Configuring Dynamic Crypto Maps

When a router has numerous remote peers, configuring a crypto map entry for every peer can be laborious. This is especially true when remote access users dial into a central router: Manually configuring each user as a peer in the router's crypto map is impractical. Remote users typically have dynamically assigned IP addresses, so there's no way to predict a remote peer's address and program that into a crypto map.

Dynamic crypto maps simplify large peering configurations by providing templates of basic IPsec requirements. The dynamic crypto map mandates a set of basic requirements and leaves other parameters, such as the peers' IP addresses, undefined. If a peer can authenticate and establish an IKE SA, and if the peer meets the basic requirements defined by the dynamic-cry pto map, the peer is allowed an IPsec SA with the router.

NOTE Dynamic crypto maps require IKE. IKE establishes dynamic IPsec SAs and authenticates the ! remote peer.

Dynamic crypto maps are nothing more than crypto maps that are missing some parameters. The missing parameters represent the information that the router does not know about the other peer and does not require from the peer to successfully establish an IPsec SA. Typically, the missing parameter is the peer's IP address (normally configured with the set peer command). This provides scalability when there are many peers because the router does not need to know and does not require the peers' IP addresses ahead of time.

The following is an example configuration of a dynamic crypto map:

crypto dynamic map DYN-MAP-DIALIN 20 match address 101

set transform-set TRANS - ESP TRANS-AH-ESP

crypto map MYMAP 500 ipsec-isakmp dynamic DYN-MAP-DIALIN

interface Seriall ip address 192.168.1.1 255.255.255.0 crypto map MYMAP

The command crypto dynamic-map DYN-M AP-DIALIN 20 creates an entry with a sequence of 20 for a dynamic crypto map called DYN-MAP-DIALIN. As with regular crypto maps, the sequence number prioritizes the map's entries.

The command match address 101 assigns crypto access list 101 to this entry. As with regular crypto maps, the list defines the traffic that requires IPsec protection and checks inbound packets to ensure consistent policy. Inbound packets that match the reverse logic of the list are expected to be protected—if they are not, the packets are dropped.

The command set transform-set TRANS-ESP TRANS-AH-ESP defines the transform sets accepted by this router. When a remote peer initiates an IPsec SA with this router, it must propose a matching transform set or the negotiation will fail.

Notice that the dynamic crypto map lacks the set peer command found in regular ciypto maps. This means the map accepts any peer that passes IKE negotiation (the authentication step) and proposes a matching transform set. This eliminates the task of having to configure each peer manually (the main benefit of dynamic crypto maps).

NOTE Recall that the choices for IKE authentication are pre-shared keys, RSA encryption, and RSA signatures with digital certificates.

The command crypto map MYMAP 500 ipsec-isakmp dynamic DYN-MAP-DIALIN binds the dynamic crypto map to an entry (sequence of 500) in a regular crypto map called MYMAP. This syntax allows you to configure multiple dynamic crypto maps in a single crypto map or to mix dynamic crypto maps with regular, static map entries.

NOTE When mixing dynamic crypto map entries with regular entries in a crypto map, set the dynamic crypto map entries to be the highest sequence numbers (lowest priority). This is why the example uses a sequence of 500 for the dynamic crypto map entry.

The command crypto map MYMAP applies MYMAP, which includes the dynamic crypto map, to interface Serial 1.

NOTE ^ By default, dynamic crypto maps can only answer incoming peer requests for IKE and IPsec SAs. They cannot initiate outbound SAs to remote peers. The exception to this is dynamic crypto maps with Cisco's Tunnel Endpoint Discovery service (covered in the following section).

Continue reading here: Enable Debugging and Clearing Existing SAs

Was this article helpful?

+1 -7