Configuring an IPSec Pass Through Inspection Policy Map for Additional Inspection Control

Inspect IPSec Pass Through is disabled by default. When enabled without using a parameter map, the inspection uses the default IPSec Pass Through parameter map, which allows only ESP traffic with unlimited connections and the default idle timeout of 10 minutes for the ESP connection.

To pass ESP or AH traffic, IPSec Pass Through parameter map is required.

To create an IPSec Pass Through map, perform the following steps:

IPSec Pass Through Inspection H

Step 1 To create an IPSec Pass Through inspection policy map, enter the following command:

hostname(config)# policy-map type inspect IPSec-pass-thru map_name hostname(config-pmap)#

Where the policy_map_name is the name of the policy map. The CLI enters policy-map configuration mode.

Step 2 (Optional) To add a description to the policy map, enter the following command:

hostname(config-pmap)# description string

Step 3 To configure parameters that affect the inspection engine, perform the following steps:

a. To enter parameters configuration mode, enter the following command:

hostname(config-pmap)# parameters hostname(config-pmap-p)#

b. To configure for ESP traffic, enter the following command:

hostname(config-pmap-p)# esp per-client-max value timeout timeout c. To configure for AH traffic, enter the following command:

hostname(config-pmap-p)# ah per-client-max value timeout timeout

The following example shows how to define an IPSec Pass Through map:

hostname(config)# access-list test-udp-acl extended permit udp any any eq 500

hostname(config)# class-map test-udp-class hostname(config-cmap)# match access-list test-udp-acl hostname(config)# policy-map type inspect IPSec-pass-thru IPsec-map hostname(config-pmap)# parameters hostname(config-pmap-p)# esp per-client-max 32 timeout 00:06:00 hostname(config-pmap-p)# ah per-client-max 16 timeout 00:05:00

hostname(config)# policy-map test-udp-policy hostname(config-pmap)# class test-udp-class hostname(config-pmap-c)# inspect IPSec-pass-thru IPSec-map

This policy is applied on the interface that has the policy to permit UDP 500 traffic through initially. In this example it is the outside interface.

To verify that the inspection engine opens the ESP or AH data flows for IPSec Pass Through based on the IKE control flow, use the show conn command:

hostname(config)# show conn

ESP out 192.168.51.25 in 192.168.52.49 idle 0:00:00 bytes 108

AH out 192.168.51.25 in 192.168.52.49 idle 0:00:01 bytes 0

ESP out 192.168.51.25 in 192.168.52.49 idle 0:00:01 bytes 0

UDP out 192.168.51.25:500 in 192.168.52.49:500 idle 0:00:00 flags -

AH out 192.168.51.25 in 192.168.52.50 idle 0:00:22 bytes 0

ESP out 192.168.51.25 in 192.168.52.50 idle 0:00:22 bytes 0

UDP out 192.168.51.25:500 in 192.168.52.50:500 idle 0:00:00 flags -

ESP out 192.168.51.25 in 192.168.52.49 idle 0:00:00 bytes 108

AH out 192.168.51.25 in 192.168.52.50 idle 0:00:00 bytes 2080

Continue reading here: RTSP Inspection Overview

Was this article helpful?

0 0

Readers' Questions

  • aziz
    What is ipsec passthrough?
    7 months ago
  • IPsec Passthrough is a function of a router or firewall designed to allow VPN (Virtual Private Network) traffic to pass through to the internal network. It helps to secure traffic that passes between two private networks over an untrusted network like the Internet.