Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Configure site-to-site VPN connection between ASA 5505 and Pix 506

Posted on 2008-10-15
8
Medium Priority
?
1,010 Views
Last Modified: 2010-05-05
   

Outside ip add  y.y.y.y                                                                    Outside ip add k.k.k.k
                               ASA (//////).....................ISP......................(//////) pix
Inside ip add     x.x.x.x       .                                                       .    Inside ip add  r.r.r.r
                                           .                                                       .
                                           .                                                       .
                                          C1                                                     C2
Hi everyone,

In the top is the diagram about the network, and I like to configur the pix and the ASA firwalls. Can anyone help me here with the confguration for both pix and ASA?
0
Comment
Question by:AL-Faide
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
8 Comments
 
LVL 8

Assisted Solution

by:Jay_Gridley
Jay_Gridley earned 225 total points
ID: 22719203
Here you can find detailed instrutions to configure a site to site tunnel on an ASA:
http://www.cisco.com/en/US/docs/security/asa/asa80/getting_started/asa5505/quick/guide/sitesite.html

Here you can find detailed instructions to configure a site to site tunnel on a PIX:
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a008055bd85.shtml

I hope this helps.
If you have specific questions don't hesitate to ask.

JG
0
 
LVL 57

Assisted Solution

by:Pete Long
Pete Long earned 375 total points
ID: 22719912
Heres some more info from my website http://www.petenetlive.com/Tech/Firewalls/Cisco/s2svpn.htm

If I were you Id configure the PIX first then configure the ASA
the pix will default to DES with MD5 change it to 3DES and SHA1
Then when you configure the ASA lease it all on its defaults
Then Disable PFS (perfect forward Secrecy) on the ASA for this tunnel and it should come up fine and dandy

on a PIX (v6, which yours will be) PFS is turned off by default on an ASA its turned on (thats why it said do it in this order - Ive done a few hundred of them by now :)

Pete
0
 

Author Comment

by:AL-Faide
ID: 22719977
Jay Gridley,
The links which you sent to me seems helpfull thanks, but I do not wana configure the site-to-site through the wizerd I like to confgure the ASA and pix through the command line (CLS). Can you help me with that? And I changed the points to 200
0
Turn your laptop into a mobile console!

The CV211 Laptop USB Console Adapter provides a direct Laptop-to-Computer connection for fast and easy remote desktop access with no software to install.

 

Author Comment

by:AL-Faide
ID: 22720066
and I'm trying to configure the telnet on the ASA but it's not working. Can you help me on this please?
                                                                                                                                                                                                                  ASA 5505 (//////).....................ISP
inside ip add          172.16.177.1               .                                                      
                                                                  .                                                      
                                                                  .
PC ip add                172.16.177.2             C1  
mask                       255.255.255.0
Defult                      172.16.177.1
0
 
LVL 57

Accepted Solution

by:
Pete Long earned 375 total points
ID: 22720956
>>I like to confgure the ASA and pix through the command line (CLS). Can you help me with that?

where
10.0.2.0 is behind the pix
10.0.1.0 is behind the ASA
123.123.123.123 is the ASA
234.234.234.234 is the pix

pix

access-list inside_outbound_nat0_acl permit ip any 10.0.1.0 255.255.255.0
access-list outside_cryptomap_20 permit ip 10.0.2.0  255.255.255.0 10.0.1.0  255.255.255.0
nat (inside) 0 access-list inside_outbound_nat0_acl
crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac
crypto map outside_map 20 ipsec-isakmp
crypto map outside_map 20 match address outside_cryptomap_20
crypto map outside_map 20 set peer 123.123.123.123
crypto map outside_map 20 set transform-set ESP-3DES-MD5
crypto map outside_map interface outside
isakmp enable outside
isakmp key 123abc address 123.123.123.123 netmask 255.255.255.255 no-xauth no-conf
ig-mode
isakmp policy 20 authentication pre-share
isakmp policy 20 encryption 3des
isakmp policy 20 hash md5
isakmp policy 20 group 2
isakmp policy 20 lifetime 86400


ASA

access-list outside_1_cryptomap extended permit ip 10.0.1.0 255.255.255.0 10.0.2.0 255.255.255.0
access-list nonat extended permit ip 10.0.1.0 255.255.255.0 10.0.2.0 255.255.255.0
nat (inside) 0 access-list nonat
crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-m5-hmac
crypto map outside_map 1 match address outside_1_cryptomap
crypto map outside_map 1 set peer 234.234.234.234
crypto map outside_map 1 set transform-set ESP-3DES-MD5
crypto map outside_map interface outside
crypto isakmp enable outside
crypto isakmp policy 10
 authentication pre-share
 encryption 3des
 hash sha
 group 2
 lifetime 86400
crypto isakmp nat-traversal
tunnel-group 234.234.234.234 type ipsec-l2l
tunnel-group 234.234.234.234 ipsec-attributes
 pre-shared-key 123abc




0
 

Author Comment

by:AL-Faide
ID: 22721927
Pete Thanks for your help
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 22722025
No probs
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 32644789
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When speed and performance are vital to revenue, companies must have complete confidence in their cloud environment.
On Feb. 28, Amazon’s Simple Storage Service (S3) went down after an employee issued the wrong command during a debugging exercise. Among those affected were big names like Netflix, Spotify and Expedia.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Suggested Courses

721 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question