Get the App
SLTechnology News&Howtos  ›  Network Security  › 

ASA8.2 version and the following ipsec tunnel configuration templates

Shulou Source: shulou.com Published: 2022-06-01 05:37:53 10月04日 Update

Configuration template:

Interface e0/0

Nameif inside

Security-level 100

Ip address x.x.x.x 255.255.255.0 (modified to local private network IP and mask)

!

Interface e0/1

Nameif outside

Security-level 0

Ip address x.x.x.x 255.255.255.248 (modified to local public network IP and mask)

!

Interface Ethernet0/2

!

Interface Ethernet0/3

!

Access-list 101extended permit ip x.x.x.x 255.255.255.0 x.x.0.0 255.255.0.0 (modified to local private network IP and mask)

Route outside 0.0.0.0 0.0.0.0 x.x.x.x (modified to local public network gateway)

Crypto ipsec transform-set name 1 esp-3des esp-md5-hmac (define character set)

Crypto map test 1 match address 101 (define stream of interest)

Crypto map test 1 set peer x.x.x.x (remote public network IP)

Crypto map test 1 set transform-set name 1

Crypto map test interface outside (API call Policy)

Crypto isakmp enable outside (enable IKE negotiation)

Crypto isakmp policy 10 (IKE Security Policy)

Authentication pre-share

Encryption des

Hash md5

Group 2

Lifetime 86400

!

Tunnel-group x.x.x.x type ipsec-l2l / / defines × × in the form of peer

Tunnel-group x.x.x.x ipsec-attributes// enters the attribute configuration of ipsec-***

Pre-shared-key xxx authentication key

Tags: X.x.x.x public network configuration name policy template security interest character character set key attribute form interface gateway negotiation authentication version tunnel Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Shulou Technology Linux Huawei NVidia Xiaomi