EasyManua.ls Logo

Cisco ASA 5515-X

Cisco ASA 5515-X
2164 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
1-29
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring IPsec and ISAKMP
Configuring IPsec
Step 2 Perform large modulus operation in the hardware:
large-mode-accel
Applying Crypto Maps to Interfaces
You must assign a crypto map set to each interface through which IPsec traffic flows. The ASA supports
IPsec on all interfaces. Assigning the crypto map set to an interface instructs the ASA to evaluate all the
traffic against the crypto map set and to use the specified policy during connection or SA negotiation.
Assigning a crypto map to an interface also initializes run-time data structures, such as the SA database
and the security policy database. Reassigning a modified crypto map to the interface resynchronizes the
run-time data structures with the crypto map configuration. Also, adding new peers through the use of
new sequence numbers and reassigning the crypto map does not tear down existing connections.
Using Interface Access Lists
By default, the ASA lets IPsec packets bypass interface ACLs. If you want to apply interface access lists
to IPsec traffic, use the no form of the sysopt connection permit-vpn command.
The crypto map access list bound to the outgoing interface either permits or denies IPsec packets through
the VPN tunnel. IPsec authenticates and deciphers packets that arrive from an IPsec tunnel, and subjects
them to evaluation against the ACL associated with the tunnel.
Access lists define which IP traffic to protect. For example, you can create access lists to protect all IP
traffic between two subnets or two hosts. (These access lists are similar to access lists used with the
access-group command. However, with the access-group command, the access list determines which
traffic to forward or block at an interface.)
Before the assignment to crypto maps, the access lists are not specific to IPsec. Each crypto map
references the access lists and determines the IPsec properties to apply to a packet if it matches a permit
in one of the access lists.
Access lists assigned to IPsec crypto maps have four primary functions:
Select outbound traffic to be protected by IPsec (permit = protect).
Trigger an ISAKMP negotiation for data travelling without an established SA.
Process inbound traffic to filter out and discard traffic that should have been protected by IPsec.
Determine whether to accept requests for IPsec SAs when processing IKE negotiation from the peer.
(Negotiation applies only to ipsec-isakmp crypto map entries.) The peer must permit a data flow
associated with an ipsec-isakmp crypto map command entry to ensure acceptance during
negotiation.
Regardless of whether the traffic is inbound or outbound, the ASA evaluates traffic against the access
lists assigned to an interface. Follow these steps to assign IPsec to an interface:
Step 1 Create the access lists to be used for IPsec.
Step 2 Map the lists to one or more crypto maps, using the same crypto map name.
Step 3 Map the IKEv1 transform sets or IKEv2 proposals to the crypto maps to apply IPsec to the data flows.

Table of Contents

Other manuals for Cisco ASA 5515-X

Related product manuals