Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

FIPS Compliant site-to-site VPN

Hello.  I have ASA 5505 boxes that I want to configure for site-to-site encryption over a WAN link.  I need the enctyption to be FIPS 140-2 compliant.  I am running Cisco ASA Version 7.2(3), installed about May 2008.

My links go: LAN-ASA-Router-<WAN>-Router-ASA-LAN, where WAN will be T-1 or similar.

I have seen the site-to-site configuration examples.  If I use 3DES at each end will that be in compliance?

Anything special (IOS, software upgrade, etc) that I need?

Thanks in advance.

Everyone's tags (3)
1 ACCEPTED SOLUTION

Accepted Solutions

Re: FIPS Compliant site-to-site VPN

Asa5505 can suport up to 25 ipsec tunnels  so the answer to your question is yes,  you can have  more than one L2L vpn  from  asa_f1 , see examples  in bellow link under site-to-site VPN.

http://www.cisco.com/en/US/products/ps6120/prod_configuration_examples_list.html

4 REPLIES

Re: FIPS Compliant site-to-site VPN

Read this whole doc, will tell you all about meeting FIPS complience -  3DES  encryption is   FIPS complience .

http://www.cisco.com/en/US/docs/security/asa/asa70/hw/fips_asa.html

 

New Member

Re: FIPS Compliant site-to-site VPN

Thank you!

I have a follow-up question, that I should have made clear in my original question.

Can I make one-to-many VPN connections with the ASA 5505 firewalls, as illustrated below:

Site to site, from FW_1 to FW_A, and FW_1 to FW_B, and FW_1 to FW_C.

Re: FIPS Compliant site-to-site VPN

Asa5505 can suport up to 25 ipsec tunnels  so the answer to your question is yes,  you can have  more than one L2L vpn  from  asa_f1 , see examples  in bellow link under site-to-site VPN.

http://www.cisco.com/en/US/products/ps6120/prod_configuration_examples_list.html

New Member

Re: FIPS Compliant site-to-site VPN

Thank you for your help. I appreciate it!

1403
Views
0
Helpful
4
Replies