{"id":1371,"date":"2016-12-21T15:40:05","date_gmt":"2016-12-21T07:40:05","guid":{"rendered":"https:\/\/networkingnotesblog.wordpress.com\/?p=1371"},"modified":"2016-12-21T15:40:05","modified_gmt":"2016-12-21T07:40:05","slug":"cisco-asa-site-to-site-ipsec-vpn-with-dynamic-ip-address","status":"publish","type":"post","link":"http:\/\/notes4it.com\/?p=1371","title":{"rendered":"Cisco ASA &#8211; Site to Site IPSec VPN with dynamic IP address"},"content":{"rendered":"<p>Setting up a policy based site to site IPSec VPN tunnel with static IP address is quite stright forward in Cisco ASA, but what if one of the end point is using dymanic IP address?<br \/>\nIn this lab, I will be using 2 virtual ASA (9.6(2)) to create a site to site IPSec VPN tunnel, as well as setting up Cisco VPN client in one of the ASA with static IP address.<br \/>\nThe ASA-F14 is the one with static IP address, and the ASA-F16 is using dynamic IP address.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1230\" src=\"https:\/\/networkingnotesblog.files.wordpress.com\/2016\/12\/20161221-mpls-2vrfs.png\" alt=\"20161221-mpls-2vrfs\" width=\"840\" height=\"578\" srcset=\"http:\/\/notes4it.com\/wp-content\/uploads\/2016\/12\/20161221-mpls-2vrfs.png 840w, http:\/\/notes4it.com\/wp-content\/uploads\/2016\/12\/20161221-mpls-2vrfs-300x206.png 300w, http:\/\/notes4it.com\/wp-content\/uploads\/2016\/12\/20161221-mpls-2vrfs-768x528.png 768w\" sizes=\"auto, (max-width: 840px) 100vw, 840px\" \/><br \/>\n<!--more--><br \/>\nLet s take a look at the IP address of ASA-F14 and ASA-F16.<\/p>\n<table border=\"1\">\n<tbody>\n<tr>\n<td><span style=\"font-size:x-small;\">net-vASA-AS5052-F14# sho ip<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-size:x-small;\">System IP Addresses:<br \/>\nInterface\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Name\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 IP address\u00a0\u00a0\u00a0\u00a0\u00a0 Subnet mask\u00a0\u00a0\u00a0\u00a0 Method<br \/>\nGigabitEthernet0\/0.3979\u00a0 untrust\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.50.2.10\u00a0\u00a0\u00a0\u00a0\u00a0 255.255.255.248 manual<br \/>\nGigabitEthernet0\/1.1014\u00a0 trust\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 192.168.104.1\u00a0\u00a0 255.255.255.128 manual<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"1\">\n<tbody>\n<tr>\n<td><span style=\"font-size:x-small;\">net-AS5052-vASA-F16# sho ip<br \/>\n<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-size:x-small;\">System IP Addresses:<br \/>\nInterface\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Name\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 IP address\u00a0\u00a0\u00a0\u00a0\u00a0 Subnet mask\u00a0\u00a0\u00a0\u00a0 Method<br \/>\nGigabitEthernet0\/0.3978\u00a0 untrust\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 10.50.2.18\u00a0\u00a0\u00a0\u00a0\u00a0 255.255.255.252 manual<br \/>\nGigabitEthernet0\/2.1016\u00a0 trust\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 192.168.106.1\u00a0\u00a0 255.255.255.128 manual<br \/>\n<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Let s take a look at the configuration in ASA-F14 and ASA-F16 below.<br \/>\n&#8211; ASA-F14 has included the site to site IPSec vpn and the remote vpn syntax.<br \/>\n&#8211; ASA-F16 has a set of site to site IPSec VPN syntax only.<br \/>\n&#8211; Highlighted objects need to pay attentions to for creating L2L VPN with dynamic address.<br \/>\n&#8211; the related tunnel syntax are putting side by side for easy of comparison.<br \/>\n<!--more--><\/p>\n<table border=\"1\">\n<tbody>\n<tr>\n<td>\u00a0ASA-F14 (with static IP address)<\/td>\n<td>\u00a0ASA-F16 (with dynamic IP address)<\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-size:x-small;\">ip local pool ciscovpn_pool 192.168.0.10-192.168.0.15<br \/>\naccess-list testgroup_splitTunnel standard permit 192.168.104.0 255.255.255.128<br \/>\n<\/span><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-size:x-small;\">group-policy testgroup internal<br \/>\ngroup-policy testgroup attributes<br \/>\ndns-server value 1.2.3.4<br \/>\nvpn-tunnel-protocol ikev1<br \/>\nsplit-tunnel-policy tunnelspecified<br \/>\nsplit-tunnel-network-list value testgroup_splitTunnel<br \/>\ndefault-domain value testgroup.local<\/span><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-size:x-small;\">username netuser password ayQxwgFdIr4e4PXC encrypted privilege 15<br \/>\n<\/span><\/td>\n<td><span style=\"font-size:x-small;\"><br \/>\n<\/span><\/td>\n<\/tr>\n<tr>\n<td><\/td>\n<td><span style=\"font-size:x-small;\"><span style=\"color:#ff0000;\">crypto isakmp identity key-id VPN_F14-F16<br \/>\n<\/span>(this is to identify the firewall itself as the name that match with the end point s tunnel group name.)<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-size:x-small;\">tunnel-group <span style=\"color:#ff0000;\">VPN_F14-F16<\/span> type<span style=\"color:#0000ff;\"> ipsec-l2l<\/span><br \/>\ntunnel-group <span style=\"color:#ff0000;\">VPN_F14-F16<\/span> ipsec-attributes<br \/>\nikev1 pre-shared-key 123456<br \/>\n(The tunnel name for dynamic address end point is similar with Cisco remote access)<br \/>\n<\/span><\/td>\n<td><span style=\"font-size:x-small;\">tunnel-group<span style=\"color:#ff0000;\"> 10.50.2.10<\/span> type ipsec-l2l<br \/>\ntunnel-group <span style=\"color:#ff0000;\">10.50.2.10<\/span> ipsec-attributes<br \/>\nikev1 pre-shared-key 123456<br \/>\n(The tunnel configuration in ASA-F16 does not have anything special)<br \/>\n<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-size:x-small;\">tunnel-group testgroup type<span style=\"color:#0000ff;\"> remote-access<\/span><br \/>\ntunnel-group testgroup general-attributes<br \/>\naddress-pool ciscovpn_pool<br \/>\ndefault-group-policy testgroup<br \/>\ntunnel-group testgroup ipsec-attributes<br \/>\nikev1 pre-shared-key cisco123<\/span><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-size:x-small;\">crypto dynamic-map cisco_remote_vpn 5 set ikev1 transform-set ESP-3DES-MD5<br \/>\ncrypto dynamic-map cisco_remote_vpn 5 set reverse-route<br \/>\n<\/span><\/td>\n<td><span style=\"font-size:x-small;\"><br \/>\n<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-size:x-small;\">crypto dynamic-map L2L-dynamic_IP 5 match address vpn-F14_to_F16<br \/>\ncrypto dynamic-map L2L-dynamic_IP 5 set ikev1 transform-set ESP-3DES-MD5<br \/>\n<\/span><\/td>\n<td><span style=\"font-size:x-small;\"><br \/>\n<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-size:x-small;\">crypto map vpn 65530 ipsec-isakmp dynamic L2L-dynamic_IP<br \/>\n(The L2L vpn is slightly higher than the Cisco VPN client profile)<br \/>\n<\/span><\/td>\n<td><span style=\"font-size:x-small;\"><span style=\"font-size:x-small;\">crypto map vpn 50 match address vpn-F16_to_F14<br \/>\ncrypto map vpn 50 set peer 10.50.2.10<br \/>\ncrypto map vpn 50 set ikev1 phase1-mode aggressive<br \/>\ncrypto map vpn 50 set ikev1 transform-set ESP-3DES-MD5<\/span><\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-size:x-small;\">crypto map vpn 65535 ipsec-isakmp dynamic cisco_remote_vpn<br \/>\n<\/span><\/td>\n<td><span style=\"font-size:x-small;\"><br \/>\n<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-size:x-small;\">crypto map vpn interface untrust<br \/>\ncrypto ikev1 enable untrust<br \/>\n<\/span><\/td>\n<td><span style=\"font-size:x-small;\">crypto map vpn interface untrust<br \/>\ncrypto ikev1 enable untrust<br \/>\n<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-size:x-small;\">crypto ikev1 policy 1<br \/>\nauthentication pre-share<br \/>\nencryption 3des<br \/>\nhash sha<br \/>\ngroup 2<br \/>\nlifetime 86400<br \/>\ncrypto ikev1 policy 10<br \/>\nauthentication pre-share<br \/>\nencryption des<br \/>\nhash sha<br \/>\ngroup 2<br \/>\nlifetime 86400<\/span><\/td>\n<td><span style=\"font-size:x-small;\">crypto ikev1 policy 1<br \/>\nauthentication pre-share<br \/>\nencryption 3des<br \/>\nhash sha<br \/>\ngroup 2<br \/>\nlifetime 86400<br \/>\ncrypto ikev1 policy 10<br \/>\nauthentication pre-share<br \/>\nencryption des<br \/>\nhash sha<br \/>\ngroup 2<br \/>\nlifetime 86400<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-size:x-small;\">access-list vpn-F14_to_F16 extended permit ip 192.168.104.0 255.255.255.0 192.168.106.0 255.255.255.128<br \/>\n<\/span><\/td>\n<td><span style=\"font-size:x-small;\">access-list vpn-F16_to_F14 extended permit ip 192.168.106.0 255.255.255.128 192.168.104.0 255.255.255.0<br \/>\n<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><!--more--><br \/>\nThe testing result:<br \/>\nThe ikev1 sa:<br \/>\nSince ASA-F16 does not have static IP address, the tunnel will be always initial right from F16 to F14, which is similar with the Cisco vpn client.<\/p>\n<table border=\"1\">\n<tbody>\n<tr>\n<td><span style=\"font-size:x-small;\">net-vASA-AS5052-F14# show crypto ikev1 sa<\/span><\/td>\n<td><span style=\"font-size:x-small;\">net-vASA-AS5052-F16# show crypto ikev1 sa<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-size:x-small;\">IKEv1 SAs:<\/span><br \/>\n<span style=\"font-size:x-small;\">Active SA: 2<br \/>\nRekey SA: 0 (A tunnel will report 1 Active and 1 Rekey SA during rekey)<br \/>\nTotal IKE SA: 2<\/span><br \/>\n<span style=\"font-size:x-small;\">1\u00a0\u00a0 IKE Peer: 10.50.2.18<br \/>\nType\u00a0\u00a0\u00a0 : <span style=\"color:#0000ff;\">L2L<\/span>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Role\u00a0\u00a0\u00a0 : <strong><span style=\"color:#ff0000;\">responder<\/span><\/strong><br \/>\nRekey\u00a0\u00a0 : no\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 State\u00a0\u00a0 : AM_ACTIVE<br \/>\n2\u00a0\u00a0 IKE Peer: 192.168.109.10<br \/>\nType\u00a0\u00a0\u00a0 : <span style=\"color:#0000ff;\">user<\/span>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Role\u00a0\u00a0\u00a0 : responder<br \/>\nRekey\u00a0\u00a0 : no\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 State\u00a0\u00a0 : AM_ACTIVE<\/span><\/td>\n<td><span style=\"font-size:x-small;\">IKEv1 SAs:<\/span><br \/>\n<span style=\"font-size:x-small;\">Active SA: 1<br \/>\nRekey SA: 0 (A tunnel will report 1 Active and 1 Rekey SA during rekey)<br \/>\nTotal IKE SA: 1<\/span><br \/>\n<span style=\"font-size:x-small;\">1\u00a0\u00a0 IKE Peer: 10.50.2.10<br \/>\nType\u00a0\u00a0\u00a0 : L2L\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Role\u00a0\u00a0\u00a0 : <strong><span style=\"color:#ff0000;\">initiator<\/span><\/strong><br \/>\nRekey\u00a0\u00a0 : no\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 State\u00a0\u00a0 : AM_ACTIVE<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><!--more--><br \/>\nThe ipsec sa from both ASA.<\/p>\n<table border=\"1\">\n<tbody>\n<tr>\n<td><span style=\"font-size:x-small;\">net-vASA-AS5052-F14# sho crypto ipsec sa<br \/>\n<\/span><\/td>\n<td><span style=\"font-size:x-small;\">net-AS5052-vASA-F16# sho crypto ipsec sa<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-size:x-small;\"><span style=\"font-size:x-small;\"><span style=\"font-size:x-small;\">interface: untrust<br \/>\nCrypto map tag: L2L-dynamic_IP, seq num: 5, local addr: 10.50.2.10<\/span><\/span><\/span><span style=\"font-size:x-small;\">access-list vpn-F14_to_F16 extended permit ip 192.168.104.0 255.255.255.0 192.168.106.0 255.255.255.128<br \/>\nlocal ident (addr\/mask\/prot\/port): (192.168.104.0\/255.255.255.0\/0\/0)<br \/>\nremote ident (addr\/mask\/prot\/port): (192.168.106.0\/255.255.255.128\/0\/0)<br \/>\ncurrent_peer: 10.50.2.18<\/span><span style=\"font-size:x-small;\">#pkts encaps: 36168, #pkts encrypt: 36168, #pkts digest: 36168<br \/>\n#pkts decaps: 36168, #pkts decrypt: 36168, #pkts verify: 36168<br \/>\n#pkts compressed: 0, #pkts decompressed: 0<br \/>\n#pkts not compressed: 36168, #pkts comp failed: 0, #pkts decomp failed: 0<br \/>\n#pre-frag successes: 0, #pre-frag failures: 0, #fragments created: 0<br \/>\n#PMTUs sent: 0, #PMTUs rcvd: 0, #decapsulated frgs needing reassembly: 0<br \/>\n#TFC rcvd: 0, #TFC sent: 0<br \/>\n#Valid ICMP Errors rcvd: 0, #Invalid ICMP Errors rcvd: 0<br \/>\n#send errors: 0, #recv errors: 0<\/span><span style=\"font-size:x-small;\">local crypto endpt.: 10.50.2.10\/0, remote crypto endpt.: 10.50.2.18\/0<br \/>\npath mtu 1500, ipsec overhead 58(36), media mtu 1500<br \/>\nPMTU time remaining (sec): 0, DF policy: copy-df<br \/>\nICMP error validation: disabled, TFC packets: disabled<br \/>\ncurrent outbound spi: 19C913BD<br \/>\ncurrent inbound spi : B6018C1C<\/span><span style=\"font-size:x-small;\">inbound esp sas:<br \/>\nspi: 0xB6018C1C (3053554716)<br \/>\ntransform: esp-3des esp-md5-hmac no compression<br \/>\nin use settings ={L2L, Tunnel, IKEv1, }<br \/>\nslot: 0, conn_id: 540672, crypto-map: L2L-dynamic_IP<br \/>\nsa timing: remaining key lifetime (kB\/sec): (3912880\/10092)<br \/>\nIV size: 8 bytes<br \/>\nreplay detection support: Y<br \/>\nAnti replay bitmap:<br \/>\n0xFFFFFFFF 0xFFFFFFFF<br \/>\noutbound esp sas:<br \/>\nspi: 0x19C913BD (432608189)<br \/>\ntransform: esp-3des esp-md5-hmac no compression<br \/>\nin use settings ={L2L, Tunnel, IKEv1, }<br \/>\nslot: 0, conn_id: 540672, crypto-map: L2L-dynamic_IP<br \/>\nsa timing: remaining key lifetime (kB\/sec): (3912880\/10092)<br \/>\nIV size: 8 bytes<br \/>\nreplay detection support: Y<br \/>\nAnti replay bitmap:<br \/>\n0x00000000 0x00000001<\/span><\/td>\n<td><span style=\"font-size:x-small;\">interface: untrust<br \/>\nCrypto map tag: vpn, seq num: 50, local addr: 10.50.2.18<\/span><span style=\"font-size:x-small;\">access-list vpn-F16_to_F14 extended permit ip 192.168.106.0 255.255.255.128 192.168.104.0 255.255.255.0<br \/>\nlocal ident (addr\/mask\/prot\/port): (192.168.106.0\/255.255.255.128\/0\/0)<br \/>\nremote ident (addr\/mask\/prot\/port): (192.168.104.0\/255.255.255.0\/0\/0)<br \/>\ncurrent_peer: 10.50.2.10<\/span><span style=\"font-size:x-small;\">#pkts encaps: 36041, #pkts encrypt: 36041, #pkts digest: 36041<br \/>\n#pkts decaps: 36041, #pkts decrypt: 36041, #pkts verify: 36041<br \/>\n#pkts compressed: 0, #pkts decompressed: 0<br \/>\n#pkts not compressed: 36041, #pkts comp failed: 0, #pkts decomp failed: 0<br \/>\n#pre-frag successes: 0, #pre-frag failures: 0, #fragments created: 0<br \/>\n#PMTUs sent: 0, #PMTUs rcvd: 0, #decapsulated frgs needing reassembly: 0<br \/>\n#TFC rcvd: 0, #TFC sent: 0<br \/>\n#Valid ICMP Errors rcvd: 0, #Invalid ICMP Errors rcvd: 0<br \/>\n#send errors: 0, #recv errors: 0<\/span><span style=\"font-size:x-small;\">local crypto endpt.: 10.50.2.18\/0, remote crypto endpt.: 10.50.2.10\/0<br \/>\npath mtu 1500, ipsec overhead 58(36), media mtu 1500<br \/>\nPMTU time remaining (sec): 0, DF policy: copy-df<br \/>\nICMP error validation: disabled, TFC packets: disabled<br \/>\ncurrent outbound spi: B6018C1C<br \/>\ncurrent inbound spi : 19C913BD<\/span><span style=\"font-size:x-small;\">inbound esp sas:<br \/>\nspi: 0x19C913BD (432608189)<br \/>\ntransform: esp-3des esp-md5-hmac no compression<br \/>\nin use settings ={L2L, Tunnel, IKEv1, }<br \/>\nslot: 0, conn_id: 503808, crypto-map: vpn<br \/>\nsa timing: remaining key lifetime (kB\/sec): (4371888\/10156)<br \/>\nIV size: 8 bytes<br \/>\nreplay detection support: Y<br \/>\nAnti replay bitmap:<br \/>\n0xFFFFFFFF 0xFFFFFFFF<br \/>\noutbound esp sas:<br \/>\nspi: 0xB6018C1C (3053554716)<br \/>\ntransform: esp-3des esp-md5-hmac no compression<br \/>\nin use settings ={L2L, Tunnel, IKEv1, }<br \/>\nslot: 0, conn_id: 503808, crypto-map: vpn<br \/>\nsa timing: remaining key lifetime (kB\/sec): (4371888\/10156)<br \/>\nIV size: 8 bytes<br \/>\nreplay detection support: Y<br \/>\nAnti replay bitmap:<br \/>\n0x00000000 0x00000001<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-size:x-small;\">Crypto map tag: cisco_remote_vpn, seq num: 5, local addr: 10.50.2.10<\/span><br \/>\n<span style=\"font-size:x-small;\">local ident (addr\/mask\/prot\/port): (0.0.0.0\/0.0.0.0\/0\/0)<br \/>\nremote ident (addr\/mask\/prot\/port): (192.168.0.10\/255.255.255.255\/0\/0)<br \/>\ncurrent_peer: 192.168.109.10, username: netuser<br \/>\ndynamic allocated peer ip: 192.168.0.10<br \/>\ndynamic allocated peer ip(ipv6): 0.0.0.0<\/span><br \/>\n<span style=\"font-size:x-small;\">#pkts encaps: 25946, #pkts encrypt: 25946, #pkts digest: 25946<br \/>\n#pkts decaps: 25946, #pkts decrypt: 25946, #pkts verify: 25946<br \/>\n#pkts compressed: 0, #pkts decompressed: 0<br \/>\n#pkts not compressed: 25946, #pkts comp failed: 0, #pkts decomp failed: 0<br \/>\n#pre-frag successes: 0, #pre-frag failures: 0, #fragments created: 0<br \/>\n#PMTUs sent: 0, #PMTUs rcvd: 0, #decapsulated frgs needing reassembly: 0<br \/>\n#TFC rcvd: 0, #TFC sent: 0<br \/>\n#Valid ICMP Errors rcvd: 0, #Invalid ICMP Errors rcvd: 0<br \/>\n#send errors: 0, #recv errors: 0<\/span><br \/>\n<span style=\"font-size:x-small;\">local crypto endpt.: 10.50.2.10\/0, remote crypto endpt.: 192.168.109.10\/0<br \/>\npath mtu 1500, ipsec overhead 58(36), media mtu 1500<br \/>\nPMTU time remaining (sec): 0, DF policy: copy-df<br \/>\nICMP error validation: disabled, TFC packets: disabled<br \/>\ncurrent outbound spi: 8C8BE792<br \/>\ncurrent inbound spi : 64FABA97<\/span><br \/>\n<span style=\"font-size:x-small;\">inbound esp sas:<br \/>\nspi: 0x64FABA97 (1694153367)<br \/>\ntransform: esp-3des esp-md5-hmac no compression<br \/>\nin use settings ={RA, Tunnel, IKEv1, }<br \/>\nslot: 0, conn_id: 532480, crypto-map: cisco_remote_vpn<br \/>\nsa timing: remaining key lifetime (sec): 25858<br \/>\nIV size: 8 bytes<br \/>\nreplay detection support: Y<br \/>\nAnti replay bitmap:<br \/>\n0xFFFFFFFF 0xFFFFFFFF<br \/>\noutbound esp sas:<br \/>\nspi: 0x8C8BE792 (2357979026)<br \/>\ntransform: esp-3des esp-md5-hmac no compression<br \/>\nin use settings ={RA, Tunnel, IKEv1, }<br \/>\nslot: 0, conn_id: 532480, crypto-map: cisco_remote_vpn<br \/>\nsa timing: remaining key lifetime (sec): 25858<br \/>\nIV size: 8 bytes<br \/>\nreplay detection support: Y<br \/>\nAnti replay bitmap:<br \/>\n0x00000000 0x00000001<\/span><\/td>\n<td><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><!--more--><br \/>\nPing test:<br \/>\nThe ASA-F16 shows the 192.168.106.10 can ping to 192.168.104.10.<br \/>\nThe ASA-F14 shows the both L2L VPN and remote vpn can ping to 192.168.104.10.<\/p>\n<table border=\"1\">\n<tbody>\n<tr>\n<td><span style=\"font-size:x-small;\">net-AS5052-vASA-F16# sho conn | in ICMP<br \/>\nICMP untrust 192.168.104.10:0 trust\u00a0 192.168.106.10:512, idle 0:00:00, bytes 72736, flags<br \/>\nICMP untrust 192.168.104.10:512 trust\u00a0 192.168.106.10:0, idle 0:00:00, bytes 72896, flags<br \/>\n<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-size:x-small;\">net-vASA-AS5052-F14# sho conn | in ICMP<br \/>\nICMP untrust <span style=\"color:#008000;\">192.168.0.10<\/span>:768 trust\u00a0 192.168.104.10:0, idle 0:00:00, bytes 916384, flags<br \/>\nICMP untrust <span style=\"color:#008000;\">192.168.106.10<\/span>:512 trust\u00a0 192.168.104.10:0, idle 0:00:00, bytes 92672, flags<br \/>\n<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>From the lab above, it shows the ASA to run the IPSec VPN with dynamic IP address does not have any issue. Plus, it can co-operate with the Cisco vpn client.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Setting up a policy based site to site IPSec VPN tunnel with static IP address is quite stright forward in Cisco ASA, but what if one of the end point is using dymanic IP address? In this lab, I will be using 2 virtual ASA (9.6(2)) to create a site to site IPSec VPN tunnel, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2,3],"tags":[14,26,28,71,84,96,136,163,195,207],"class_list":["post-1371","post","type-post","status-publish","format-standard","hentry","category-networking","category-virtualization","tag-asa-en","tag-cisco-en","tag-cisco-vpn-client-en","tag-ikev1-en","tag-ipsec-en","tag-l2l-en","tag-remote-vpn-en","tag-site-to-site-en","tag-virtual-asa-en","tag-vpn-en"],"_links":{"self":[{"href":"http:\/\/notes4it.com\/index.php?rest_route=\/wp\/v2\/posts\/1371","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/notes4it.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/notes4it.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/notes4it.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/notes4it.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1371"}],"version-history":[{"count":0,"href":"http:\/\/notes4it.com\/index.php?rest_route=\/wp\/v2\/posts\/1371\/revisions"}],"wp:attachment":[{"href":"http:\/\/notes4it.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1371"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/notes4it.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1371"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/notes4it.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1371"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}