Study Notes – IKEv1 Tunnel Through an ASA with NAT-Traversal

This is a post in a series of “stream-of-study” content where I post loosely-structured notes taken while labbing various scenarios and technologies. !—————————! ! IKEv1 tunnel Through ! ! an ASA with NAT-T ! !—————————! ! !here we will configure a basic GREoIPSec tunnel between two routers through an ASA, but one of the routers…… Continue reading Study Notes – IKEv1 Tunnel Through an ASA with NAT-Traversal

Study Notes – IOS-to-IOS VPN Through an ASA

This is a post in a series of “stream-of-study” content where I post loosely-structured notes taken while labbing various scenarios and technologies. !———————————! ! IOS Router VPN through an ASA ! !———————————! ! !in this setup we will configure an IOS to IOS VPN which must pass THROUGH an ASA without NAT, where we need…… Continue reading Study Notes – IOS-to-IOS VPN Through an ASA

Study Notes – ASA to IOS IKEv2 Policy-based VPN with Manual NAT Exemption

This is a post in a series of “stream-of-study” content where I post loosely-structured notes taken while labbing various scenarios and technologies. !———————————————-! ! Policy-based IKEv2 VPN between ASA and IOS ! ! With Manual NAT Exemption ! !———————————————-! ! !in this setup we will stand up an IKEv2 based tunnel between an ASA and…… Continue reading Study Notes – ASA to IOS IKEv2 Policy-based VPN with Manual NAT Exemption

Study Notes – ASA to IOS Policy-Based IKEv1 VPN with Manual NAT Exemption

This is a post in a series of “stream-of-study” content where I post loosely-structured notes taken while labbing various scenarios and technologies. !———————————————-! ! Policy-based IKEv1 VPN between ASA and IOS ! ! With Manual NAT Exemption ! !———————————————-! ! !in this setup we will stand up an IKEv1 based tunnel between an ASA and…… Continue reading Study Notes – ASA to IOS Policy-Based IKEv1 VPN with Manual NAT Exemption

Study Notes – Basic ASA to IOS IKEv1 Policy-Based VPN

This is a post in a series of “stream-of-study” content where I post loosely-structured notes taken while labbing various scenarios and technologies. !———————————————-! ! Policy-based IKEv1 VPN between ASA and IOS ! !———————————————-! ! !in this setup we will stand up an IKEv1 based tunnel between an ASA and an IOS router based on interesting…… Continue reading Study Notes – Basic ASA to IOS IKEv1 Policy-Based VPN

Study Notes – Basic Active-Active ASA HA Pair Config

This is a post in a series of “stream-of-study” content where I post loosely-structured notes taken while labbing various scenarios and technologies. !——————————————! ! Basic Active-Active ASA HA Pair Config ! !——————————————! ! !we can take the concept of Active/Standby hardware HA as well as multiple contexts and create, effectively, multiple logical HA pairs where…… Continue reading Study Notes – Basic Active-Active ASA HA Pair Config

Study Notes – Basic Multi-Context ASA Setup

This is a post in a series of “stream-of-study” content where I post loosely-structured notes taken while labbing various scenarios and technologies. !——————————–! ! Basic Multi-Context ASA Setup ! !——————————–! ! !ASA Security contexts allow a firewall to be logically provisioned into multiple smaller firewalls, with interfaces physically allocated to each logical box. contexts can…… Continue reading Study Notes – Basic Multi-Context ASA Setup

Study Notes – ASA Active/Standby Failover With LAN and STATE Links

This is a post in a series of “stream-of-study” content where I post loosely-structured notes taken while labbing various scenarios and technologies. !————————————! ! ASA Active/Standby Failover With ! ! LAN and STATE Links ! !————————————! ! !in this setup there is no value in configuring the secondary ASA with anything other than minimum config…… Continue reading Study Notes – ASA Active/Standby Failover With LAN and STATE Links

Study Notes – Transparent ASA

This is a post in a series of “stream-of-study” content where I post loosely-structured notes taken while labbing various scenarios and technologies. Transparent ASA Notes Bump in the wire deployment, no need to change layer 3 topology to insert security control BPDUs and ARP are allowed by default IP traffic is enabled for inspection by…… Continue reading Study Notes – Transparent ASA