
1-5
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring Easy VPN Services on the ASA 5505
Comparing Tunneling Options
If you configure an ASA 5505 to use TCP-encapsulated IPsec, enter the following command to let it send
large packets over the outside interface:
hostname(config)#
crypto ipsec df-bit clear-df outside
hostname(config)#
This command clears the Don't Fragment (DF) bit from the encapsulated header. A DF bit is a bit within
the IP header that determines whether the packet can be fragmented. This command lets the Easy VPN
hardware client send packets that are larger than the MTU size.
The following example shows how to configure the Easy VPN hardware client to use TCP-encapsulated
IPsec, using the default port 10000, and to let it send large packets over the outside interface:
hostname(config)#
vpnclient ipsec-over-tcp
hostname(config)#
crypto ipsec df-bit clear-df outside
hostname(config)#
The next example shows how to configure the Easy VPN hardware client to use TCP-encapsulated IPsec,
using the port 10501, and to let it send large packets over the outside interface:
hostname(config)#
vpnclient ipsec-over-tcp port 10501
hostname(config)#
crypto ipsec df-bit clear-df outside
hostname(config)#
To remove the attribute from the running configuration, use the
no
form of this command, as follows:
no vpnclient ipsec-over-tcp
For example:
hostname(config)#
no vpnclient ipsec-over-tcp
hostname(config)#
Comparing Tunneling Options
The tunnel types the Cisco ASA 5505 configured as an Easy VPN hardware client sets up depends on a
combination of the following factors:
•
Use of the
split-tunnel-network-list
and the
split-tunnel-policy
commands on the headend to
permit, restrict, or prohibit split tunneling. (See the
Specify a Network List for Split-Tunneling,
and
“Setting the Split-Tunneling Policy” section on page 1-54
, respectively.)
Split tunneling determines the networks for which the remote-access client encrypts and sends data
through the secured VPN tunnel, and determines which traffic it sends to the Internet in the clear.
•
Use of the
command to specify one of the following automatic tunnel
initiation options:
–
tunnel
to limit administrative access to the client side by specific hosts or networks on the
corporate side and use IPsec to add a layer of encryption to the management sessions over the
HTTPS or SSH encryption that is already present.
–
clear
to permit administrative access using the HTTPS or SSH encryption used by the
management session.
–
no
to prohibit management access
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......