1-22
Cisco ASA Series CLI Configuration Guide
Chapter 1 Introduction to the Cisco ASA
New Features
Next Generation Encryption
The National Standards Association (NSA) specified a set of cryptographic
algorithms that devices must support to meet U.S. federal standards for
cryptographic strength. RFC 6379 defines the Suite B cryptographic suites.
Because the collective set of algorithms defined as NSA Suite B are becoming
a standard, the AnyConnect IPsec VPN (IKEv2 only) and public key
infrastructure (PKI) subsystems now support them. The next generation
encryption (NGE) includes a larger superset of this set adding cryptographic
algorithms for IPsec V3 VPN, Diffie-Hellman Groups 14 and 24 for IKEv2,
and RSA certificates with 4096 bit keys for DTLS and IKEv2.
The following functionality is added to ASA to support the Suite B algorithms:
•
AES-GCM/GMAC support (128-, 192-, and 256-bit keys)
–
IKEv2 payload encryption and authentication
–
ESP packet encryption and authentication
–
Hardware supported only on multi-core platforms
•
SHA-2 support (256-, 384-, and 512-bit hashes)
–
ESP packet authentication
–
Hardware and software supported only on multi-core platforms
•
ECDH support (groups 19, 20, and 21)
–
IKEv2 key exchange
–
IKEv2 PFS
–
Software only supported on single- or multi-core platforms
•
ECDSA support (256-, 384-, and 521-bit elliptic curves)
–
IKEv2 user authentication
–
PKI certificate enrollment
–
PKI certificate generation and verification
–
Software only supported on single- or multi-core platforms
New cryptographic algorithms are added for IPsecV3.
Note
Suite B algorithm support requires an AnyConnect Premium license
for IKEv2 remote access connections, but Suite B usage for other
connections or purposes (such as PKI) has no limitations. IPsecV3 has
no licensing restrictions.
We introduced or modified the following commands:
crypto ikev2 policy
,
crypto ipsec ikev2 ipsec-proposal
,
crypto key generate
,
crypto key zeroize
,
show crypto key mypubkey
,
show vpn-sessiondb
.
We introduced or modified the following screens:
Monitor > VPN > Sessions
Monitor > VPN > Encryption Statistics
Configuration > Site-to-Site VPN > Certificate Management > Identity
Certificates
Configuration > Site-to-Site VPN > Advanced > System Options
Configuration > Remote Access VPN > Network (Client) Access > Advanced
> IPsec > Crypto Maps
Table 1-5
New Features for ASA Version 9.0(1)/ASDM Version 7.0(1) (continued)
Feature
Description
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......