps (by default) are only receivers of IKE negotiation requests. That is, unlike regular crypto maps, they cannot initiate outbound...

Configuring IKE with RSA Signatures and Digital Certificates

IKE authentication with digital certificates uses RSA digital signatures and provides scalability for larger networks. As mentioned previously, digital certificates provide nonrepudiation through the service of a CA. Your organization might administer a CA server and act as the CA for all of the devices and people that belong to your organization. Also, you might be the CA for third parties (suppliers, partners, customers) that do business with your organization. With digital certificate...

Transform Sets

A transform set is a list of IPsec protocols and cryptographic algorithms that a peer can accept. Because IPsec allows for the use of different protocols and algorithms, a peer needs to declare and negotiate with other peers what it can support. Peers communicate the protocols and algorithms they support by exchanging transform sets. For two peers to communicate successfully, they must share a common transform set. If they do not, their attempt to establish a peering will fail and they will not...