10-06-2010 08:00 AM
Hi, I would like to know if it is possible to build an IPv6 VPN over a IPv4 network using ASA's, like this:
ipv6 access-list VPN_IPV6_ACL permit ip 2001:470:aaaa:aaaa::/64 2001:470:bbbb:bbbb::/64
crypto map OUTSIDE_CM 40 match address VPN_IPV6_ACL
crypto map OUTSIDE_CM 40 set pfs group5
crypto map OUTSIDE_CM 40 set peer 10.10.10.10
crypto map OUTSIDE_CM 40 set transform-set ESP-AES256-SHA
crypto map OUTSIDE_CM 40 set security-association lifetime seconds 28800
crypto map OUTSIDE_CM 40 set security-association lifetime kilobytes 4608000
crypto map OUTSIDE_CM 40 set reverse-route
Is this possible? Thanks!
10-06-2010 11:26 AM
Only on ASA 8.3.
http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/site2sit.html#wp1055829
"The adaptive security appliances have IPv6 inside networks and the outside network is IPv4 (IPv6 addresses on the inside interface and IPv4 addresses on the outside interfaces)."
HTH,
Marcin
10-06-2010 11:27 AM
copying from the release notes
http://www.cisco.com/en/US/partner/docs/security/asa/asa83/release/notes/asarn83.html
For LAN-to-LAN connections using mixed IPv4 and IPv6 addressing, or all IPv6 addressing, the adaptive security appliance supports VPN tunnels if both peers are Cisco ASA 5500 series adaptive security appliances, and if both inside networks have matching addressing schemes (both IPv4 or both IPv6).
Specifically, the following topologies are supported when both peers are Cisco ASA 5500 series adaptive security appliances:
•The adaptive security appliances have IPv4 inside networks and the outside network is IPv6 (IPv4 addresses on the inside interfaces and IPv6 addresses on the outside interfaces).
•The adaptive security appliances have IPv6 inside networks and the outside network is IPv4 (IPv6 addresses on the inside interface and IPv4 addresses on the outside interfaces).
•The adaptive security appliances have IPv6 inside networks and the outside network is IPv6 (IPv6 addresses on the inside and outside interfaces).
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: