EasyManuals Logo
Home>Cisco>Firewall>5510 - ASA SSL / IPsec VPN Edition

Cisco 5510 - ASA SSL / IPsec VPN Edition User Manual

Cisco 5510 - ASA SSL / IPsec VPN Edition
2164 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #1581 background imageLoading...
Page #1581 background image
1-31
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring IPsec and ISAKMP
Configuring IPsec
Note Every static crypto map must define an access list and an IPsec peer. If either is missing, the crypto map
is incomplete and the ASA drops any traffic that it has not already matched to an earlier, complete crypto
map. Use the show conf command to ensure that every crypto map is complete. To fix an incomplete
crypto map, remove the crypto map, add the missing entries, and reapply it.
We discourage the use of the any keyword to specify source or destination addresses in crypto access
lists because they cause problems. We strongly discourage the permit any any command statement
because it does the following:
• Protects all outbound traffic, including all protected traffic sent to the peer specified in the
corresponding crypto map.
• Requires protection for all inbound traffic.
In this scenario, the ASA silently drops all inbound packets that lack IPsec protection.
Be sure that you define which packets to protect. If you use the any keyword in a permit statement,
preface it with a series of deny statements to filter out traffic that would otherwise fall within that permit
statement that you do not want to protect.
Note Decrypted through traffic is permitted from the client despite having an access group on the outside
interface, which calls a deny ip any any access-list, while no sysopt connection permit-vpn is
configured.
Users who want to control access to the protected network via site-to-site or remote access VPN using
the no sysopt permit command in conjunction with an access control list (ACL) on the outside interface
are not successful.
In this situation, when management-access inside is enabled, the ACL is not applied, and users can still
connect using SSH to the security appliance. Traffic to hosts on the inside network are blocked correctly
by the ACL, but cannot block decrypted through traffic to the inside interface.
The ssh and http commands are of a higher priority than the ACLs. In other words, to deny SSH, Telnet,
or ICMP traffic to the device from the VPN session, use ssh, telnet and icmp commands, which deny
the IP local pool should be added.
Changing IPsec SA Lifetimes
You can change the global lifetime values that the ASA uses when negotiating new IPsec SAs. You can
override these global lifetime values for a particular crypto map.
IPsec SAs use a derived, shared, secret key. The key is an integral part of the SA; the keys time out
together to require the key to refresh. Each SA has two lifetimes: timed and traffic-volume. An SA
expires after the respective lifetime and negotiations begin for a new one. The default lifetimes are
28,800 seconds (eight hours) and 4,608,000 kilobytes (10 megabytes per second for one hour).
If you change a global lifetime, the ASA drops the tunnel. It uses the new value in the negotiation of
subsequently established SAs.
When a crypto map does not have configured lifetime values and the ASA requests a new SA, it inserts
the global lifetime values used in the existing SA into the request sent to the peer. When a peer receives
a negotiation request, it uses the smaller of either the lifetime value the peer proposes or the locally
configured lifetime value as the lifetime of the new SA.

Table of Contents

Other manuals for Cisco 5510 - ASA SSL / IPsec VPN Edition

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco 5510 - ASA SSL / IPsec VPN Edition and is the answer not in the manual?

Cisco 5510 - ASA SSL / IPsec VPN Edition Specifications

General IconGeneral
BrandCisco
Model5510 - ASA SSL / IPsec VPN Edition
CategoryFirewall
LanguageEnglish

Related product manuals