1-31
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring IPsec and ISAKMP
Configuring IPsec
Note
Every static crypto map must define an access list and an IPsec peer. If either is missing, the crypto map
is incomplete and the ASA drops any traffic that it has not already matched to an earlier, complete crypto
map. Use the
show conf
command to ensure that every crypto map is complete. To fix an incomplete
crypto map, remove the crypto map, add the missing entries, and reapply it.
We discourage the use of the
any
keyword to specify source or destination addresses in crypto access
lists because they cause problems. We strongly discourage the
permit any any
command statement
because it does the following:
•
Protects all outbound traffic, including all protected traffic sent to the peer specified in the
corresponding crypto map.
•
Requires protection for all inbound traffic.
In this scenario, the ASA silently drops all inbound packets that lack IPsec protection.
Be sure that you define which packets to protect. If you use the
any
keyword in a
permit
statement,
preface it with a series of
deny
statements to filter out traffic that would otherwise fall within that
permit
statement that you do not want to protect.
Note
Decrypted through traffic is permitted from the client despite having an access group on the outside
interface, which calls a deny ip any any access-list, while
no sysopt connection permit-vpn
is
configured.
Users who want to control access to the protected network via site-to-site or remote access VPN using
the
no sysopt permit
command in conjunction with an access control list (ACL) on the outside interface
are not successful.
In this situation, when management-access inside is enabled, the ACL is not applied, and users can still
connect using SSH to the security appliance. Traffic to hosts on the inside network are blocked correctly
by the ACL, but cannot block decrypted through traffic to the inside interface.
The
ssh
and
http
commands are of a higher priority than the ACLs. In other words, to deny SSH, Telnet,
or ICMP traffic to the device from the VPN session, use
ssh
,
telnet
and
icmp
commands, which deny
the IP local pool should be added.
Changing IPsec SA Lifetimes
You can change the global lifetime values that the ASA uses when negotiating new IPsec SAs. You can
override these global lifetime values for a particular crypto map.
IPsec SAs use a derived, shared, secret key. The key is an integral part of the SA; the keys time out
together to require the key to refresh. Each SA has two lifetimes: timed and traffic-volume. An SA
expires after the respective lifetime and negotiations begin for a new one. The default lifetimes are
28,800 seconds (eight hours) and 4,608,000 kilobytes (10 megabytes per second for one hour).
If you change a global lifetime, the ASA drops the tunnel. It uses the new value in the negotiation of
subsequently established SAs.
When a crypto map does not have configured lifetime values and the ASA requests a new SA, it inserts
the global lifetime values used in the existing SA into the request sent to the peer. When a peer receives
a negotiation request, it uses the smaller of either the lifetime value the peer proposes or the locally
configured lifetime value as the lifetime of the new SA.
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......