1-18
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring IPsec and ISAKMP
Configuring IPsec
•
You can assign multiple rules to the same group. To do that, you add the rule priority and group first.
Then you define as many criteria statements as you need for each group. When multiple rules are
assigned to the same group, a match results for the first rule that tests true.
•
By creating a single rule, you can require all criteria to match before assigning a user to a specific
tunnel group. Requiring all criteria to match is equivalent to a logical AND operation. Alternatively,
create one rule for each criterion if you want to require that only one match before assigning a user
to a specific tunnel group. Requiring only one criterion to match is equivalent to a logical OR
operation.
The following example enables mapping of certificate-based ISAKMP sessions to a tunnel group based
on the content of the phase1 ISAKMP ID:
hostname(config)#
tunnel-group-map enable ike-id
hostname(config)#
The following example enables mapping of certificate-based ISAKMP sessions to a tunnel group based
on the IP address of the peer:
hostname(config)#
tunnel-group-map enable peer-ip
hostname(config)#
The following example enables mapping of certificate-based ISAKMP sessions based on the
organizational unit (OU) in the subject distinguished name (DN):
hostname(config)#
tunnel-group-map enable ou
hostname(config)#
The following example enables mapping of certificate-based ISAKMP sessions based on established
rules:
hostname(config)#
tunnel-group-map enable rules
hostname(config)#
Using the Tunnel-group-map default-group Command
This command specifies a default tunnel group to use when the configuration does not specify a tunnel
group.
The syntax is
tunnel-group-map
[
rule-index
]
default-group
tunnel-group-name
where
rule-index
is the
priority for the rule, and
tunnel-group name
must be for a tunnel group that already exists.
Configuring IPsec
This section provides background information about IPsec and describes the procedures required to
configure the ASA when using IPsec to implement a VPN. It contains the following topics:
•
Understanding IPsec Tunnels, page 1-19
•
Understanding IKEv1 Transform Sets and IKEv2 Proposals, page 1-19
•
Defining Crypto Maps, page 1-19
•
Applying Crypto Maps to Interfaces, page 1-29
•
Using Interface Access Lists, page 1-29
•
Changing IPsec SA Lifetimes, page 1-31
•
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......