Site-to-Site IPsec VPN
Cisco ASA Firewall EVE-NG — ASAv (CLI + ASDM)
مقصدObjectiveObjective
Complete IKEv2 site-to-site IPsec VPN بنائیں: IKEv2 policy اور proposal، IPsec transform set، crypto map، tunnel group، اور NAT exemption۔Complete IKEv2 site-to-site IPsec VPN banao: IKEv2 policy aur proposal, IPsec transform set, crypto map, tunnel group, aur NAT exemption.Build a complete IKEv2 site-to-site IPsec VPN: IKEv2 policy and proposal, IPsec transform set, crypto map, tunnel group, and NAT exemption.
آسان مثالSimple AnalogySimple Analogy
Site-to-site VPN دو company buildings کے درمیان public گلی (internet) کے نیچے کھودی ہوئی private armored tunnel ہے۔ IKEv2 وہ handshake ہے جس میں دونوں guards tunnel کے locks پر agree کرتے ہیں، کوئی truck گزرنے سے پہلے۔Site-to-site VPN do company buildings ke darmiyan public gali (internet) ke neeche khodi hui private armored tunnel hai. IKEv2 woh handshake hai jisme dono guards tunnel ke locks par agree karte hain, koi truck guzarne se pehle.A site-to-site VPN is a private armored tunnel dug between two company buildings across the public street (the internet). IKEv2 is the handshake where both guards agree on the tunnel's locks before any truck drives through.
سیٹ اپLab SetupLab Setup
EVE-NG میں دو ASAv nodes: ASA-A (outside 203.0.113.2، inside 10.1.1.0/24) اور ASA-B (outside 198.51.100.2، inside 10.2.2.0/24)، outside پر directly connected۔ Pre-shared key: OurSecret123۔ نیچے والے steps ASA-A کے لیے ہیں؛ ASA-B پر mirror کریں۔EVE-NG mein do ASAv nodes: ASA-A (outside 203.0.113.2, inside 10.1.1.0/24) aur ASA-B (outside 198.51.100.2, inside 10.2.2.0/24), outside par directly connected. Pre-shared key: OurSecret123. Neeche wale steps ASA-A ke liye hain; ASA-B par mirror karo.Two ASAv nodes in EVE-NG: ASA-A (outside 203.0.113.2, inside 10.1.1.0/24) and ASA-B (outside 198.51.100.2, inside 10.2.2.0/24), directly connected on outside. Pre-shared key: OurSecret123. Steps below are for ASA-A; mirror them on ASA-B.
اقداماتStepsSteps
Step 1
IKEv2 policy define کریں (Phase 1): AES-256 encryption، SHA-256 integrity، Diffie-Hellman group 14، 24-hour lifetime۔IKEv2 policy define karo (Phase 1): AES-256 encryption, SHA-256 integrity, Diffie-Hellman group 14, 24-hour lifetime.Define the IKEv2 policy (Phase 1): AES-256 encryption, SHA-256 integrity, Diffie-Hellman group 14, 24-hour lifetime.
crypto ikev2 policy 10 encryption aes-256 integrity sha256 group 14 prf sha256 lifetime seconds 86400 exit
Step 2
IPsec proposal define کریں (Phase 2): AES-256 اور SHA-256 کے ساتھ ESP، 8-hour SA lifetime۔IPsec proposal define karo (Phase 2): AES-256 aur SHA-256 ke sath ESP, 8-hour SA lifetime.Define the IPsec proposal (Phase 2): ESP with AES-256 and SHA-256, 8-hour SA lifetime.
crypto ipsec ikev2 ipsec-proposal AES256-SHA protocol esp encryption aes-256 protocol esp integrity sha-256 exit crypto ipsec security-association lifetime seconds 28800
Step 3
Crypto ACL سے interesting traffic define کریں: دونوں sites کے درمیان LAN-to-LAN traffic encrypt ہوگا۔Crypto ACL se interesting traffic define karo: dono sites ke darmiyan LAN-to-LAN traffic encrypt hoga.Define interesting traffic with a crypto ACL: LAN-to-LAN traffic between the two sites gets encrypted.
access-list VPN_INTERESTING extended permit ip 10.1.1.0 255.255.255.0 10.2.2.0 255.255.255.0
Step 4
Crypto map بنائیں: interesting-traffic ACL bind کریں، remote peer set کریں، IPsec proposal attach کریں، اور map کو outside interface پر apply کریں۔Crypto map banao: interesting-traffic ACL bind karo, remote peer set karo, IPsec proposal attach karo, aur map ko outside interface par apply karo.Build the crypto map: bind the interesting-traffic ACL, set the remote peer, attach the IPsec proposal, and apply the map to the outside interface.
crypto map OUTSIDE_MAP 10 match address VPN_INTERESTING crypto map OUTSIDE_MAP 10 set peer 198.51.100.2 crypto map OUTSIDE_MAP 10 set ikev2 ipsec-proposal AES256-SHA crypto map OUTSIDE_MAP interface outside
Step 5
Peer کے لیے tunnel group بنائیں دونوں طرف pre-shared key کے ساتھ، اور outside interface پر IKEv2 enable کریں۔Peer ke liye tunnel group banao dono taraf pre-shared key ke sath, aur outside interface par IKEv2 enable karo.Create the tunnel group for the peer with the pre-shared key on both sides, and enable IKEv2 on the outside interface.
tunnel-group 198.51.100.2 type ipsec-l2l tunnel-group 198.51.100.2 ipsec-attributes ikev2 remote-authentication pre-shared-key OurSecret123 ikev2 local-authentication pre-shared-key OurSecret123 exit crypto ikev2 enable outside
Step 6
Twice-NAT identity exemption add کریں تاکہ VPN traffic NAT نہ ہو۔ ASA-B پر سارے steps addresses swap کرکے mirror کریں۔Twice-NAT identity exemption add karo taake VPN traffic NAT na ho. ASA-B par sare steps addresses swap karke mirror karo.Add the twice-NAT identity exemption so VPN traffic is not NATed. Mirror all steps on ASA-B with addresses swapped.
object network LOCAL_LAN subnet 10.1.1.0 255.255.255.0 exit object network REMOTE_LAN subnet 10.2.2.0 255.255.255.0 exit nat (inside,outside) source static LOCAL_LAN LOCAL_LAN destination static REMOTE_LAN REMOTE_LAN no-proxy-arp
🖱️ ASDM: Wizards > VPN Wizards > Site-to-Site VPN Wizard — guided wizard سے same config۔ASDM: Wizards > VPN Wizards > Site-to-Site VPN Wizard — guided wizard se same config.ASDM: Wizards > VPN Wizards > Site-to-Site VPN Wizard — the same config through a guided wizard.
Step 7
دونوں ASAs پر configuration save کریں۔Dono ASAs par configuration save karo.Save the configuration on both ASAs.
write memory
تصدیقVerifyVerify
`show crypto ikev2 sa` میں active SA نظر آئے، `show crypto ipsec sa` میں encrypted/decrypted packet counters بڑھتے ہوں، اور 10.1.1.x سے 10.2.2.x تک ping کامیاب ہو۔`show crypto ikev2 sa` mein active SA nazar aaye, `show crypto ipsec sa` mein encrypted/decrypted packet counters barhte hon, aur 10.1.1.x se 10.2.2.x tak ping kamyab ho.`show crypto ikev2 sa` shows an active SA, `show crypto ipsec sa` shows encrypted/decrypted packet counters increasing, and a ping from 10.1.1.x to 10.2.2.x succeeds.
show crypto ikev2 sa show crypto ipsec sa show crypto map
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ `show crypto ikev2 sa` میں کوئی SA نہیں — Phase 1 کبھی up نہیں ہوتا۔`show crypto ikev2 sa` mein koi SA nahi — Phase 1 kabhi up nahi hota.`show crypto ikev2 sa` shows no SA — Phase 1 never comes up.
✅ Phase 1 mismatched policy یا PSK پر fail ہوتا ہے۔ دونوں طرف `show run crypto ikev2` line by line compare کریں، pre-shared keys بالکل same دوبارہ type کریں، اور confirm کریں کہ outside IPs کے درمیان UDP 500/4500 permitted ہے۔Phase 1 mismatched policy ya PSK par fail hota hai. Dono taraf `show run crypto ikev2` line by line compare karo, pre-shared keys bilkul same dobara type karo, aur confirm karo ke outside IPs ke darmiyan UDP 500/4500 permitted hai.Phase 1 fails on mismatched policy or PSK. Compare `show run crypto ikev2` on both sides line by line, retype the pre-shared keys identically, and confirm UDP 500/4500 is permitted between the outside IPs.
⚠️ Phase 1 up ہے لیکن traffic نہیں گزر رہا — Phase 2 fail ہو رہا ہے۔Phase 1 up hai lekin traffic nahi guzar raha — Phase 2 fail ho raha hai.Phase 1 is up but no traffic passes — Phase 2 fails.
✅ Check کریں crypto ACLs mirror images ہیں (source/dest swapped) اور IPsec proposals match کرتے ہیں۔ NAT exemption بھی verify کریں — NAT ہوا VPN traffic Phase 2 selectors توڑ دیتا ہے۔Check karo crypto ACLs mirror images hain (source/dest swapped) aur IPsec proposals match karte hain. NAT exemption bhi verify karo — NAT hua VPN traffic Phase 2 selectors tor deta hai.Check that the crypto ACLs are mirror images (source/dest swapped) and the IPsec proposals match. Also verify the NAT exemption exists — NATed VPN traffic breaks Phase 2 selectors.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ IKE Phase 1 اور Phase 2 میں کیا فرق ہے؟IKE Phase 1 aur Phase 2 mein kya farq hai?What is the difference between IKE Phase 1 and Phase 2?
Phase 1 (IKEv2) دونوں firewalls کے درمیان secure management channel بناتا ہے؛ Phase 2 (IPsec) child SAs negotiate کرتا ہے جو اصل میں user traffic encrypt کرتے ہیں۔ اگر Phase 1 fail ہو تو کچھ نہیں چلے گا — `show crypto ikev2 sa` سے check کریں۔Phase 1 (IKEv2) dono firewalls ke darmiyan secure management channel banata hai; Phase 2 (IPsec) child SAs negotiate karta hai jo asal mein user traffic encrypt karte hain. Agar Phase 1 fail ho to kuch nahi chalega — `show crypto ikev2 sa` se check karo.Phase 1 (IKEv2) builds the secure management channel between the two firewalls; Phase 2 (IPsec) negotiates the child SAs that actually encrypt user traffic. If Phase 1 fails, nothing works — check with `show crypto ikev2 sa`.
❓ ASA IPsec VPN میں 'interesting traffic' کیا ہوتا ہے؟ASA IPsec VPN mein 'interesting traffic' kya hota hai?What is 'interesting traffic' in an ASA IPsec VPN?
Interesting traffic وہ traffic ہے جسے crypto ACL encryption کے لیے select کرتی ہے — typically LAN-to-LAN subnets۔ ACL سے match ہونے والا traffic tunnel negotiation trigger کرتا ہے؛ باقی سب normally باہر جاتا ہے (یا NAT سے)۔Interesting traffic woh traffic hai jise crypto ACL encryption ke liye select karti hai — typically LAN-to-LAN subnets. ACL se match hone wala traffic tunnel negotiation trigger karta hai; baqi sab normally bahar jata hai (ya NAT se).Interesting traffic is the traffic the crypto ACL selects for encryption — typically LAN-to-LAN subnets. Traffic matching the ACL triggers tunnel negotiation; everything else goes out normally (or via NAT).