This is a post in a series of “stream-of-study” content where I post loosely-structured notes taken while labbing various scenarios and technologies. !———————————————-! ! Policy-based IKEv1 VPN between ASA and IOS ! !———————————————-! ! !in this setup we will stand up an IKEv1 based tunnel between an ASA and an IOS router based on interesting…… Continue reading Study Notes – Basic ASA to IOS IKEv1 Policy-Based VPN
Study Notes – Basic Active-Active ASA HA Pair Config
This is a post in a series of “stream-of-study” content where I post loosely-structured notes taken while labbing various scenarios and technologies. !——————————————! ! Basic Active-Active ASA HA Pair Config ! !——————————————! ! !we can take the concept of Active/Standby hardware HA as well as multiple contexts and create, effectively, multiple logical HA pairs where…… Continue reading Study Notes – Basic Active-Active ASA HA Pair Config
Study Notes – Basic Multi-Context ASA Setup
This is a post in a series of “stream-of-study” content where I post loosely-structured notes taken while labbing various scenarios and technologies. !——————————–! ! Basic Multi-Context ASA Setup ! !——————————–! ! !ASA Security contexts allow a firewall to be logically provisioned into multiple smaller firewalls, with interfaces physically allocated to each logical box. contexts can…… Continue reading Study Notes – Basic Multi-Context ASA Setup
Study Notes – ASA Active/Standby Failover With LAN and STATE Links
This is a post in a series of “stream-of-study” content where I post loosely-structured notes taken while labbing various scenarios and technologies. !————————————! ! ASA Active/Standby Failover With ! ! LAN and STATE Links ! !————————————! ! !in this setup there is no value in configuring the secondary ASA with anything other than minimum config…… Continue reading Study Notes – ASA Active/Standby Failover With LAN and STATE Links
Study Notes – Transparent ASA
This is a post in a series of “stream-of-study” content where I post loosely-structured notes taken while labbing various scenarios and technologies. Transparent ASA Notes Bump in the wire deployment, no need to change layer 3 topology to insert security control BPDUs and ARP are allowed by default IP traffic is enabled for inspection by…… Continue reading Study Notes – Transparent ASA
Study Notes – FlexVPN Spoke-to-Spoke (PSK Auth)
This is a post in a series of “stream-of-study” content where I post loosely-structured notes taken while labbing various scenarios and technologies. !—————————————-! ! FlexVPN PSK Spoke-to-Spoke (PSK Auth) ! !—————————————-! ! !To configure FlexVPN and allow dynamic Spoke to Spoke tunnels, we need to do a few things differently from the Hub and Spoke…… Continue reading Study Notes – FlexVPN Spoke-to-Spoke (PSK Auth)
Study Notes – FlexVPN Hub and Spoke with Negotiated Tunnels and PSK Auth
This is a post in a series of “stream-of-study” content where I post loosely-structured notes taken while labbing various scenarios and technologies. !————————————————! ! FlexVPN with Negotiated Tunnels and PSK Auth ! !————————————————! ! !building on sVTI/dVTI, FlexVPN allows for hub and spoke or dynamic spoke-to-spoke WAN mesh/partial mesh while also supporting the ability to…… Continue reading Study Notes – FlexVPN Hub and Spoke with Negotiated Tunnels and PSK Auth
Study Notes – IKEv2 sVTI/dVTI Point-to-Point VPN
This is a post in a series of “stream-of-study” content where I post loosely-structured notes taken while labbing various scenarios and technologies. !—————————! ! IKEv2 sVTI/dVTI P2P VPN ! !—————————! ! !In a typical sVTI or GREoIPSec point-to-point VPN tunnel, we generally know the external/initiating identity IP of each peer router, and we can configure…… Continue reading Study Notes – IKEv2 sVTI/dVTI Point-to-Point VPN
Study Notes – IKEv2 DMVPN with RSA-Sig Auth and fVRF
This is a post in a series of “stream-of-study” content where I post loosely-structured notes taken while labbing various scenarios and technologies. !————————————-! ! IKEv2 DMVPN with RSA-SIG and fVRF ! !————————————-! ! !—————————- ! R1 DMVPN Hub and CA !—————————- ! !start by creating the basic fvrf underlay and ivrf (default/global) interfaces ! int…… Continue reading Study Notes – IKEv2 DMVPN with RSA-Sig Auth and fVRF
Study Notes – Basic IKEv2 Route-Based VPN using sVTI on IOS
This is a post in a series of “stream-of-study” content where I post loosely-structured notes taken while labbing various scenarios and technologies. !——————————————–! ! IKEv2 Route-Based VPN using sVTI on IOS ! !——————————————–! ! !We configure this the same was as policy-based VPN, except instead of a crypto map we apply an IPSec profile, just…… Continue reading Study Notes – Basic IKEv2 Route-Based VPN using sVTI on IOS
