Solved

Configure site-to-site VPN connection between ASA 5505 and Pix 506

Posted on 2008-10-15
8
1,004 Views
Last Modified: 2010-05-05
   

Outside ip add  y.y.y.y                                                                    Outside ip add k.k.k.k
                               ASA (//////).....................ISP......................(//////) pix
Inside ip add     x.x.x.x       .                                                       .    Inside ip add  r.r.r.r
                                           .                                                       .
                                           .                                                       .
                                          C1                                                     C2
Hi everyone,

In the top is the diagram about the network, and I like to configur the pix and the ASA firwalls. Can anyone help me here with the confguration for both pix and ASA?
0
Comment
Question by:AL-Faide
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
8 Comments
 
LVL 8

Assisted Solution

by:Jay_Gridley
Jay_Gridley earned 75 total points
ID: 22719203
Here you can find detailed instrutions to configure a site to site tunnel on an ASA:
http://www.cisco.com/en/US/docs/security/asa/asa80/getting_started/asa5505/quick/guide/sitesite.html

Here you can find detailed instructions to configure a site to site tunnel on a PIX:
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a008055bd85.shtml

I hope this helps.
If you have specific questions don't hesitate to ask.

JG
0
 
LVL 57

Assisted Solution

by:Pete Long
Pete Long earned 125 total points
ID: 22719912
Heres some more info from my website http://www.petenetlive.com/Tech/Firewalls/Cisco/s2svpn.htm

If I were you Id configure the PIX first then configure the ASA
the pix will default to DES with MD5 change it to 3DES and SHA1
Then when you configure the ASA lease it all on its defaults
Then Disable PFS (perfect forward Secrecy) on the ASA for this tunnel and it should come up fine and dandy

on a PIX (v6, which yours will be) PFS is turned off by default on an ASA its turned on (thats why it said do it in this order - Ive done a few hundred of them by now :)

Pete
0
 

Author Comment

by:AL-Faide
ID: 22719977
Jay Gridley,
The links which you sent to me seems helpfull thanks, but I do not wana configure the site-to-site through the wizerd I like to confgure the ASA and pix through the command line (CLS). Can you help me with that? And I changed the points to 200
0
Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

 

Author Comment

by:AL-Faide
ID: 22720066
and I'm trying to configure the telnet on the ASA but it's not working. Can you help me on this please?
                                                                                                                                                                                                                  ASA 5505 (//////).....................ISP
inside ip add          172.16.177.1               .                                                      
                                                                  .                                                      
                                                                  .
PC ip add                172.16.177.2             C1  
mask                       255.255.255.0
Defult                      172.16.177.1
0
 
LVL 57

Accepted Solution

by:
Pete Long earned 125 total points
ID: 22720956
>>I like to confgure the ASA and pix through the command line (CLS). Can you help me with that?

where
10.0.2.0 is behind the pix
10.0.1.0 is behind the ASA
123.123.123.123 is the ASA
234.234.234.234 is the pix

pix

access-list inside_outbound_nat0_acl permit ip any 10.0.1.0 255.255.255.0
access-list outside_cryptomap_20 permit ip 10.0.2.0  255.255.255.0 10.0.1.0  255.255.255.0
nat (inside) 0 access-list inside_outbound_nat0_acl
crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac
crypto map outside_map 20 ipsec-isakmp
crypto map outside_map 20 match address outside_cryptomap_20
crypto map outside_map 20 set peer 123.123.123.123
crypto map outside_map 20 set transform-set ESP-3DES-MD5
crypto map outside_map interface outside
isakmp enable outside
isakmp key 123abc address 123.123.123.123 netmask 255.255.255.255 no-xauth no-conf
ig-mode
isakmp policy 20 authentication pre-share
isakmp policy 20 encryption 3des
isakmp policy 20 hash md5
isakmp policy 20 group 2
isakmp policy 20 lifetime 86400


ASA

access-list outside_1_cryptomap extended permit ip 10.0.1.0 255.255.255.0 10.0.2.0 255.255.255.0
access-list nonat extended permit ip 10.0.1.0 255.255.255.0 10.0.2.0 255.255.255.0
nat (inside) 0 access-list nonat
crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-m5-hmac
crypto map outside_map 1 match address outside_1_cryptomap
crypto map outside_map 1 set peer 234.234.234.234
crypto map outside_map 1 set transform-set ESP-3DES-MD5
crypto map outside_map interface outside
crypto isakmp enable outside
crypto isakmp policy 10
 authentication pre-share
 encryption 3des
 hash sha
 group 2
 lifetime 86400
crypto isakmp nat-traversal
tunnel-group 234.234.234.234 type ipsec-l2l
tunnel-group 234.234.234.234 ipsec-attributes
 pre-shared-key 123abc




0
 

Author Comment

by:AL-Faide
ID: 22721927
Pete Thanks for your help
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 22722025
No probs
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 32644789
0

Featured Post

2017 Webroot Threat Report

MSPs: Get the facts you need to protect your clients.
The 2017 Webroot Threat Report provides a uniquely insightful global view into the analysis and discoveries made by the Webroot® Threat Intelligence Platform to provide insights on key trends and risks as seen by our users.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Concerto Cloud Services, a provider of fully managed private, public and hybrid cloud solutions, announced today it was named to the 20 Coolest Cloud Infrastructure Vendors Of The 2017 Cloud  (http://www.concertocloud.com/about/in-the-news/2017/02/0…
WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Suggested Courses

623 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question