Cisco Security Cloud Control: Secure Firewall ASA Management

PDF

Cisco Security Cloud Control: Secure Firewall ASA Management

Monitor ASA Site-to-Site Virtual Private Networks

Want to summarize with AI?

Log in

Learn how to monitor ASA site-to-site VPN tunnels, check connectivity, review dashboard status, identify issues, and view tunnel details.


Security Cloud Control allows you to monitor already existing site-to-site VPN configurations on onboarded ASA devices. It doesn't allow you to modify or delete the site-to-site configuration.


Check Site-to-Site VPN Tunnel Connectivity

Use the Check Connectivity button to trigger a real-time connectivity check against the tunnel to identify whether the tunnel is currently active or idle. Unless you click the on-demand connectivity check button, a check across all tunnels, available across all onboarded devices, occurs once an hour.

Note
  • Security Cloud Control runs this connectivity check command on the ASA to determine if a tunnel is active or idle:
    show vpn-sessiondb l2l sort ipaddress
  • Model ASA device(s) tunnels will always show as Idle.

To check tunnel connectivity from the VPN page:

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

In the left pane, choose Secure Connections > Network Connections > Site to Site VPN.

3.

Search and filter the list of tunnels for your site-to-site VPN tunnel and select it.

4.

In the Actions pane at the right, click Check Connectivity.


Site-To-Site VPN Dashboard

Security Cloud Control provides a consolidated information about site-to-site VPN connections created in the tenant.

  1. From the Security Cloud Control Home page, click Firewall.

  2. In the left pane, click Secure Connections > Site to Site VPN. The Site-to-Site VPN provides the information in the following widgets:

  • Sessions & Insights: Displays a bar graph representing Active VPN Tunnels and Idle VPN Tunnels, each in appropriate colors.

  • Issues: Shows the total number of tunnels detected with issues.

  • Pending Deploy: Shows the total number of tunnels with pending deployment.

By clicking on a value in the pie chart or any link in the widget, the site-to-site VPN listing page is displayed with a filter based on the selected value. For instance, in the VPN Tunnel Status widget, on clicking the Active VPN Tunnels, you will be directed to the site-to-site VPN listing page with the Active status filter applied, showing only the active tunnels.


Identify VPN Issues


Find VPN Tunnels with Missing Peers

The "Missing IP Peer" condition is more likely to occur on ASA devices than FDM-managed devices.

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

In the left pane, click Secure Connections > Network Connections > Site to Site VPN to open the VPN page.

3.

Select Table View.

4.

Open the Filter panel by clicking the filter icon .

5.

Check Detected Issues.

6.

Select each device reporting an issue and look in the Peers pane at the right. One peer name will be listed. Security Cloud Control reports the other peer name as, "[Missing peer IP.]"


Find VPN Peers with Encryption Key Issues

Use this approach to locate VPN Peers with encryption key issues such as:

  • IKEv1 or IKEv2 keys are invalid, missing, or mismatched

  • Obsolete or low encryption tunnels

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

In the left pane, click Secure Connections > Network Connections > Site to Site VPN to open the VPN page.

3.

Select Table View.

4.

Open the Filter panel by clicking the filter icon .

5.

Select each device reporting an issue and look in the Peers pane at the right. The peer information will show you both peers.

6.

Click on View Peers for one of the devices.

7.

Double-click the device reporting the issue in the Diagram View.

8.

Click Key Exchange in the Tunnel Details panel at the bottom. You will be able to view both devices and diagnose the key issue from that point.


Find Incomplete or Misconfigured Access Lists Defined for a Tunnel

The "incomplete or misconfigured access-list" condition could only occur on ASA devices.

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

In the left pane, click Secure Connections > Network Connections > Site to Site VPN to open the VPN page.

3.

Select Table View.

4.

Open the Filter panel by clicking the filter icon .

5.

Select each device reporting an issue and look in the Peers pane at the right. The peer information shows you both peers.

6.

Click on View Peers for one of the devices.

7.

Double-click the device reporting the issue in the Diagram View.

8.

Click Tunnel Details in the Tunnel Details panel at the bottom. You will see the message, "Network Policy: Incomplete"


Find Issues in Tunnel Configuration

The tunnel configuration error can occur in the following scenarios:

  • When the IP address of a site-to-site VPN interface changes, the "Peer IP Address Value has changed".

  • When the IKE value of a VPN tunnel doesn't match the other VPN tunnel, the "IKE value Mismatch" message appears.

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

In the left pane, click Secure Connections > Network Connections > Site to Site VPN to open the VPN page.

3.

Select Table View.

4.

Open the Filter panel by clicking the filter icon .

5.

In the Tunnel Issues, click Detected Issues to view the VPN configuration reporting errors. You can view the configuration reporting issues .

6.

Select the VPN configuration reporting issues.

7.

In the Peers pane on the right, the icon appears for the peer having the issue. Hover over the icon to see the issue and resolution.


Resolve Tunnel Configuration Issues

This procedure attempts to resolve these tunnel configuration issues:

  • When the IP address of a site-to-site VPN interface changes, the "Peer IP Address Value has changed".

  • When the IKE value of a VPN tunnel doesn’t match the other VPN tunnel, the "IKE value Mismatch" message appears.

See Find Issues in Tunnel Configuration for more information.

Procedure

1.

In the left pane, click Security Devices.

2.

Click the Devices tab.

3.

Click the appropriate device type tab and select the device associated with the VPN configuration reporting an issue.

4.

Accept the device changes.

5.

In the left pane, click VPN > ASA/FDM Site-to-Site VPN to open the VPN page.

6.

Select the VPN configuration reporting this issue.

7.

In the Actions pane, click the Edit icon.

8.

Click Next in each step until you click the Finish button in step 4.

9.

Preview and deploy configuration changes for all devices.


Search and filter site-to-site VPN tunnels

Use the filter sidebar Filter icon. in combination with the search field to focus your search of VPN tunnels presented in the VPN tunnel diagram.

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

Choose Secure Connections > Network Connections > Site to Site VPN.

3.

Click the filter icon Filter icon. to open the filter pane.

4.

Use these filters to refine your search:

  • Filter by Device: Click Filter by Device, select the device type tab, and check the devices you want to find by filtering.

  • Tunnel Issues: Indicates whether issues have been detected on either side of the tunnel. For example, a device may be missing an associated interface, peer IP address, access list, or may have IKEv1 proposal mismatches. (Detecting tunnel issues is not yet available for AWS VPC VPN tunnels.)

  • Devices/Services: Filters by type of device.

  • Status: Indicates tunnel status, which can be active or idle.

    • Active: An open session exists in which network packets traverse the VPN tunnel, or a successful session was established that has not timed out yet. The "Active" status indicates that the tunnel is operational and relevant.

    • Idle: Security Cloud Control is unable to discover an open session for this tunnel. The tunnel may either be not in use or there is an issue with this tunnel.

  • Onboarded: Devices could be managed by Security Cloud Control or not managed (unmanaged) by Security Cloud Control.

    • Managed: Filters by devices that Security Cloud Control manages.

    • Unmanaged: Filters by devices that Security Cloud Control does not manage.

  • Device Types: Indicates whether either side of the tunnel is a live (connected) or model device.

5.

You can also search the filtered results by device name or IP address by entering that information in the search bar. The search is case-insensitive.


Onboard an Unmanaged Site-to-Site VPN Peer

Security Cloud Control will discover a site-to-site VPN tunnel when one of the peers is onboarded. If the second peer is not managed by Security Cloud Control, you can filter the list of VPN tunnels to find the unmanaged device and onboard it:

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

In the left pane, click Secure Connections > Network Connections > Site to Site VPN to open the VPN page.

3.

Select Table View.

4.

Open the filter panel by clicking .

5.

Check Unmanaged.

6.

Select a tunnel from the table from the results.

7.

In the Peers pane on the right, click Onboard Device and follow the instructions on the screen.


View IKE Object Details of Site-To-Site VPN Tunnels

You can view the details of the IKE objects configured on the peers/devices of the selected tunnel. These details appear in a tree structure in a hierarchy based on the priority of the IKE policy object.

Note

Extranet devices don't show the IKE Objects details.

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

In the left pane, click Secure Connections > Network Connections > Site to Site VPN to open the VPN page.

3.

In the VPN Tunnels page, click the name of the VPN tunnel that connects the peers.

4.

Under Relationships on the right, expand the object that you want to see its details.


View Last Successful Site-to-Site VPN Tunnel Establishment Date

This information typically provides the date and time when the VPN tunnel was last successfully established, ensuring connectivity between the two sites. Accessing this data can help you monitor VPN health and troubleshoot any connectivity issues that might arise.

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

In the left pane, click Secure Connections > Network Connections > Site to Site VPN to open the VPN page.

3.

The VPN Tunnels page displays all the site-to-site VPN tunnels configured across your managed devices. You can click a tunnel to view more details in the right pane.

Note

Use Search and Filter Site-to-Site VPN Tunnels to find a specific tunnel.

The Last Active field shows the date and time the VPN tunnel was successfully established.


View Site-to-Site VPN Tunnel Information

The site-to-site VPN table view is a complete listing of all site-to-site VPN tunnels available across all devices onboarded to Security Cloud Control. A tunnel only exists once in this list. Clicking on a tunnel listed in the table provides an option in the right side bar to navigate directly to a tunnel's peers for further investigation.

In cases where Security Cloud Control does not manage both sides of a tunnel, you can click Onboard Device to open the main onboarding page an onboard the unmanaged peer. In cases where Security Cloud Control manages both side of a tunnel, the Peer 2 column contains the name of the managed device. However, in the case of an AWS VPC, the Peer 2 column contains the IP address of the VPN gateway.

To view site-to-site VPN connections in the table view:

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

In the left pane, click Secure Connections > Network Connections > Site to Site VPN to open the VPN page.

3.

The VPN Tunnels page displays all the site-to-site VPN tunnels configured across your managed devices. You can click on a tunnel to view more details in the right pane.

Note

Use Search and Filter Site-to-Site VPN Tunnels to find a specific tunnel.


Site-to-Site VPN Global View

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

In the left pane, click Secure Connections > Network Connections > Site to Site VPN.

3.

Click the Global view button.

4.

Use Search and Filter Site-to-Site VPN Tunnels to find a specific tunnel, or zoom into the Global View graphic to find the VPN gateway and its peers that you are looking for.

5.

Select one of the peers represented in the Global View.

6.

Click View Details.

7.

Click the other end of the VPN tunnel and Security Cloud Control displays Tunnel Details, NAT Information, and Key Exchange information for that connection:

  • Tunnel Details-Displays the name and connectivity information about the tunnel. Clicking the Refresh icon updates the connectivity information for the tunnels.

  • Tunnel Details specific to AWS connections-Tunnel details for AWS site-to-site connections are slightly different than for other connections. For each connection from the AWS VPC to your VPN gateway, AWS creates two VPN tunnels. This is for high availability.

    • The name of the tunnel represents the name of the VPC your VPN gateway is connected to. The IP address named in the tunnel is the IP address that your VPN gateway knows as the VPC.

    • If the Security Cloud Control Connectivity status shows active, the AWS tunnel state is Up. If the Security Cloud Control Connectivity state is inactive, the AWS tunnel state is Down.

  • NAT Information-Displays the type of NAT rule being used, original and translated packet information, and provides links to the NAT table to view the NAT rule for that tunnel. (Not yet available for AWS VPC site-to-site VPN.)

  • Key Exchange-Displays the cryptographic keys in use by the tunnel and key-exchange issues. (Not yet available for AWS VPC site-to-site VPN.)


Site-to-Site VPN Tunnels Pane

The Tunnels pane displays a list of all the tunnels associated with a particular VPN gateway. For site-to-site VPN connections between your VPN gateway and an AWS VPC, the tunnels pane shows all the tunnels from your VPN gateway to the VPC. Since each site-to-site VPN connection between your VPN gateway and an AWS VPC has two tunnels, you will see double the number of tunnels you normally would for other devices.

VPN Gateway Details

Displays the number of peers connected to the VPN gateway and the IP address of the VPN gateway. This is only visible in the VPN Tunnels page.

View Peer

After you select a site-to-site VPN peer pair, the peers pane lists the two devices in the pair and allows you to click View Peer for one of the devices. By clicking View Peer, you see any other site-to-site peer that device is associated with. This is visible in the Table view and in the Global view.