Configuring an IPSec Pass Through Inspection Policy Map for Additional Inspection Control
Inspect IPSec Pass Through is disabled by default. When enabled without using a parameter map, the inspection uses the default IPSec Pass Through parameter map, which allows only ESP traffic with unlimited connections and the default idle timeout of 10 minutes for the ESP connection.
To pass ESP or AH traffic, IPSec Pass Through parameter map is required.
To create an IPSec Pass Through map, perform the following steps:
IPSec Pass Through Inspection H
Step 1 To create an IPSec Pass Through inspection policy map, enter the following command:
hostname(config)# policy-map type inspect IPSec-pass-thru map_name hostname(config-pmap)#
Where the policy_map_name is the name of the policy map. The CLI enters policy-map configuration mode.
Step 2 (Optional) To add a description to the policy map, enter the following command:
hostname(config-pmap)# description string
Step 3 To configure parameters that affect the inspection engine, perform the following steps:
a. To enter parameters configuration mode, enter the following command:
hostname(config-pmap)# parameters hostname(config-pmap-p)#
b. To configure for ESP traffic, enter the following command:
hostname(config-pmap-p)# esp per-client-max value timeout timeout c. To configure for AH traffic, enter the following command:
hostname(config-pmap-p)# ah per-client-max value timeout timeout
The following example shows how to define an IPSec Pass Through map:
hostname(config)# access-list test-udp-acl extended permit udp any any eq 500
hostname(config)# class-map test-udp-class hostname(config-cmap)# match access-list test-udp-acl hostname(config)# policy-map type inspect IPSec-pass-thru IPsec-map hostname(config-pmap)# parameters hostname(config-pmap-p)# esp per-client-max 32 timeout 00:06:00 hostname(config-pmap-p)# ah per-client-max 16 timeout 00:05:00
hostname(config)# policy-map test-udp-policy hostname(config-pmap)# class test-udp-class hostname(config-pmap-c)# inspect IPSec-pass-thru IPSec-map
This policy is applied on the interface that has the policy to permit UDP 500 traffic through initially. In this example it is the outside interface.
To verify that the inspection engine opens the ESP or AH data flows for IPSec Pass Through based on the IKE control flow, use the show conn command:
hostname(config)# show conn
ESP out 192.168.51.25 in 192.168.52.49 idle 0:00:00 bytes 108
AH out 192.168.51.25 in 192.168.52.49 idle 0:00:01 bytes 0
ESP out 192.168.51.25 in 192.168.52.49 idle 0:00:01 bytes 0
UDP out 192.168.51.25:500 in 192.168.52.49:500 idle 0:00:00 flags -
AH out 192.168.51.25 in 192.168.52.50 idle 0:00:22 bytes 0
ESP out 192.168.51.25 in 192.168.52.50 idle 0:00:22 bytes 0
UDP out 192.168.51.25:500 in 192.168.52.50:500 idle 0:00:00 flags -
ESP out 192.168.51.25 in 192.168.52.49 idle 0:00:00 bytes 108
AH out 192.168.51.25 in 192.168.52.50 idle 0:00:00 bytes 2080
Continue reading here: RTSP Inspection Overview
Was this article helpful?
Readers' Questions
-
aziz7 months ago
- Reply