Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- interfaces {
- /* GRE Tunnel was not working . Why because I didn't put it in any zone! DOH! */
- gr-0/0/0 {
- unit 0 {
- tunnel {
- source 10.127.0.6;
- destination 192.168.244.1;
- }
- family inet;
- }
- }
- fe-0/0/1 {
- unit 0 {
- family inet {
- address 10.10.20.1/24;
- }
- }
- }
- fe-0/0/2 {
- unit 0 {
- family inet {
- address 1.1.1.1/27;
- }
- }
- }
- lo0 {
- unit 0 {
- family inet {
- address 10.127.0.6/32;
- }
- }
- }
- st0 {
- unit 1 {
- family inet {
- mtu 1500;
- /* ephemeral interface */
- next-hop-tunnel 10.128.1.2 ipsec-vpn ASA_vpn;
- address 10.128.1.1/27
- }
- }
- }
- }
- routing-options {
- static {
- route 0.0.0.0/0 next-hop 1.1.1.7;
- route 192.168.244.1/32 next-hop 10.128.1.2;
- route 10.10.10.0/24 next-hop gr-0/0/0.0;
- }
- router-id 10.127.0.6;
- }
- security {
- ike {
- traceoptions {
- file iketrace size 1m;
- flag ike;
- flag policy-manager;
- }
- /* Changed to 3des and md5 on request of other side */
- proposal my_p1 {
- authentication-method pre-shared-keys;
- dh-group group2;
- authentication-algorithm md5;
- encryption-algorithm 3des-cbc;
- lifetime-seconds 28800;
- }
- policy ASA_gw {
- mode main;
- proposals my_p1;
- pre-shared-key ascii-text "xxxxxxxxxxx"; ## SECRET-DATA
- }
- gateway orbcomm_gw {
- ike-policy ASA_gw;
- address 2.2.2.2;
- external-interface fe-0/0/2;
- }
- }
- ipsec {
- /* Changed to 3des and MD5 at request of Otherside */
- proposal my_p2 {
- protocol esp;
- authentication-algorithm hmac-md5-96;
- encryption-algorithm 3des-cbc;
- lifetime-seconds 3600;
- }
- policy my_pol {
- perfect-forward-secrecy {
- keys group2;
- }
- proposals my_p2;
- }
- vpn ASA_vpn {
- bind-interface st0.1;
- ike {
- gateway ASA_gw;
- no-anti-replay;
- proxy-identity {
- local 10.127.0.6/32;
- remote 192.168.244.1/32;
- }
- ipsec-policy my_pol;
- }
- establish-tunnels immediately;
- }
- }
- flow {
- tcp-mss {
- ipsec-vpn {
- mss 1350;
- }
- }
- }
- }
Add Comment
Please, Sign In to add comment