Cisco Security Cloud Control: Secure Firewall ASA Management

PDF

Cisco Security Cloud Control: Secure Firewall ASA Management

Site-to-Site VPN Configuration for Cloud-Delivered Firewall Management Center-managed Firewall Threat Defense

Want to summarize with AI?

Log in

Learn how to create site-to-site VPN tunnels for Cloud-Delivered Firewall Management Center-managed Firewall Threat Defense devices with supported peers.


You can create site-to-site IPsec connections between a Cloud-Delivered Firewall Management Center-managed Firewall Threat Defense device and the following devices:

  • Firewall Threat Defense

  • Secure Firewall ASA

  • Multicloud Defense


Create a Site-to-Site VPN Tunnel Between Cloud-Delivered Firewall Management Center-managed Firewall Threat Defense Devices

Use the following procedure to create a site-to-site VPN tunnel between two Firewall Threat Defense devices managed by Cloud-Delivered Firewall Management Center.

Before you begin

There should not be any pending deployments on the Firewall Threat Defense device.

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

In the left pane, choose Secure Connections > Network Connections > Site to Site VPN.

3.

Click the Create Tunnel () icon and then click Site-to-Site VPN.

4.

In the Peer Selection area, provide the following information:

  • Configuration Name: Enter a unique topology name.

    We recommend naming your topology to indicate that it is a Firewall Threat Defense device VPN, and its topology type.

  • Peer 1: Click the FTD tab and select a Firewall Threat Defense device.

  • Peer 2: Click the FTD tab and select a Firewall Threat Defense device.

    If you choose an extranet device, select Static and specify an IP address or select Dynamic for extranet devices with DHCP assigned IP. The IP Address displays the IP address for static interface or DHCP Assigned for the dynamic interface.

5.

Click Next.

6.

In the Peer Details area, provide the following information:

  • VPN Access Interface: Select the interface for both peer 1 and peer 2 to establish a connection between them.

  • LAN Interfaces: Select the interface for both peer 1 and peer 2 that controls the LAN subnet. You can select multiple interfaces

  • Routing: Click Add Networks and select one or more protected networks for peer 1 and peer 2 to establish a site-to-site tunnel between between them.

7.

Click Next.

8.

In the IKE Settings area, choose the IKE versions to use during Internet Key Exchange (IKE) negotiations and specify the privacy configurations: For more information on the IKE policies, see Configuring the Global IKE Policy.

Note

IKE policies are global to a device and apply to all VPN tunnels associated with it. Therefore, adding or deleting policies affect all VPN tunnels in which this device is participating.

  1. Select either or both options as appropriate.

    Note

    By default, IKEV Version 2 is enabled.

  2. Click Add IKEv2 Policies to select the IKEv2 policies for peer 1 and peer 2.

  3. The Local Pre-Shared Key and Remote Pre-Shared Key for the participating devices are auto-genreated. Preshared keys are secret key strings configured on each peer in the connection. These keys are used by IKE during the authentication phase.

  4. Click IKE Version 1 to enable it.

  5. Click Add IKEv1 Policies to select the IKEv1 policies for peer 1 and peer 2.

  6. The IPEv1 Pre-Shared Key is auto-generated.

9.

Click Next.

10.

In the IPSec Settings area, specify the IPSec configurations for peer 1 and peer 2. The corresponding IKEV proposals are available depending on the selection that is made in the IKE Settings step.

For more information on the IPSec settings, see the About IPSec Proposals.

  1. Click Add IKEv2 IPSec Proposals and select the IKEv2 proposals you want for peer 1 and peer 2.

  2. Choose the Diffie-Hellman Group for Perfect Forward Secrecy. For more information, see Encryption and Hash Algorithms Used in VPN.

  3. Click Next.

11.

In the Finish area, you will find a summary of the configurations you have completed.

Read the configuration and then click Submit if you're satisfied.

12.

13.

Perform the following steps to deploy the configuration to a Cloud-Delivered Firewall Management Center-managed Firewall Threat Defense device:

  1. Choose Administration > Integrations > Firewall Management Center.

  2. Ensure the check box corresponding to Cloud-Delivered FMC is checked and in the Actions pane on the right, click Deployment.

  3. Select the device participating in the site-to-site VPN configuration and click Deploy.

  4. Choose Devices > VPN > Site To Site. You can see the same VPN topology that was configured in Security Cloud Control.


Create a Site-to-Site VPN Tunnel Between Cloud-Delivered Firewall Management Center-Managed Firewall Threat Defense and Multicloud Defense

Note

If you are a new customer and you want to use Security Cloud Control to configure a site-to-site VPN between Multicloud Defense and a Cloud-Delivered Firewall Management Center-managed Firewall Threat Defense device, contact Cisco Technical Assistance Center (Cisco TAC) to enable this feature. To manually configure a site-to-site VPN between ASA and Multicloud Defense, you can configure the VPN in the Multicloud Defense application and also on the Cloud-Delivered Firewall Management Center-managed Firewall Threat Defense device manually, and bring up the site-to-site VPN.

You can create site-to-site IPsec connections between a Cloud-Delivered Firewall Management Center-managed Firewall Threat Defense and Multicloud Defense from the Security Cloud Control dashboard that complies with all relevant standards. After the VPN connection is established, the hosts behind the firewall can connect to the hosts behind the gateway through the secure VPN tunnel.

Multicloud Defense currently supports Amazon Web Services (AWS), Azure, Google Cloud Platform (GCP), and Oracle OCI cloud accounts.

Use the following procedure to create a VPN tunnel between a Cloud-Delivered Firewall Management Center-managed Firewall Threat Defense device and Multicloud Defense from the Security Cloud Control dashboard:

Before you begin

Ensure that the following prerequisites are met:

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

In the navigation pane, choose Secure Connections > Network Connections > Site to Site VPN.

3.

Click the Create Tunnel () icon and then click Site-to-Site VPN.

4.

In the Peer Selection area, provide the following information:

  • Configuration Name: Enter a unique topology name.

  • Peer 1: Click the FTD tab and select a Firewall Threat Defense device.

  • Peer 2: Click the Multicloud Defense tab and select the gateway you want.

    If you choose an extranet device, select Static and specify an IP address or select Dynamic for extranet devices with DHCP assigned IP. The IP Address displays the IP address for static interface or DHCP Assigned for the dynamic interface.

5.

Click Next.

6.

In the Peer Details area, provide the following information:

  • VPN Access Interface: Select the interface for Firewall Threat Defense to establish a connection with the gateway.

  • Public IP (optional): Specify the public IP address of the NAT that maps to the outside interface of the selected Firewall Threat Defense.

  • Routing: Click Add Networks and select one or more protected networks from Firewall Threat Defense to create a site-to-site tunnel between the selected networks and the Multicloud Defense Gateway

7.

Click Next.

8.

In the Tunnel Details area, provide the following information:

  • Virtual Tunnel Interface IP: Specify the addresses for the new Virtual Tunnel Interfaces on the peer. You can assign any unused IP address that is currently not used on this device.

  • Autonomous System Number: Specify the autonomous system number of the network.

9.

Click Next.

10.

In the IKE Settings area, click Add IKEv2 and add the IKE version for the Internet Key Exchange (IKE) negotiations and specify the privacy configurations.

Security Cloud Control generates a default Local Pre-Shared Key. This is a secret key string that is configured on the peers. IKE uses this key during the authentication phase. It is used to verify each other when establishing a tunnel between the peers.
11.

Click Next.

12.

In the IPSec Settings area, click Add IKEv2 IPSec Proposals and select the IKE IPSec configuration. The proposals are available depending on the selection that is made in the IKE Settings step. See Configuring IPSec Proposals.

13.

Click Next.

14.

In the Finish area, review the configuration and continue further only if you’re satisfied with the configuration.

15.

Click Submit.

The configurations are pushed to the Multicloud Defense Gateway.

16.

Perform the following steps to deploy the configuration to a Cloud-Delivered Firewall Management Center-managed Firewall Threat Defense device:

  1. Choose Administration > Integrations > Firewall Management Center.

  2. Ensure the check box corresponding to Cloud-Delivered FMC is checked and in the Actions pane on the right, click Deployment.

  3. Select the device participating in the site-to-site VPN configuration and click Deploy.

  4. Choose Devices > VPN > Site To Site. You can see the same VPN topology that was configured in Security Cloud Control.


Create a Site-to-Site VPN Between Cloud-Delivered Firewall Management Center-managed Firewall Threat Defense and Secure Firewall ASA

Before you begin

There should not be any pending deployments on the Firewall Threat Defense device.

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

In the navigation pane, choose Secure Connections > Network Connections > Site to Site VPN.

3.

Click the Create Tunnel () icon and then click Site-to-Site VPN.

4.

In the Peer Selection area, provide the following information:

  • Configuration Name: Enter a unique topology name.

    We recommend naming your topology to indicate that it is a Firewall Threat Defense device VPN, and its topology type.

  • Peer 1: Click the FTD tab and select a Firewall Threat Defense device.

  • Peer 2: Click the ASA tab and select a Secure Firewall ASAdevice.

    If you choose an extranet device, select Static and specify an IP address or select Dynamic for extranet devices with DHCP assigned IP. The IP Address displays the IP address for static interface or DHCP Assigned for the dynamic interface.

5.

Click Next.

6.

In the Peer Details area, provide the following information:

  • VPN Access Interface: Select the interface for both peer 1 and peer 2 to establish a connection between them.

  • LAN Interfaces: Select the interface for both peer 1 and peer 2 that controls the LAN subnet. You can select multiple interfaces

  • Routing: Click Add Networks and select one or more protected networks for peer 1 and peer 2 to establish a site-to-site tunnel between between them.

7.

Click Next.

8.

In the Tunnel Details area, provide the following information:

  • Virtual Tunnel Interface IP: Specify the address for the new Virtual Tunnel Interfaces for Secure Firewall ASA. Security Cloud Control provides a sample address for Secure Firewall ASA which you can change if it causes conflict. You can assign any unused IP address that is currently not used on this device.

9.

Click Next.

10.

In the IKE Settings area, choose the IKE versions to use during Internet Key Exchange (IKE) negotiations and specify the privacy configurations: For more information on the IKE policies, see Configuring the Global IKE Policy.

Note

IKE policies are global to a device and apply to all VPN tunnels associated with it. Therefore, adding or deleting policies affect all VPN tunnels in which this device is participating.

  1. Select either or both options as appropriate.

    Note

    By default, IKEV Version 2 is enabled.

  2. Click Add IKEv2 Policies to select the IKEv2 policies for peer 1 and peer 2.

  3. The Local Pre-Shared Key and Remote Pre-Shared Key for the participating devices are auto-genreated. Preshared keys are secret key strings configured on each peer in the connection. These keys are used by IKE during the authentication phase.

  4. Click IKE Version 1 to enable it.

  5. Click Add IKEv1 Policies to select the IKEv1 policies for peer 1 and peer 2.

  6. The IPEv1 Pre-Shared Key is auto-generated.

11.

Click Next.

12.

In the IPSec Settings area, specify the IPSec configurations for peer 1 and peer 2. The corresponding IKEV proposals are available depending on the selection that is made in the IKE Settings step.

For more information on the IPSec settings, see the About IPSec Proposals.

  1. Click Add IKEv2 IPSec Proposals and select the IKEv2 proposals you want for peer 1 and peer 2.

  2. Choose the Diffie-Hellman Group for Perfect Forward Secrecy. For more information, see Deciding Which Diffie-Hellman Modulus Group to Use.

13.

Click Next.

14.

In the Finish area, you will find a summary of the configurations you have completed.

Read the configuration and then click Submit if you're satisfied.

15.

Perform the following steps to deploy the configuration to a Cloud-Delivered Firewall Management Center-managed Firewall Threat Defense device:

  1. Choose Administration > Integrations > Firewall Management Center.

  2. Ensure the check box corresponding to Cloud-Delivered FMC is checked and in the Actions pane on the right, click Deployment.

  3. Select the device participating in the site-to-site VPN configuration and click Deploy.

  4. Choose Devices > VPN > Site To Site. You can see the same VPN topology that was configured in Security Cloud Control.