Enabling IPSec over TCP

IPSec over TCP enables a Cisco VPN client to operate in an environment in which standard ESP or ISAKMP cannot function, or can function only with modification to existing firewall rules. IPSec over TCP encapsulates both the ISAKMP and IPSec protocols within a TCP-like packet, and enables secure tunneling through both NAT and PAT devices and firewalls. This feature is disabled by default. % _

Note This feature does not work with proxy-based firewalls.

IPSec over TCP works with remote access clients. You enable it globally, and it works on all ISAKMP enabled interfaces. It is a client to security appliance feature only. It does not work for LAN-to-LAN connections.

The security appliance can simultaneously support standard IPSec, IPSec over TCP, NAT-Traversal, and IPSec over UDP, depending on the client with which it is exchanging data. IPSec over TCP, if enabled, takes precedence over all other connection methods.

The VPN 3002 hardware client, which supports one tunnel at a time, can connect using standard IPSec, IPSec over TCP, NAT-Traversal, or IPSec over UDP.

You enable IPSec over TCP on both the security appliance and the client to which it connects.

You can enable IPSec over TCP for up to 10 ports that you specify. If you enter a well-known port, for example port 80 (HTTP) or port 443 (HTTPS), the system displays a warning that the protocol associated with that port no longer works on the public interface. The consequence is that you can no longer use a browser to manage the security appliance through the public interface. To solve this problem, reconfigure the HTTP/HTTPS management to different ports.

The default port is 10000.

You must configure TCP port(s) on the client as well as on the security appliance. The client configuration must include at least one of the ports you set for the security appliance.

To enable IPSec over TCP globally on the security appliance, enter the following command:

crypto isakmp ipsec-over-tcp [port port 1...port0]

This example enables IPSec over TCP on port 45:

hostname(config)# crypto isakmp ctcp port 45

Configuring Certificate Group Matching I

Continue reading here: Using Dynamic Crypto Maps

Was this article helpful?

0 0

Readers' Questions

  • mustafa petros
    What ports does ipsec use?
    1 month ago
  • IPsec uses the following ports: - ESP (Encapsulating Security Payload): IPsec protocol suite uses IP protocol number 50 for ESP packets. It does not use any specific ports. - AH (Authentication Header): IPsec protocol suite uses IP protocol number 51 for AH packets. It also does not use any specific ports. - UDP 500: IPsec uses UDP port 500 for IKE (Internet Key Exchange) phase 1 negotiation. This is used to establish a secure connection and negotiate parameters for IPsec tunneling. - UDP 4500: IPsec also uses UDP port 4500 for NAT Traversal. This allows IPsec packets to pass through Network Address Translation (NAT) devices. Note: The use of specific ports may vary depending on the implementation and configuration of IPsec.
    • benjamin
      What protocol and port number does isakmp use?
      6 months ago
    • ISAKMP (Internet Security Association and Key Management Protocol) uses UDP port 500.
      • Cerys
        What protocol and port does isakmp use?
        7 months ago
      • UDP port 500
        • reece
          What port does ipsec use?
          8 months ago
        • IPsec typically uses both UDP port 500 and IP protocol type 50 for communication.