EasyManuals Logo
Home>Cisco>Firewall>FirePOWER ASA 5500 series

Cisco FirePOWER ASA 5500 series User Manual

Cisco FirePOWER ASA 5500 series
989 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #513 background imageLoading...
Page #513 background image
27-11
Cisco Security Appliance Command Line Configuration Guide
OL-10088-01
Chapter 27 Configuring IPSec and ISAKMP
Configuring IPSec
The following example enables mapping of certificate-based ISAKMP sessions to a tunnel group based
on the IP address of the peer:
hostname(config)# tunnel-group-map enable peer-ip
hostname(config)#
The following example enables mapping of certificate-based ISAKMP sessions based on the
organizational unit (OU) in the subject distinguished name (DN):
hostname(config)# tunnel-group-map enable ou
hostname(config)#
The following example enables mapping of certificate-based ISAKMP sessions based on established
rules:
hostname(config)# tunnel-group-map enable rules
hostname(config)#
Using the Tunnel-group-map default-group Command
This command specifies a default tunnel group to use when the configuration does not specify a tunnel
group.
The syntax is tunnel-group-map [rule-index] default-group tunnel-group-name where the rule-index
is the priority for the rule, and tunnel-group name must be for a tunnel group that already exists.
Configuring IPSec
This section provides background information about IPSec and describes the procedures required to
configure the security appliance when using IPSec to implement a VPN. It contains the following topics:
• Understanding IPSec Tunnels, page 27-11
• Understanding Transform Sets, page 27-12
• Defining Crypto Maps, page 27-12
• Applying Crypto Maps to Interfaces, page 27-20
• Using Interface Access Lists, page 27-20
• Changing IPSec SA Lifetimes, page 27-22
• Creating a Basic IPSec Configuration, page 27-22
• Using Dynamic Crypto Maps, page 27-24
• Providing Site-to-Site Redundancy, page 27-26
• Viewing an IPSec Configuration, page 27-26
Understanding IPSec Tunnels
IPSec tunnels are sets of SAs that the security appliance establishes between peers. The SAs define the
protocols and algorithms to apply to sensitive data, and also specify the keying material the peers use.
IPSec SAs control the actual transmission of user traffic. SAs are unidirectional, but are generally
established in pairs (inbound and outbound).
The peers negotiate the settings to use for each SA. Each SA consists of the following:

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco FirePOWER ASA 5500 series and is the answer not in the manual?

Cisco FirePOWER ASA 5500 series Specifications

General IconGeneral
BrandCisco
ModelFirePOWER ASA 5500 series
CategoryFirewall
LanguageEnglish

Related product manuals