C i s c o P r o f i l e C o n t a c t s & F e e d b a c k H e l p C isc o S M B S up p ort A ssistant Pass Routing Information over IPsec VPN Tunnel between two ASA/PIX H ome > W ork W ith M y S ec urity D evic es > C isc o S ec urity A p p l ianc es > P a s s R o u t i n g I n f o r m a t i o n o v e r I P s e c V P N T u n n e l b e t w e e n t w o A S A / P I X Pass Routing Information over IPsec VPN Tunnel between two ASA/PIX Introd uc tion Req uirements C onfigure Router to Router G RE T unnel C onfigure PIX / A S A to Pass Routing Information over IPsec V PN N ex t S tep T roub l esh oot th e Proc ed ure Rel ated Information Download PDF Pass Routing Information over IPsec V PN T unnel b etw een tw o A S A / PIX S e r v i c e R e q u e s t s O p en a servic e req uest U p d ate a servic e req uest Fe e db ac k P l e a s e r a t e t h i s s i t e : + + + + / - - - - S u g g e s t i o n s f o r i m p r o v e m e n t : I nt r odu c t i on T h is d oc ument ex p l ains h ow to p ass routing information over IPsec V PN tunnel b etw een tw o A S A / PIX. T h is d oc ument ap p l ies to C isc o A S A / PIX sec urity ap p l ianc es th at runs softw are version 7.x or ab ove. A n IPsec V PN tunnel al l ow s unic ast IP p ac k ets to fl ow th rough it. M ul tic ast p ac k ets, and oth er netw ork l ay er p rotoc ol p ac k ets ( e.g. IPX ), are not al l ow ed to p ass th rough IPsec V PN tunnel. Routing p rotoc ol s th at uses th e mul tic ast to p rop agate routing information, c oul d not w ork if th e netw ork c onnec tivity is th rough IPsec V PN tunnel. T o overc ome th is l imitation, th e mul tic ast traffic is enc ap sul ated in a G RE tunnel, th at ex ists b etw een tw o routers at d ifferent sites, and th en sent to th e sec urity ap p l ianc e th at c onnec ts to th e oth er site via an IPsec V PN tunnel. G eneric routing enc ap sul ation ( G RE ) is a tunnel ing p rotoc ol, d evel op ed b y C isc o, to enc ap sul ate a w id e variety of p rotoc ol p ac k et ty p es insid e IP tunnel. I f C i s c o m a y c o n t a c t y o u f o r m o r e d e t a i l s o r f o r f u t u r e f e e d b a c k o p p o r t u n i t i e s, p l e a s e e n t e r y o u r c o n t a c t i n f o r m a t i o n : F u l l N a m e : E m a i l : R e q u i r e m e nt s T o p erform th e step s in th is d oc ument, y ou need th ese items: C omp l ete th e, C onfigure th e A S A 5 5 0 0 S ec urity A p p l ianc e d oc ument. C omp l ete th e, S et U p a S ite- to- S ite V PN on th e A S A / PIX S ec urity A p p l ianc e d oc ument. Y ou must h ave a set of p ub l ic IP ad d resses assigned from y our Internet S ervic e Provid er entered in fiel d B 4 0 of th e Internet W ork sh eet. N ot e : T h is d oc ument is b ased on A S D M version 6.1. O th er versions d isp l ay a d ifferent outp ut. C onf i g u r e R ou t e r t o R ou t e r G R E T u nne l F ol l ow th ese step s, in ord er to c onfigure G RE tunnel b etw een tw o routers at d ifferent sites: 1. C onnec t to th e c onsol e c ab l e of th e router. Refer to for more information. G et into th e c onfiguration mod e, and enter th e i nt e r f ac e T u nne l 0 c ommand to c reate tunnel interfac e for G RE. 2. F ol l ow th eses step s, in ord er to c onfigure th e tunnel p arameters: a. b. U se th e i p addr e s s c ommand fol l ow ed b y an IP ad d ress, and sub net mask to c onfigure an IP ad d ress for th is tunnel interfac e. U se t u nne l s ou r c e c ommand to assign th e router interfac e c onnec ted to PIX / A S A as tunnel sourc e interfac e. c. U se t u nne l de s t i nat i on c ommand to assign th e IP ad d ress of th e remote router s interfac e c onnec ted to PIX / A S A as th e d estination for th is tunnel. d. E x it from th e c onfiguration mod e using th e e x i t c ommand. 1 of 5
M M 3. F orc e th e insid e netw ork or p rivate netw ork traffic th rough th e G RE tunnel using i p r ou t e c ommand, fol l ow ed b y th e internal / p rivate netw ork ad d ress as sourc e, and tunnel 0 interfac e as d estination. 4. E x it from th e c onfiguration mod e, and save th is c onfiguration to fl ash using th e wr i t e m e m or y c ommand. N ot e : Rep eat th e same step s on th e oth er end router, to c onfigure G RE on th at router as w el l. C onf i g u r e PI X / A S A t o Pas s R ou t i ng I nf or m at i on ov e r I Ps e c V PN F ol l ow th ese step s, in ord er to c onfigure PIX / A S A to p ass routing information over an IPsec V PN tunnel : 1. C reate a site- to- site IPsec V PN tunnel b etw een th e tw o sec urity d evic es. Refer to th e Complete the VPN wizard sec tion of S et U p a S ite- to- S ite V PN on th e A S A / PIX S ec urity A p p l ianc e for more information. 2. a. ak e sure th at in step 6, y ou enter th e IP ad d ress of th e netw ork c onnec ted to PIX / A S A insid e interfac e, and not th e ac tual p rivate or internal netw ork. b. ak e sure th at in step 7, y ou enter th e IP ad d ress of th e netw ork c onnec ted to remote PIX / A S A insid e interfac e. C l ic k C onf i g u r at i on on top of th e sc reen. 3. C l ic k S i t e - t o- S i t e V PN from th e l eft sid e menu. 4. E x p and th e A d vanc ed op tions, and c l ic k A C L M anag e r. 2 of 5
5. S el ec t th e A c c ess l ist th at sp ec ifies th e c ry p to map for th e IPsec tunnel, and c l ic k E di t. 6. C l ic k th e sq uare b ox in th e S ervic e op tions. 7. S el ec t g r e, and c l ic k O K. 3 of 5
8. C l ic k O K to ac c ep t th e c h anges. 9. C l ic k A p p ly to send th is c onfiguration to th e d evic e. 1 0. C l ic k S av e on top of th e sc reen, to save th is c onfiguration to fl ash. 4 of 5
N e x t S t e p Y ou h ave c omp l eted th is p roc ed ure. Refer to th e, S ec urity A p p l ianc e S up p ort Page to mak e furth er c h anges to th e PIX / A S A. Refer to th e, C onfiguration O verview Page to c onfigure oth er d evic es in y our netw ork. T r ou b le s h oot t h e Pr oc e du r e T h is sec tion p rovid es information ab out c ommon p rob l ems th at y ou c an enc ounter. If th is information d oes not sol ve y our p rob l em, c ontac t th e S M B T ec h nic al A ssistanc e C enter ( S M B T A C ) for assistanc e. Prob l em C ause( s) and S uggested S ol ution( s) Y ou c oul d not c onnec t to th e PIX / A S A. E nsure th at y ou ty p e https b efore th e PIX / A S A IP ad d ress in y our b row ser. E nsure th at y ou are c onnec ted c orrec tl y to th e PIX / A S A interfac e. R e lat e d I nf or m at i on S ite S urvey C onfigure an IP A d d ress on Y our PC C onfigure th e A S A 5 5 0 0 S ec urity A p p l ianc e C onfigure PIX 5 0 0 series S ec urity A p p l ianc e 1 9 9 2-2 0 0 6 C isc o S y stems, Inc. A l l righ ts reserved. T erms and C ond itions, Privac y S tatement, C ook ie Pol ic y and T rad emark s of C isc o S y stems, Inc. 5 of 5