1-2
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring L2TP over IPsec
Information About L2TP over IPsec/IKEv1
The minimum IPsec security association lifetime supported by the Windows client is 300 seconds. If the
lifetime on the ASA is set to less than 300 seconds, the Windows client ignores it and replaces it with a
300 second lifetime.
IPsec Transport and Tunnel Modes
By default, the ASA uses IPsec tunnel mode—the entire original IP datagram is encrypted, and it
becomes the payload in a new IP packet. This mode allows a network device, such as a router, to act as
an IPsec proxy. That is, the router performs encryption on behalf of the hosts. The source router encrypts
packets and forwards them along the IPsec tunnel. The destination router decrypts the original IP
datagram and forwards it on to the destination system. The major advantage of tunnel mode is that the
end systems do not need to be modified to receive the benefits of IPsec. Tunnel mode also protects
against traffic analysis; with tunnel mode, an attacker can only determine the tunnel endpoints and not
the true source and destination of the tunneled packets, even if they are the same as the tunnel endpoints.
However, the Windows L2TP/IPsec client uses IPsec transport mode—only the IP payload is encrypted,
and the original IP headers are left intact. This mode has the advantages of adding only a few bytes to
each packet and allowing devices on the public network to see the final source and destination of the
packet.
illustrates the differences between IPsec tunnel and transport modes.
In order for Windows L2TP and IPsec clients to connect to the ASA, you must configure IPsec transport
mode for a transform set using the
crypto ipsec transform-set trans_name mode transport
command.
This command is used in the configuration procedure
.
With this transport capability, you can enable special processing (for example, QoS) on the intermediate
network based on the information in the IP header. However, the Layer 4 header is encrypted, which
limits the examination of the packet. Unfortunately, if the IP header is transmitted in clear text, transport
mode allows an attacker to perform some traffic analysis.
Figure 1-1
IPsec in Tunnel and Transport Modes
IP HDR
23246
Data
Encrypted
Tunnel mode
IP HDR
Data
Encrypted
IPSec HDR
New IP HDR
IP HDR
Data
Transport mode
Data
IPSec HDR
IP HDR
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......