mikrotik to cisco asa ipsec vpn - vion technology blog

Upload: tithleang

Post on 08-Aug-2018

261 views

Category:

Documents


0 download

TRANSCRIPT

  • 8/22/2019 Mikrotik to Cisco ASA IPsec VPN - VION Technology Blog

    1/6

    Search this site...

    269 days ago by Nikola Stojanoski 4

    HOME NETWORKING MIKROTIK TO CISCO ASA IPSEC VPN

    Mikrotik to Cisco ASA IPsec VPN

    We needed to setup IPsec VPN for a client with a remote location that already had Cisco ASA. So, here is a Mikrotik to

    Cisco ASA IPsec howto.

    Tutorial Scenario

    Cisco ASA site

    WAN: 1.1.1.2/30 (outside)

    LAN: 192.168.2.1/24 (inside)

    Mikrotik site

    WAN: 1.1.1.1/30 (ether1)

    LAN: 192.168.1.1/24 (ether2)

    Cisco ASA to Mikrotik configuration

    Launch the VPN configuration wizard on your Cisco ASA router

    Set VPN Tunnel Type as Site-to-Site

    Set the Remote Peer IP Address: 1.1.1.1(Mikrotik WAN) and Pre-shared key. Also Tunnel Group Name should be

    the Remote Peer IP Address.

    Yo uTu be Tw it te r F ac eb oo k R SS E mai l

    Popular Posts

    openerp-server.conf for OpenERP 7 explained

    Install OpenERP 7.0 from trunk

    Meridian Option 11 Programming Manual

    skip-name-resolve to speed up MySQL and avoid

    problems

    Site-to-Site IPSec VPN using Mikrotik Routers

    VirtualBox 4.2 and phpVirtualBox on Debian

    Mikrotik to Cisco ASA IPsec VPN

    Oracle Instant Client and PHP OCI8 on Debian

    Squeeze

    OpenERP 7.0 compared to OpenERP 6.1

    Zimbra ActiveSync with Z-Push v2

    VION Technology Blog

    Like

    85 people like VION Technology Blog.

    Facebook social plugin

    HOME ABOUT CON TACT DOWNLOADS PRIVACY

    Blogging Database Development General Networking Telephony

    otik to Cisco ASA IPsec VPN - VION Technology Blog http://www.vionblog.com/mikrotik-to-cisco-asa-i

    6/27/2013

  • 8/22/2019 Mikrotik to Cisco ASA IPsec VPN - VION Technology Blog

    2/6

    Set the IKE Policy Encryption to 3DES, Authentication to MD5 and DH Group to 2

    Set the IPsec Encryption to 3DES and Authentication to MD5

    Tags

    ApacheAria SOHO ASA Blogging chat Cisco

    Debian DHCP Door Phone firewall Full-Text SearchHunt Group IM iPECS iPECS-LIKiPECS-MG ipLDK IPSecLG-Ericsson memcached MeridianMikrotik Mobile MySQL nginx Nortel NTP

    OpenERP Option 11 PBX PC Admin PHPpidgin PostgreSQL Reverse Proxy SIP skip-name-resolve

    Skype SSL VirtualBox VoiceMail VoIP VPN WebmasterZimbra

    otik to Cisco ASA IPsec VPN - VION Technology Blog http://www.vionblog.com/mikrotik-to-cisco-asa-i

    6/27/2013

  • 8/22/2019 Mikrotik to Cisco ASA IPsec VPN - VION Technology Blog

    3/6

    Set the Local and Remote Networks

    Dont forget to set the IKE Parameters to Identity: Address to avoid connection problems

    otik to Cisco ASA IPsec VPN - VION Technology Blog http://www.vionblog.com/mikrotik-to-cisco-asa-i

    6/27/2013

  • 8/22/2019 Mikrotik to Cisco ASA IPsec VPN - VION Technology Blog

    4/6

    Mikrotik to Cisco ASA configuration

    Create new policy

    Create new Peer

    Modify the default proposal to accept MD5 as Authentication

    otik to Cisco ASA IPsec VPN - VION Technology Blog http://www.vionblog.com/mikrotik-to-cisco-asa-i

    6/27/2013

  • 8/22/2019 Mikrotik to Cisco ASA IPsec VPN - VION Technology Blog

    5/6

    Tags: ASA, Cisco, IPSec, Mikrotik, VPN

    Setting Mikrotik as IPSec

    Concentrator

    My Mikrotik Initial Setup Site-to-Site IPSec VPN

    using Mikrotik Routers

    December 18, 2012 at 11:34 am

    Create NAT rule to bypass the traffic that should to trough the tunnel

    Move the rule to the top

    Now you can connect your branch offices using Mikrotik Routers even if you have Cisco ASAs installed on the other

    locations.

    Links: Cisco ASA, Mikrotik Routerboard

    Nikola Stojanoski

    System Administrator and Developer. Giving back to the community by blogging about my problems,

    solutions and practical howto's.

    Related Articles

    4 Responses to Mikrotik to Cisco ASA IPsec VPN

    Damjan Momirovski

    Mnogu dobar blog , povekje od korisen :) , bravo za Mrki.

    ReplyReply

    otik to Cisco ASA IPsec VPN - VION Technology Blog http://www.vionblog.com/mikrotik-to-cisco-asa-i

    6/27/2013

  • 8/22/2019 Mikrotik to Cisco ASA IPsec VPN - VION Technology Blog

    6/6

    February 8, 2013 at 2:29 pm

    April 2, 2013 at 1:19 pm

    April 10, 2013 at 12:26 pm

    patriotmk

    , , :)

    Horst Bursik

    You saved my day thank you! :)

    ConfigurationsMikrotik

    Good post

    Leave a Reply

    Name (Required)

    Mail (will not be published) (Required)

    Website

    7 1 =

    2013 VION Technology Blog. All rights reserved. Bloggers.com

    ReplyReply

    ReplyReply

    ReplyReply

    otik to Cisco ASA IPsec VPN - VION Technology Blog http://www.vionblog.com/mikrotik-to-cisco-asa-i