To configure a CloudBridge Connector tunnel on a Cisco ASA appliance, use the Cisco ASA command line interface, which is the primary user interface for configuring, monitoring, and maintaining Cisco ASA appliances.
Before you begin the CloudBridge Connector tunnel configuration on a Cisco ASA appliance, make sure that:
-
You have a user account with administrator credentials on the Cisco ASA appliance.
-
You are familiar with the Cisco ASA command line interface.
-
The Cisco ASA appliance is UP and running, is connected to the Internet, and is also connected to the private subnets whose traffic is to be protected over the CloudBridge Connector tunnel.
The procedures for configuring CloudBridge Connector tunnel on a Cisco ASA appliance might change over time, depending on the Cisco release cycle. Citrix® recommends that you follow the official Cisco ASA product documentation for Configuring IPSec VPN tunnels, at:
To configure a CloudBridge connector tunnel between a NetScaler appliance and a Cisco ASA appliance, perform the following tasks on the Cisco ASA appliance’s command line:
-
Create an IKE Policy. An IKE policy defines a combination of security parameters to be used during the IKE negotiation (phase 1). For example, parameters such as hash algorithm, encryption algorithm, and authentication method to be used in the IKE negotiation are set in this task.
-
Enable IKE on the outside interface. Enable IKE on the outside interface through which the tunnel traffic will flow to the tunnel peer.
-
Create a tunnel group. A tunnel group specifies the type of tunnel and the pre-shared key. The tunnel type must be set to ipsec-l2l, which stands for IPsec LAN to LAN. A pre-shared key is a text string, which the peers of a CloudBridge Connector tunnel use to mutually authenticate with each other. The pre-shared keys are matched against each other for IKE authentication. Therefore, for the authentication to be successful, you must configure the same pre-shared key on the Cisco ASA appliance and the NetScaler appliance.
-
Define a transform set. A transform set defines a combination of security parameters (phase 2) to be used in the exchange of data over the CloudBridge Connector tunnel after the IKE negotiation is successful.
-
Create an access List. Crypto access lists are used to define the subnets whose IP traffic will be protected over the CloudBridge tunnel. The source and destination parameters in the access list specify the Cisco appliance side and NetScaler side subnets that are to be protected over the CloudBridge Connector Tunnel. The access list must be set to permit. Any request packet that originates from an appliance in the Cisco appliance side subnet and is destined to an appliance in the NetScaler side subnet, and that matches the source and destination parameters of the access list, is sent across the CloudBridge Connector tunnel.
-
Create a crypto map. Crypto maps define the IPSec parameters for security associations (SAs). They include the following: Crypto access list to identify the subnets whose traffic is to be protected over the CloudBridge tunnel, peer (NetScaler) identification by IP address, and transform set to match the peer security settings.
-
Apply the crypto Map to the outside interface. In this task, you apply the crypto map to the outside interface through which the tunnel traffic will flow to the tunnel peer. Applying the crypto map to an interface instructs the Cisco ASA appliance to evaluate all interface traffic against the crypto map set and to use the specified policy during connection or security association negotiations.
The examples in the following procedures create settings of Cisco ASA appliance Cisco-ASA-Appliance-1 used in Example of CloudBridge Connector Configuration and Data Flow.
To create an IKE policy by using the Cisco ASA command line
At the Cisco ASA appliance’s command prompt, type the following commands, starting in global configuration mode, in the order shown:
| Command |
Example |
Command Description |
| crypto ikev1 policy priority |
Cisco-ASA-appliance-1(config)# crypto ikev1 policy 1 |
Enter IKE policy configuration mode and identify the policy to create. (Each policy is uniquely identified by the priority number you assign.) This example configures policy 1. |
| encryption (3des | aes) |
Cisco-ASA-appliance-1 (config-ikev1-policy)# encryption 3des |
Specify the encryption algorithm. This example configures the 3DES algorithm. |
| hash (sha | md5) |
Cisco-ASA-appliance-1 (config- ikev1-policy)# hash sha |
Specify the hash algorithm. This example configures SHA. |
| authenticationpre-share |
Cisco-ASA-appliance-1 (config- ikev1-policy)# authentication pre-share |
Specify the pre-share authentication method. |
| group 2 |
Cisco-ASA-appliance-1 (config- ikev1-policy)# group 2 |
Specify 1024-bit Diffie-Hellman group identifier (2). |
| lifetime seconds |
Cisco-ASA-appliance-1 (config- ikev1-policy)# lifetime 28800 |
Specify the security association's lifetime in seconds. This example configures 28800 seconds, which is the default value of lifetime in a NetScaler appliance. |
To enable IKE on the outside interface by using the Cisco ASA command line
At the Cisco ASA appliance’s command prompt, type the following commands, starting in global configuration mode, in the order shown:
| Command |
Example |
Command Description |
| crypto ikev1 enable outside |
Cisco-ASA-appliance-1(config)# crypto ikev1 enable outside |
Enable IKEv1 on the interface through which the tunnel traffic flows to the tunnel peer. This example enables IKEv1 on the interface named outside. |
To create a tunnel group by using the Cisco ASA command line
To create a crypto access list by using the Cisco ASA command line
At the Cisco ASA appliance’s command prompt, type the following command in global configuration mode, in the order shown:
| Command |
Example |
Command Description |
| access-list access-list-number permit IP source source-wildcard destination destination-wildcard |
Cisco-ASA-appliance-1(config)# access-list 111 permit ip 10.20.20.0 0.0.0.255 10.102.147.0 0.0.0.255 |
Specify conditions to determine the subnets whose IP traffic is to be protected over the CloudBridge Connector tunnel. This example configures access list 111 to protect traffic from subnets 10.20.20.0/24 (at the Cisco-ASA-Appliance-1 side) and 10.102.147.0/24 (at the NS_Appliance-1 side). |
To define a transform set by using the Cisco ASA command line
To create a crypto map by using the Cisco ASA command line
At the Cisco ASA appliance’s command prompt, type the following commands starting in global configuration mode, in the order shown:
| Command |
Example |
Command Description |
| crypto map map-name seq-num match address access-list-name |
Cisco-ASA-appliance-1 (config)# crypto map NS-CISCO-CM 1 match address 111 |
Create a crypto map and specify an access list to it. This example configures crypto map NS-CISCO-CM with sequence number 1 and assigns access list 111 to NS-CISCO-CM. |
| crypto map map-name seq-num set peer ip-address |
Cisco-ASA-appliance-1 (config)# crypto map NS-CISCO-CM 1 set peer 198.51.100.100 |
Specify the peer (NetScaler appliance) by its IP address. This example specifies 198.51.100.100, which is the tunnel endpoint IP address on the NetScaler appliance. |
| crypto map map-name seq-num set ikev1 transform-set transform-set-name |
Cisco-ASA-appliance-1 (config)# crypto map NS-CISCO-CM 1 set ikev1 transform-set NS-CISCO-TS |
Specify which transform set is allowed for this crypto map entry. This example specifies transform set NS-CISCO-TS. |
To apply a crypto map to an interface by using the Cisco ASA command line
At the Cisco ASA appliance’s command prompt, type the following commands starting in global configuration mode, in the order shown:
| Command |
Example |
Command Description |
| crypto map map-nameinterface interface-name |
Cisco-ASA-appliance-1(config)# crypto map NS-CISCO-CM interface outside |
Apply the crypto map to the interface through which CloudBridge Connector tunnel traffic will flow. This example applies crypto map NS-CISCO-CM to interface outside. |