Configuring Cisco ASA IKEv2 Site-to-Site VPN

  Рет қаралды 15,957

Network Wizkid

Network Wizkid

2 жыл бұрын

SUBSCRIBE - LIKE - HIT THE NOTIFICATIONS BELL
CCIE Security Links:
All CCNP/CCIE Security books to help you get certified: www.amazon.co.uk/shop/networkwiizkiid
CCNP and CCIE Security Core SCOR 350-701 Official Cert Guide - amzn.to/2yF4GWU
Integrated Security Technologies and Solutions - Volume I: Cisco Security Solutions for Advanced Threat Protection with Next-Generation Firewall, ... Security (CCIE Professional Development) amzn.to/3awraa7
CCIE/CCNP Security SNCF 300-710: Todd Lammle Authorized amzn.to/3cJDLZ3
Useful links:
Fund me: t.co/Iva1Y3IchF
Website: www.networkwizkid.com
Twitter: iwiizkiid
Instagram: iwiizkiid

Пікірлер: 50
@edinetwork
@edinetwork 2 жыл бұрын
Been waiting for this. Thank you so much brother. Your NAT on ASA video helped me configure nat on the job and also helped me understand all the types of nat (Nat exemption for vpns, static nat & pat, dynamic nat & pat and how to configure them using auto or manual). I really appreciate it 🙌🏽 from Africa The Gambia🇬🇲
@NetworkWizkid
@NetworkWizkid 2 жыл бұрын
Hey Edi, thank you, I'm glad that my videos have helped you. Thank you for showing your support.
@julioalvarado6516
@julioalvarado6516 Жыл бұрын
Good job, your are the first with detailed explanation and steps
@NetworkWizkid
@NetworkWizkid Жыл бұрын
Thank you and thank you for watching, I'm glad that it helped
@thanhphunguyen2320
@thanhphunguyen2320 2 жыл бұрын
Love it! Very helpful! Thank you very much!
@NetworkWizkid
@NetworkWizkid 2 жыл бұрын
No problem, thank you for watching!
@douglasf775
@douglasf775 10 ай бұрын
Totally useful and working great! thanks for this
@NetworkWizkid
@NetworkWizkid 10 ай бұрын
No problem, thank you for watching.
@enriquemolinab3080
@enriquemolinab3080 Жыл бұрын
Thanks boy for your brilliant explanation 👏👏👏👏👏👏👏👏👏👏👏👏👏👏
@NetworkWizkid
@NetworkWizkid Жыл бұрын
No problem, glad it helped.
@1manairband
@1manairband Жыл бұрын
Done very well, thank you for this. It answers some of my questions.
@NetworkWizkid
@NetworkWizkid Жыл бұрын
Glad it helped, thank you for watching!
@1manairband
@1manairband Жыл бұрын
@@NetworkWizkid One question for you, if you have multiple ikev2 policies (lets say 10 with different parms) will tunnels choose the best that fits the requirements of the other end during negotiation phase 1 negotiation?
@NetworkWizkid
@NetworkWizkid Жыл бұрын
@@1manairband I believe the selection works on the priority of the IKEv2 policy. This is done when you configure the IKEv2 policy and specify the priority number, for example: crypto ikev2 policy 10 - The number 10 is the priority in this case (the lower the number, the higher the priority). I hope that helps (11:30 in the video)
@1manairband
@1manairband Жыл бұрын
@@NetworkWizkid I did catch that in your video but I was just curious if it worked from top down or bottom up. If priority 1 policy didn't match then would it match priority 2 if that was a better match based on settings?
@NetworkWizkid
@NetworkWizkid Жыл бұрын
Yes, I mean it would all depend on the policy used on the other side...if the stars align and we have x2 exact same policies but one has a higher priority then the higher one will be selected.
@KenPaula
@KenPaula 2 жыл бұрын
This is very informative and useful. How’s that Master going?
@NetworkWizkid
@NetworkWizkid 2 жыл бұрын
Thank you Kenny! It's going well, I finish soon and then I'm thinking about going on to do a PhD.
@frankspranze
@frankspranze 2 жыл бұрын
Very informative, can you post a policy based configuration? Thank you!
@NetworkWizkid
@NetworkWizkid 2 жыл бұрын
Thank you Frank. You can view the configuration on my website: networkwizkid.com/2021/09/15/video-configuring-cisco-asa-ikev2-site-to-site-vpns/ Hope that helps and thank you for watching.
@shrenikshah7552
@shrenikshah7552 2 жыл бұрын
Awesome explanation, Thanks for the video. can you help me with show command for ASA 5506 AND 5505, how to verify IKE details phase-1 and IPSec phase-2 details? how do I see the parameters like Authentication, IKE version, Encryption and Hash algorithm and DH group, lifetime for phase 1 and IPSec protocol mode, authentication, Encryption, lifetime and PFS for phase 2? appreciate your quick reply.
@NetworkWizkid
@NetworkWizkid 2 жыл бұрын
Thank you for watching. Please subscribe if you've found the content useful. The commands that you might be looking for are: show crypto ikev2 sa (if using IKEv2) show crypto ipsecsa show crypto isakmp sa
@ronniewatson322
@ronniewatson322 2 жыл бұрын
This gave me problems when deployment of Cisco SDWAN mixed with ASA 5506. I remember on Twitter we had conversations about my VPN problems lol 😆
@NetworkWizkid
@NetworkWizkid 2 жыл бұрын
Did you resolve it in the end? I've recently been apart of some work where VPN's haven't been working how we'd expect them to on the ASA too :-/
@ronniewatson322
@ronniewatson322 2 жыл бұрын
@@NetworkWizkid I did resolve it by reapplying the encryption key for both nodes that were main FW and branch FW. It was just a bandaid until my MX84 and MX67 Firewall deployment was done.
@NetworkWizkid
@NetworkWizkid 2 жыл бұрын
At least you got it working bro! I plan on doing more videos with different technologies forming VPNs too in the future.
@ronniewatson322
@ronniewatson322 2 жыл бұрын
@@NetworkWizkid That would be great 👍 keep it up. I like videos like this!
@NetworkWizkid
@NetworkWizkid 2 жыл бұрын
Thank you for the support brother!
@dantewhite7206
@dantewhite7206 Жыл бұрын
Hello Wizkid! I am new to your channel and enjoy your content. I recently earn my CCNA and am interested in studying for my CCNP Security exam. Can you tell me the software you use in your demonstrations? Any advice is appreciated!
@NetworkWizkid
@NetworkWizkid Жыл бұрын
Congratulations and I'm glad to hear that you want to study for the CCNP Security. In this video, I am using EVE-NG; I hope that helps.
@dantewhite7206
@dantewhite7206 Жыл бұрын
@@NetworkWizkid I believe I need Cisco images to create the lab but I am not sure where I can them. Do you know where I can find the needed images your EVE-NG? Do I have to purchase a license?
@NetworkWizkid
@NetworkWizkid Жыл бұрын
You can find some of them online by searching. Others you may need to have a Cisco account in order to download the software that you need. Most can run off evaluations.
@dl2651
@dl2651 11 ай бұрын
Trying to configure the SITE-TO-SITE for days now. Can i use ip address dhcp setroute on the outside interface Eth 0/0 ? My router is in bridge mode and i connect directly to my ASA5505. Thanks !
@NetworkWizkid
@NetworkWizkid 11 ай бұрын
I think it should work. Maybe check the IKEv2 Site-to-Site VPN documentation for further clarity or check out the following link that might help: community.cisco.com/t5/routing/configure-site-to-site-vpn-with-dynamic-ip-on-one-side/td-p/3846935
@veerabsc
@veerabsc 2 жыл бұрын
I have tried this lab today, works perfectly. Do you have lab for ASA VTI?
@NetworkWizkid
@NetworkWizkid 2 жыл бұрын
Glad it worked for you and thank you for watching. I haven't yet but I have made a note and will try and produce some content around this. If you've subscribed, you'll be notified of any new videos that I upload.
@veerabsc
@veerabsc 2 жыл бұрын
@@NetworkWizkid Bro I’m gonna subscribe for you. Your videos very helpful 👍
@veerabsc
@veerabsc 2 жыл бұрын
I have a stand-alone FTD running on my environment, how can I add another FTD from the inside network to FMC?
@NetworkWizkid
@NetworkWizkid 2 жыл бұрын
Hey, check out this video: kzbin.info/www/bejne/rJDYi2x9l652eM0
@winniealexander7566
@winniealexander7566 Жыл бұрын
Why not have ISP and NAT?
@NetworkWizkid
@NetworkWizkid Жыл бұрын
Lets take the following scenario as an example: You managed two sites; the corporate office and a smaller branch site. You have been asked to come up with a way to allow access to a corporate office FTP server from the branch site. Now, NAT could be a possibility by simply creating a static NAT policy but at the same time branch traffic to the FTP server is exposed (a good reference here: digitalguardian.com/blog/what-ftp-security-securing-ftp-usage#:~:text=FTP%20was%20not%20built%20to,among%20other%20basic%20attack%20methods.) This is just one example of why a site-to-site VPN would be the better option as it would address confidentiality, integrity and availability concerns. I hope that helps.
@veerapandiyanrengasamy8919
@veerapandiyanrengasamy8919 Жыл бұрын
Hello Kevin, thanks for the videos, i have issue with my ASA S2S, tunnel is up, one side ASA(SITE-A)encap is packet but not decap the packet, I have checked other side ASA(SITE-B) encaps and decaps(more decaps than encaps) happening here, and also default route pointing towards ISP. But why cant i ping SITE-A to SITE-B vice versa?
@NetworkWizkid
@NetworkWizkid Жыл бұрын
Hey, thank you for watching and reaching out. Have you double-checked your ACL's for your interesting traffic? It may be worth posting your configuration into our Discord community so that we can take a look. Here is the link: discord.gg/au9a8DnsQh
@TheNatedoggva
@TheNatedoggva 9 ай бұрын
What is the VPC4? A virtual machine? Can't duplicate this example without that
@NetworkWizkid
@NetworkWizkid 9 ай бұрын
A virtual machine in EVE-NG. You can replace it with a PC or other networking device.
@TheNatedoggva
@TheNatedoggva 9 ай бұрын
@@NetworkWizkid The lab at my job has a switch in place of the vm or PC. Can this configuration still work? I tried it and failed. Please help
@NetworkWizkid
@NetworkWizkid 9 ай бұрын
If you configured the switch as a L3 device, then so long as routing is in place you should be able to get it to work.
@TheNatedoggva
@TheNatedoggva 9 ай бұрын
@@NetworkWizkid Both 9200 L's are not configured as L3. The error I'm getting when trying to see the routes are "gateway of last resort is not set"
@NetworkWizkid
@NetworkWizkid 9 ай бұрын
That's why you are getting the message you are seeing. The switch needs to be able to route the traffic to the destination. Maybe the easier option would be to place a device behind the switch to route to the default gateway and then configure the interesting traffic on the router.
Configuring a CIsco ISE Distributed Deployment
1:17:00
Network Wizkid
Рет қаралды 6 М.
1❤️#thankyou #shorts
00:21
あみか部
Рет қаралды 88 МЛН
🌊Насколько Глубокий Океан ? #shorts
00:42
Please be kind🙏
00:34
ISSEI / いっせい
Рет қаралды 120 МЛН
Tom & Jerry !! 😂😂
00:59
Tibo InShape
Рет қаралды 42 МЛН
Site To Site VPN with VTIs on Cisco ASA (Route Based)
18:51
Implementing and Troubleshooting Site-to-Site VPN
1:23:11
INEtraining
Рет қаралды 68 М.
Site to Site VPNs for CCNAs
19:31
StormWind Studios
Рет қаралды 192 М.
Настройка FlexVPN / IKEv2(cisco)
27:32
Techno Azimut
Рет қаралды 1,3 М.
How to Configure Site-2-Site IPSec VPN Between CISCO ASA Firewall
19:49
How To Configure IPSEC SITE TO SITE VPN using IKEV2
46:04
How To
Рет қаралды 6 М.
Configuring Network Address Translation (NAT) | Cisco ASA Firewalls
23:55
Network Direction
Рет қаралды 38 М.
Мечта Каждого Геймера
0:59
ЖЕЛЕЗНЫЙ КОРОЛЬ
Рет қаралды 1,6 МЛН
Iphone or nokia
0:15
rishton vines😇
Рет қаралды 1,8 МЛН
сюрприз
1:00
Capex0
Рет қаралды 1,6 МЛН
Хотела заскамить на Айфон!😱📱(@gertieinar)
0:21
Взрывная История
Рет қаралды 3,3 МЛН