Cisco Router 892 IPSec Initiator?

Answered Question
Sep 5th, 2016
User Badges:

Hello everyone!

I have IPSec tunnel between Cisco Router 892 (c890-universalk9-mz.154-3.M4.bin) and Cisco PIX 515E (ver. 8.0(4)28) with 5 subnets behind PIX.

PIX configured to process bi-directional connection-type, but Router not support it =(

So, when I generate intresting traffic from hosts behind the Router IPSec is not working. When I generate traffic from hosts behind PIX everything works, but I need to be initiator from Router side :-(

Is there way to make my Cisco router 892 initiator of IPSec tunnel to work with Cisco PIX/ASA?

I afraid I should replace Router to another device =((


Thank you!

Correct Answer by JP Miranda Z about 7 months 3 weeks ago

Hi Yura Kazakevich,


Try enabling pfs on the Router:


crypto map SDM_CMAP_1 1 ipsec-isakmp

set pfs

Hope this info helps!!


Rate if helps you!! 


-JP-

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (2 ratings)
Loading.
JP Miranda Z Mon, 09/05/2016 - 19:59
User Badges:
  • Cisco Employee,

Hi Yura Kazakevich,


You are right, you can't configure the connection-type on a Router but this one uses bi-directional by default, in this case you need to find out what is not letting the tunnel to come up when initiating from the Router, i would recommend you to take captures on the outside interface of the PIX when trying to initiate the tunnel from the Router and also run debugs from the Router as initiator.

Some commands that you can use:

Router debugs:

debug cry condition peer ipv4 <peerip>

debug cry isa


ASA capture:

capture test interface outside match ip host <publicipPIX> host <publicipRouter>

capture drop type asp-drop all circular-buffer


To check the captures you can run this commands:

sh cap test 

sh cap drop | in <PIXpublicip>


Hope this info helps!!


Rate if helps you!! 


-JP-

Yura Kazakevich Tue, 09/06/2016 - 10:53
User Badges:

Thank you for you answer, Jose!

When I trying to generate traffic from Router side I see the following errors in ASDM:
Group = 10.1.36.126, Username = 10.1.36.126, IP = 10.1.36.126, Session disconnected. Session Type: IKE, Duration: 0h:00m:00s, Bytes xmt: 0, Bytes rcv: 0, Reason: Phase 2 Mismatch
Group = 10.1.36.126, IP = 10.1.36.126, Removing peer from correlator table failed, no match!
Group = 10.1.36.126, IP = 10.1.36.126, QM FSM error (P2 struct &0x2fe6488, mess id 0x866d8b0d)!
Group = 10.1.36.126, IP = 10.1.36.126, Freeing previously allocated memory for authorization-dn-attributes

10.1.36.126 - Router
10.1.11.30 - PIX
(It's corpatate link throung ISP).

As soon I send ping behind PIX side toward Router side - IPSec UPs immidiatly. This is strange!

Here is attachment with captures and PIX Config. I ready to pay for resolve the issue.

"capture drop type asp-drop all circular-buffer" has no records related with my peers (neither 10.1.11.30 or 10.1.36.126).

Here is UDP500 port check (on PIX) from the server behind Router:

$nmap -sU -p 500 10.1.11.30
Starting Nmap 5.51 ( http://nmap.org ) at 2016-09-06 20:51 AST
Nmap scan report for 10.1.11.30
Host is up (0.015s latency).
PORT    STATE SERVICE
500/udp open  isakmp


I've forgot to tell I have another IPSec (defferent peer and intresting traffic) between the Router and Mikrotik (another brounch). Here is not such problems!
When I disconnect IPSec from both sides and generate traffic behind the Router everything works. The same when I generate traffic behind Mikrotik.

Why Cisco Router => Cisco PIX is so odd?... =|

Attachment: 
JP Miranda Z Tue, 09/06/2016 - 11:05
User Badges:
  • Cisco Employee,

Yura Kazakevich,


Can you share the tunnel configuration on the Router?


Hope this info helps!!


Rate if helps you!! 


-JP-

Yura Kazakevich Tue, 09/06/2016 - 11:51
User Badges:

Here is:

crypto isakmp policy 1
 encr 3des
 authentication pre-share
 group 2

!
crypto isakmp policy 2
 encr 3des
 authentication pre-share
 group 2
 lifetime 28800

crypto isakmp key **** address 10.1.11.30

crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
 mode tunnel
crypto ipsec transform-set ESP-3DES-SHA1 esp-3des esp-sha-hmac
 mode tunnel
crypto ipsec transform-set ESP-3DES-SHA2 esp-3des esp-sha-hmac
 mode tunnel
crypto ipsec df-bit clear

crypto map SDM_CMAP_1 1 ipsec-isakmp
 description Tunnel to_BS_BFT
 set peer 10.1.11.30
 set security-association lifetime seconds 28800
 set transform-set ESP-3DES-SHA1
 match address 100

Intresting traffic:

access-list 100 permit ip 192.168.3.0 0.0.0.255 192.168.111.0 0.0.0.255
access-list 100 permit ip 192.168.3.0 0.0.0.255 172.16.61.0 0.0.0.255
access-list 100 permit ip 192.168.3.0 0.0.0.255 172.16.192.0 0.0.0.255
access-list 100 permit ip 192.168.3.0 0.0.0.255 172.16.154.0 0.0.0.255
access-list 100 permit ip 192.168.3.0 0.0.0.255 172.16.10.0 0.0.0.255
access-list 100 permit ip 192.168.3.0 0.0.0.255 172.17.19.0 0.0.0.255
access-list 100 permit ip 192.168.4.0 0.0.0.255 192.168.111.0 0.0.0.255

Nat0:
access-list 101 deny   ip 192.168.3.0 0.0.0.255 192.168.111.0 0.0.0.255
access-list 101 deny   ip 192.168.3.0 0.0.0.255 172.16.192.0 0.0.0.255
access-list 101 deny   ip 192.168.3.0 0.0.0.255 172.16.177.0 0.0.0.255
access-list 101 deny   ip 192.168.3.0 0.0.0.255 172.16.61.0 0.0.0.255
access-list 101 deny   ip 192.168.3.0 0.0.0.255 172.17.19.0 0.0.0.255
access-list 101 deny   ip 192.168.4.0 0.0.0.255 192.168.111.0 0.0.0.255
access-list 101 deny   ip 192.168.3.0 0.0.0.255 host 172.16.194.100
access-list 101 deny   ip 192.168.3.0 0.0.0.255 10.0.0.0 0.255.255.255
access-list 101 deny   ip 192.168.4.0 0.0.0.255 10.0.0.0 0.255.255.255
access-list 101 deny   ip host 192.168.4.1 host 212.98.173.36
access-list 101 deny   ip host 192.168.4.1 host 212.98.162.139
access-list 101 deny   ip 192.168.4.0 0.0.0.255 host 172.31.255.1
access-list 101 deny   ip 192.168.4.0 0.0.0.255 host 172.16.194.100
access-list 101 deny   ip host 192.168.4.2 host 172.30.69.173
access-list 101 permit ip 192.168.3.0 0.0.0.255 any
access-list 101 permit ip 192.168.4.0 0.0.0.255 any

route-map SDM_RMAP_TO_BFT permit 10
 match ip address 102
 match interface FastEthernet8

ip nat inside source route-map SDM_RMAP_TO_BFT interface FastEthernet8 overload


Hope it will help)


JP Miranda Z Tue, 09/06/2016 - 12:13
User Badges:
  • Cisco Employee,

Hi Yura Kazakevich,


After checking the config i can definitely see a phase2 mismatch on the interesting traffic, do the ACL 100 should be mirrored on the bft_5_cryptomap ACL and is not, make sure the interesting traffic is mirrored and test again.


Hope this info helps!!


Rate if helps you!! 


-JP-

Yura Kazakevich Tue, 09/06/2016 - 12:56
User Badges:

I did so. I even removed all ACL entries exampt one, but without luck.

So I made it again as you advised. Now all entries are mirrored and in the same sequence.

ROUTER:

c892-datacenter#sho access-lists 100
Extended IP access list 100
    10 permit ip 192.168.3.0 0.0.0.255 192.168.111.0 0.0.0.255 (6357807 matches)
    20 permit ip 192.168.3.0 0.0.0.255 172.16.61.0 0.0.0.255 (74726 matches)
    30 permit ip 192.168.3.0 0.0.0.255 172.16.192.0 0.0.0.255 (30 matches)
    40 permit ip 192.168.3.0 0.0.0.255 172.16.154.0 0.0.0.255
    60 permit ip 192.168.3.0 0.0.0.255 172.16.10.0 0.0.0.255
    70 permit ip 192.168.3.0 0.0.0.255 172.17.19.0 0.0.0.255
    80 permit ip 192.168.4.0 0.0.0.255 192.168.111.0 0.0.0.255 (5894255 matches)

PIX:

PIX Crypto traffic

I even rised Priority of bft_5_cryptomap to the highest as you can see in sceenshot above. No Luck(


Then for testing I've modified intresting traffic to the following:

ROUTER:

c892-datacenter#sho access-lists 100
Extended IP access list 100
    10 permit ip 192.168.3.0 0.0.0.255 192.168.111.0 0.0.0.255
c892-datacenter#

PIX:

PIX

Logs on PIX still shows:

Group = 10.1.36.126, IP = 10.1.36.126, Removing peer from correlator table failed, no match!
Group = 10.1.36.126, IP = 10.1.36.126, QM FSM error (P2 struct &0x4127e78, mess id 0x7910dbd9)!


Awesome!((( Its bug.

Correct Answer
JP Miranda Z Tue, 09/06/2016 - 13:11
User Badges:
  • Cisco Employee,

Hi Yura Kazakevich,


Try enabling pfs on the Router:


crypto map SDM_CMAP_1 1 ipsec-isakmp

set pfs

Hope this info helps!!


Rate if helps you!! 


-JP-

Yura Kazakevich Tue, 09/06/2016 - 13:32
User Badges:

Oh my god))) Yes!

Here is dog was buried! How I didn't see it..........

crypto map SDM_CMAP_1 1 ipsec-isakmp
 description Tunnel to_BS_BFT
 set peer 10.1.11.30
 set security-association lifetime seconds 28800
 set transform-set ESP-3DES-SHA1
 set pfs group2
 match address 100

It seems now everything working as expected.

Jose, thank you! Send me please in email (white#maxigame.by) your paypal account. Man!

Actions

This Discussion

Related Content