6: Networking
EMG™ Edge Management Gateway User Guide
98
Cisco configuration
interface GigabitEthernet0/0
nameif outside
security-level 0
ip address 192.168.1.130 255.255.255.0
interface GigabitEthernet0/3
nameif inside security-level 100
ip address 192.168.3.130 255.255.255.0
object-group network local-network
network-object 192.168.3.0 255.255.255.0
network-object 192.168.3.250 255.255.255.255
object-group network remote-network
network-object 192.168.0.0 255.255.255.0
network-object 192.168.0.222 255.255.255.255
access-list asa-router-vpn extended permit ip object-group local-network
object-group remote-network
access-list ASA-SLC-ACCESS extended permit ip object-group local-network
object-group remote-network
route outside 192.168.0.0 255.255.255.0 192.168.1.204 1
route inside 192.168.3.250 255.255.255.255 192.168.3.250 1
crypto ipsec ikev2 ipsec-proposal IPSECv2
protocol esp encryption 3des
protocol esp integrity sha-256
crypto ipsec security-association pmtu-aging infinite
crypto map CM 20
match address ASA-SLC-ACCESS
set pfs group5
set peer 192.168.1.204
set ikev2 ipsec-proposal IPSECv2
crypto map CM interface outside
crypto ikev2 policy 20
encryption 3des integrity sha256
group 5
prf sha256
lifetime seconds 86400
crypto ikev2 enable outside
tunnel-group 192.168.1.204 type ipsec-l2l
tunnel-group 192.168.1.204 ipsec-attributes
ikev2 remote-authentication pre-shared-key *****
ikev2 local-authentication pre-shared-key *****