{"id":647,"date":"2016-03-23T19:19:00","date_gmt":"2016-03-23T19:19:00","guid":{"rendered":"http:\/\/www.safekom.pl\/blog\/?p=647"},"modified":"2020-03-25T12:24:04","modified_gmt":"2020-03-25T11:24:04","slug":"lab_ipsec_palo_ciscoasa","status":"publish","type":"post","link":"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/","title":{"rendered":"LAB &#8211;  IPSec Palo &#8211; Cisco ASA"},"content":{"rendered":"<p>Poni\u017cej pokazuj\u0119 jak zestawia\u0107 po\u0142\u0105czenie IPsec pomi\u0119dzy PaloAlto Networks a Cisco ASA. W mym przypadku oba urz\u0105dzenia s\u0105 w wersji wirtualnej ale konfiguracja ich odpowiada tak jak by\u015bmy konfigurowali urz\u0105dzenia fizyczne.<\/p>\n<p>Za\u0142o\u017cenia:<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_palo.png\" rel=\"attachment wp-att-648\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"648\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/attachment\/asa_palo\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_palo.png?fit=764%2C146&amp;ssl=1\" data-orig-size=\"764,146\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"asa_palo\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_palo.png?fit=764%2C146&amp;ssl=1\" class=\"alignnone wp-image-648\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_palo.png?resize=733%2C140\" alt=\"asa_palo\" width=\"733\" height=\"140\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_palo.png?w=764&amp;ssl=1 764w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_palo.png?resize=300%2C57&amp;ssl=1 300w\" sizes=\"auto, (max-width: 733px) 100vw, 733px\" \/><\/a><\/p>\n<table>\n<tbody>\n<tr>\n<td>Faza 1<\/td>\n<td>aes256 sha-1 pfs g2 86400s<\/td>\n<\/tr>\n<tr>\n<td>Faza 2<\/td>\n<td>aes256 sha-1 pfs g2 28800s<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table>\n<tbody>\n<tr>\n<td><\/td>\n<td>Palo<\/td>\n<td>Cisco ASA<\/td>\n<\/tr>\n<tr>\n<td>Sieci kt\u00f3re b\u0119d\u0105 podlega\u0142y szyfrowaniu<\/td>\n<td>10.20.10.0\/24<\/td>\n<td>172.16.1.0\/24<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table>\n<tbody>\n<tr>\n<td><\/td>\n<td>Palo<\/td>\n<td>Cisco ASA<\/td>\n<\/tr>\n<tr>\n<td>Interfejs z adresem tzw. publicznym<\/td>\n<td>192.168.1.51\/24<\/td>\n<td>192.168.1.80\/24<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h4><\/h4>\n<p><!--more--><\/p>\n<h4>Konfiguracja Cisco ASA<\/h4>\n<p>Logujemy si\u0119 do SSH lub ASDM&#8217;a. Poni\u017cej b\u0119d\u0119 prezentowa\u0107 konfiguracj\u0119 obu sposob\u00f3w.<\/p>\n<p>ASDM &#8211; przechodzimy do Configuration &#8211;&gt; Site-to-Site VPN<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec01.png\" rel=\"attachment wp-att-658\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"658\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/attachment\/asa_ipsec01\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec01.png?fit=769%2C342&amp;ssl=1\" data-orig-size=\"769,342\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"asa_ipsec01\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec01.png?fit=769%2C342&amp;ssl=1\" class=\"alignnone size-full wp-image-658\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec01.png?resize=769%2C342\" alt=\"asa_ipsec01\" width=\"769\" height=\"342\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec01.png?w=769&amp;ssl=1 769w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec01.png?resize=300%2C133&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec01.png?resize=768%2C342&amp;ssl=1 768w\" sizes=\"auto, (max-width: 769px) 100vw, 769px\" \/><\/a><\/p>\n<p>w\u0142\u0105czamy <strong>IKE<\/strong> dla Interfejsu NET_LAB &nbsp;nasz interfejs publiczny oraz przechodzimy do konfiguracji <strong>Profilu<\/strong> po\u0142\u0105czenie klikaj\u0105c <strong>Add<\/strong><\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec02.png\" rel=\"attachment wp-att-657\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"657\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/attachment\/asa_ipsec02\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec02.png?fit=561%2C359&amp;ssl=1\" data-orig-size=\"561,359\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"asa_ipsec02\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec02.png?fit=561%2C359&amp;ssl=1\" class=\"alignnone size-full wp-image-657\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec02.png?resize=561%2C359\" alt=\"asa_ipsec02\" width=\"561\" height=\"359\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec02.png?w=561&amp;ssl=1 561w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec02.png?resize=300%2C192&amp;ssl=1 300w\" sizes=\"auto, (max-width: 561px) 100vw, 561px\" \/><\/a><\/p>\n<p>CLI:<\/p>\n<pre class=\"lang:sh decode:true \">crypto ikev1 enable NET_LAB<\/pre>\n<p>w nowym oknie konfigurujemy parametry naszego po\u0142\u0105czenia <strong>IPSEC,&nbsp;<\/strong>w polach:<\/p>\n<p>Peer IP Address wpisujemy adres Palo, Local Network oraz Remote Network wpisujemy ip pomi\u0119dzy kt\u00f3rymi b\u0119dzie szyfrowanie IPSEC<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec03.png\" rel=\"attachment wp-att-656\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"656\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/attachment\/asa_ipsec03\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec03.png?fit=784%2C772&amp;ssl=1\" data-orig-size=\"784,772\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"asa_ipsec03\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec03.png?fit=770%2C758&amp;ssl=1\" class=\"alignnone size-full wp-image-656\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec03.png?resize=770%2C758\" alt=\"asa_ipsec03\" width=\"770\" height=\"758\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec03.png?w=784&amp;ssl=1 784w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec03.png?resize=300%2C295&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec03.png?resize=768%2C756&amp;ssl=1 768w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><\/p>\n<p>w polu Group Policy Name wybieramy Manage gdzie tworzymy profil dla naszego profilu.<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec05.png\" rel=\"attachment wp-att-654\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"654\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/attachment\/asa_ipsec05\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec05.png?fit=760%2C263&amp;ssl=1\" data-orig-size=\"760,263\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"asa_ipsec05\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec05.png?fit=760%2C263&amp;ssl=1\" class=\"alignnone size-full wp-image-654\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec05.png?resize=760%2C263\" alt=\"asa_ipsec05\" width=\"760\" height=\"263\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec05.png?w=760&amp;ssl=1 760w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec05.png?resize=300%2C104&amp;ssl=1 300w\" sizes=\"auto, (max-width: 760px) 100vw, 760px\" \/><\/a><\/p>\n<p>Tworzymy nowe IKE Policy<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec08.png\" rel=\"attachment wp-att-651\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"651\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/attachment\/asa_ipsec08\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec08.png?fit=644%2C349&amp;ssl=1\" data-orig-size=\"644,349\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"asa_ipsec08\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec08.png?fit=644%2C349&amp;ssl=1\" class=\"alignnone size-full wp-image-651\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec08.png?resize=644%2C349\" alt=\"asa_ipsec08\" width=\"644\" height=\"349\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec08.png?w=644&amp;ssl=1 644w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec08.png?resize=300%2C163&amp;ssl=1 300w\" sizes=\"auto, (max-width: 644px) 100vw, 644px\" \/><\/a><\/p>\n<p>wybieramy odpowiedni\u0105 polityk\u0119 IPSEC<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec09.png\" rel=\"attachment wp-att-650\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"650\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/attachment\/asa_ipsec09\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec09.png?fit=562%2C325&amp;ssl=1\" data-orig-size=\"562,325\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"asa_ipsec09\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec09.png?fit=562%2C325&amp;ssl=1\" class=\"alignnone size-full wp-image-650\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec09.png?resize=562%2C325\" alt=\"asa_ipsec09\" width=\"562\" height=\"325\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec09.png?w=562&amp;ssl=1 562w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec09.png?resize=300%2C173&amp;ssl=1 300w\" sizes=\"auto, (max-width: 562px) 100vw, 562px\" \/><\/a><\/p>\n<p>Przechodzimy do Advanced &#8211;&gt; Crypto Map Entry &nbsp;gdzie ustawiamy nasze parametry<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec10.png\" rel=\"attachment wp-att-649\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"649\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/attachment\/asa_ipsec10\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec10.png?fit=773%2C765&amp;ssl=1\" data-orig-size=\"773,765\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"asa_ipsec10\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec10.png?fit=770%2C762&amp;ssl=1\" class=\"alignnone size-full wp-image-649\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec10.png?resize=770%2C762\" alt=\"asa_ipsec10\" width=\"770\" height=\"762\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec10.png?w=773&amp;ssl=1 773w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec10.png?resize=300%2C297&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec10.png?resize=768%2C760&amp;ssl=1 768w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><\/p>\n<p>CLI<\/p>\n<pre class=\"lang:sh decode:true\">\/\/Tworzymy ACL'k\u0119 kt\u00f3ra b\u0119dzie u\u017cyta do krypto mapy\naccess-list NET_LAB_cryptomap extended permit ip 172.16.1.0 255.255.255.0 10.20.10.0 255.255.255.0\n\/\/ Tworzymy profil dla fazy 1\ncrypto ikev1 policy 10\n authentication pre-share\n encryption aes-256\n hash sha\n group 2\n lifetime 86400\n\n\/\/Tworzymy profil Group Policy\ngroup-policy IPSEC-PALO internal\ngroup-policy IPSEC-PALO attributes\n vpn-tunnel-protocol ikev1\n\n\/\/Configuracja Crypto mapy \ncrypto map NET_LAB_map2 1 match address NET_LAB_cryptomap\ncrypto map NET_LAB_map2 1 set pfs \ncrypto map NET_LAB_map2 1 set peer 192.168.1.51 \ncrypto map NET_LAB_map2 1 set ikev1 transform-set ESP-AES-256-SHA\ncrypto map NET_LAB_map2 1 set nat-t-disable\ncrypto map NET_LAB_map2 interface NET_LAB\n\n\/\/Profil Tunelu \ntunnel-group 192.168.1.51 type ipsec-l2l\ntunnel-group 192.168.1.51 general-attributes\n default-group-policy IPSEC-PALO\ntunnel-group 192.168.1.51 ipsec-attributes\n ikev1 pre-shared-key Qwert6<\/pre>\n<p>Tworzymy Polityk\u0119 NAT aby ruch nie by\u0142 nigdy NATOWANY<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec11.png\" rel=\"attachment wp-att-670\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"670\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/attachment\/asa_ipsec11\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec11.png?fit=1161%2C782&amp;ssl=1\" data-orig-size=\"1161,782\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"asa_ipsec11\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec11.png?fit=770%2C519&amp;ssl=1\" class=\"alignnone size-full wp-image-670\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec11.png?resize=770%2C519\" alt=\"asa_ipsec11\" width=\"770\" height=\"519\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec11.png?w=1161&amp;ssl=1 1161w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec11.png?resize=300%2C202&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec11.png?resize=768%2C517&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec11.png?resize=1024%2C690&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec11.png?resize=272%2C182&amp;ssl=1 272w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><\/p>\n<p>CLI<\/p>\n<pre class=\"lang:sh decode:true\">object network Net_172.16.1.0\n subnet 172.16.1.0 255.255.255.0\nobject network NET_10.20.10.0\n subnet 10.20.10.0 255.255.255.0\n\nnat (LAN,NET_LAB) source static Net_172.16.1.0 Net_172.16.1.0 destination static NET_10.20.10.0 NET_10.20.10.0<\/pre>\n<p>&nbsp;<\/p>\n<h4>Konfiguracja PALO<\/h4>\n<p>przechodzimy do&nbsp;<strong>network &#8211;&gt; network-profiles &#8211;&gt; ike-crypto<\/strong> tworzymy profil dla naszego po\u0142\u0105czenia<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec01.png\" rel=\"attachment wp-att-668\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"668\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/attachment\/palo_ipsec01\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec01.png?fit=810%2C399&amp;ssl=1\" data-orig-size=\"810,399\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"palo_ipsec01\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec01.png?fit=770%2C379&amp;ssl=1\" class=\"alignnone size-full wp-image-668\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec01.png?resize=770%2C379\" alt=\"palo_ipsec01\" width=\"770\" height=\"379\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec01.png?w=810&amp;ssl=1 810w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec01.png?resize=300%2C148&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec01.png?resize=768%2C378&amp;ssl=1 768w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><\/p>\n<p>CLI<\/p>\n<pre class=\"lang:sh decode:true \">set network ike crypto-profiles ike-crypto-profiles IKE-ASA hash sha1\nset network ike crypto-profiles ike-crypto-profiles IKE-ASA dh-group group2\nset network ike crypto-profiles ike-crypto-profiles IKE-ASA encryption aes-256-cbc\nset network ike crypto-profiles ike-crypto-profiles IKE-ASA lifetime hours 24\n<\/pre>\n<p>przechodzimy do<strong>&nbsp;network &#8211;&gt; network-profiles &#8211;&gt; ipsec-crypto&nbsp;<\/strong>tworzymy profil dla kt\u00f3ry u\u017cyjemy podczas konfiguracji fazy 2<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec02.png\" rel=\"attachment wp-att-667\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"667\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/attachment\/palo_ipsec02-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec02.png?fit=817%2C438&amp;ssl=1\" data-orig-size=\"817,438\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"palo_ipsec02\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec02.png?fit=770%2C413&amp;ssl=1\" class=\"alignnone size-full wp-image-667\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec02.png?resize=770%2C413\" alt=\"palo_ipsec02\" width=\"770\" height=\"413\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec02.png?w=817&amp;ssl=1 817w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec02.png?resize=300%2C161&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec02.png?resize=768%2C412&amp;ssl=1 768w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><\/p>\n<p>CLI<\/p>\n<pre class=\"lang:sh decode:true\">set network ike crypto-profiles ipsec-crypto-profiles Ipsec-asa esp authentication sha1\nset network ike crypto-profiles ipsec-crypto-profiles Ipsec-asa esp encryption aes-256-cbc\nset network ike crypto-profiles ipsec-crypto-profiles Ipsec-asa lifetime hours 8\nset network ike crypto-profiles ipsec-crypto-profiles Ipsec-asa dh-group group2<\/pre>\n<p>w kolejnym kroku przechodzimy do&nbsp;<strong>network &#8211;&gt; network-profiles &#8211;&gt; ike-gateways&nbsp;<\/strong>jest to konfiguracja Fazy 1<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec03.png\" rel=\"attachment wp-att-666\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"666\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/attachment\/palo_ipsec03-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec03.png?fit=613%2C468&amp;ssl=1\" data-orig-size=\"613,468\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"palo_ipsec03\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec03.png?fit=613%2C468&amp;ssl=1\" class=\"alignnone size-full wp-image-666\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec03.png?resize=613%2C468\" alt=\"palo_ipsec03\" width=\"613\" height=\"468\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec03.png?w=613&amp;ssl=1 613w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec03.png?resize=300%2C229&amp;ssl=1 300w\" sizes=\"auto, (max-width: 613px) 100vw, 613px\" \/><\/a><\/p>\n<p>w <strong>Advanced Options<\/strong>:<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec04.png\" rel=\"attachment wp-att-665\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"665\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/attachment\/palo_ipsec04-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec04.png?fit=610%2C444&amp;ssl=1\" data-orig-size=\"610,444\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"palo_ipsec04\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec04.png?fit=610%2C444&amp;ssl=1\" class=\"alignnone size-full wp-image-665\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec04.png?resize=610%2C444\" alt=\"palo_ipsec04\" width=\"610\" height=\"444\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec04.png?w=610&amp;ssl=1 610w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec04.png?resize=300%2C218&amp;ssl=1 300w\" sizes=\"auto, (max-width: 610px) 100vw, 610px\" \/><\/a><\/p>\n<p>CLI<\/p>\n<pre class=\"lang:sh decode:true\">set network ike gateway VPN-ASA authentication pre-shared-key key Qwert6\nset network ike gateway VPN-ASA protocol ikev1 dpd enable no\nset network ike gateway VPN-ASA protocol ikev1 ike-crypto-profile IKE-ASA\nset network ike gateway VPN-ASA protocol ikev1 exchange-mode main\nset network ike gateway VPN-ASA protocol ikev2 dpd enable yes\nset network ike gateway VPN-ASA protocol-common nat-traversal enable no\nset network ike gateway VPN-ASA protocol-common fragmentation enable no\nset network ike gateway VPN-ASA local-address interface ethernet1\/1\nset network ike gateway VPN-ASA peer-address ip 192.168.1.80<\/pre>\n<p>Tworzymy interfejs <strong>Tunnel.1<\/strong> z przypisanie do <strong>Security Zone&nbsp;VPN<\/strong><\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec11.png\" rel=\"attachment wp-att-669\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"669\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/attachment\/palo_ipsec11\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec11.png?fit=872%2C549&amp;ssl=1\" data-orig-size=\"872,549\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"palo_ipsec11\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec11.png?fit=770%2C485&amp;ssl=1\" class=\"alignnone size-full wp-image-669\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec11.png?resize=770%2C485\" alt=\"palo_ipsec11\" width=\"770\" height=\"485\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec11.png?w=872&amp;ssl=1 872w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec11.png?resize=300%2C189&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec11.png?resize=768%2C484&amp;ssl=1 768w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><\/p>\n<p>CLI<\/p>\n<pre class=\"lang:sh decode:true\">set network interface tunnel units tunnel.1\nset zone VPN network layer3 tunnel.1<\/pre>\n<p>tworzymy konfiguracj\u0119 dla Fazy 2 przechodz\u0105c do&nbsp;<strong>network &#8211;&gt; ipsec-tunnels&nbsp;<\/strong>w polu <strong>Tunnel Interface<\/strong> wybieramy nasz interfejs <strong>tunnel.1&nbsp;<\/strong> w <strong>IKE Gataway<\/strong> nasz profil kt\u00f3ry wcze\u015bniej stworzyli\u015bmy <strong>VPN-ASA<\/strong> oraz <strong>IPSec Crypo Profile Ipsec-asa<\/strong><\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec05.png\" rel=\"attachment wp-att-664\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"664\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/attachment\/palo_ipsec05-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec05.png?fit=734%2C331&amp;ssl=1\" data-orig-size=\"734,331\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"palo_ipsec05\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec05.png?fit=734%2C331&amp;ssl=1\" class=\"alignnone size-full wp-image-664\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec05.png?resize=734%2C331\" alt=\"palo_ipsec05\" width=\"734\" height=\"331\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec05.png?w=734&amp;ssl=1 734w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec05.png?resize=300%2C135&amp;ssl=1 300w\" sizes=\"auto, (max-width: 734px) 100vw, 734px\" \/><\/a><\/p>\n<p>w <strong>proxy ID&#8217;s<\/strong> ustawiamy nasz\u0105 konfiguracj\u0119 r\u00f3wnie\u017c<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec06.png\" rel=\"attachment wp-att-663\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"663\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/attachment\/palo_ipsec06-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec06.png?fit=731%2C475&amp;ssl=1\" data-orig-size=\"731,475\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"palo_ipsec06\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec06.png?fit=731%2C475&amp;ssl=1\" class=\"alignnone size-full wp-image-663\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec06.png?resize=731%2C475\" alt=\"palo_ipsec06\" width=\"731\" height=\"475\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec06.png?w=731&amp;ssl=1 731w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec06.png?resize=300%2C195&amp;ssl=1 300w\" sizes=\"auto, (max-width: 731px) 100vw, 731px\" \/><\/a><\/p>\n<p>CLI<\/p>\n<pre class=\"lang:sh decode:true \">set network tunnel ipsec tunel-asa auto-key ike-gateway VPN-ASA \nset network tunnel ipsec tunel-asa auto-key proxy-id asa-palo protocol any \nset network tunnel ipsec tunel-asa auto-key proxy-id asa-palo local 10.20.10.0\/24\nset network tunnel ipsec tunel-asa auto-key proxy-id asa-palo remote 172.16.1.0\/24\nset network tunnel ipsec tunel-asa auto-key ipsec-crypto-profile Ipsec-asa\nset network tunnel ipsec tunel-asa tunnel-monitor enable no\nset network tunnel ipsec tunel-asa tunnel-interface tunnel.1\nset network tunnel ipsec tunel-asa anti-replay no<\/pre>\n<p>Dodajemy <strong>routing<\/strong> do sieci po stronie ASY przechodzimy do&nbsp;<strong>network &#8211;&gt; virtual-routers<\/strong><\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec10.png\" rel=\"attachment wp-att-659\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"659\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/attachment\/palo_ipsec10\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec10.png?fit=1363%2C687&amp;ssl=1\" data-orig-size=\"1363,687\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"palo_ipsec10\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec10.png?fit=770%2C388&amp;ssl=1\" class=\"alignnone size-full wp-image-659\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec10.png?resize=770%2C388\" alt=\"palo_ipsec10\" width=\"770\" height=\"388\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec10.png?w=1363&amp;ssl=1 1363w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec10.png?resize=300%2C151&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec10.png?resize=768%2C387&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec10.png?resize=1024%2C516&amp;ssl=1 1024w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><\/p>\n<p>CLI<\/p>\n<pre class=\"lang:sh decode:true \">set network virtual-router default routing-table ip static-route Route-toASA interface tunnel.1\nset network virtual-router default routing-table ip static-route Route-toASA metric 10\nset network virtual-router default routing-table ip static-route Route-toASA destination 172.16.1.0\/24<\/pre>\n<h3>Weryfikujemy po\u0142\u0105czenia<\/h3>\n<h4>Cisco ASA<\/h4>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec12.png\" rel=\"attachment wp-att-671\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"671\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/attachment\/asa_ipsec12\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec12.png?fit=1567%2C899&amp;ssl=1\" data-orig-size=\"1567,899\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"asa_ipsec12\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec12.png?fit=770%2C441&amp;ssl=1\" class=\"alignnone size-full wp-image-671\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec12.png?resize=770%2C442\" alt=\"asa_ipsec12\" width=\"770\" height=\"442\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec12.png?w=1567&amp;ssl=1 1567w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec12.png?resize=300%2C172&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec12.png?resize=768%2C441&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/asa_ipsec12.png?resize=1024%2C587&amp;ssl=1 1024w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><\/p>\n<p>CLI<\/p>\n<p>Faza1:<\/p>\n<pre class=\"lang:sh decode:true\"># show crypto isakmp sa detail \n\nIKEv1 SAs:\n\n   Active SA: 1\n    Rekey SA: 0 (A tunnel will report 1 Active and 1 Rekey SA during rekey)\nTotal IKE SA: 1\n\n1   IKE Peer: 192.168.1.51\n    Type    : L2L             Role    : initiator \n    Rekey   : no              State   : MM_ACTIVE \n    Encrypt : aes-256         Hash    : SHA       \n    Auth    : preshared       Lifetime: 86400\n    Lifetime Remaining: 86380\n\nThere are no IKEv2 SAs\n\n<\/pre>\n<p>Faza 2<\/p>\n<pre class=\"lang:sh decode:true \"># show ipsec sa detail \ninterface: NET_LAB\n    Crypto map tag: NET_LAB_map2, seq num: 1, local addr: 192.168.1.80\n\n      access-list NET_LAB_cryptomap extended permit ip 172.16.1.0 255.255.255.0 10.20.10.0 255.255.255.0 \n      local ident (addr\/mask\/prot\/port): (172.16.1.0\/255.255.255.0\/0\/0)\n      remote ident (addr\/mask\/prot\/port): (10.20.10.0\/255.255.255.0\/0\/0)\n      current_peer: 192.168.1.51\n\n\n      #pkts encaps: 3, #pkts encrypt: 3, #pkts digest: 3\n      #pkts decaps: 3, #pkts decrypt: 3, #pkts verify: 3\n      #pkts compressed: 0, #pkts decompressed: 0\n      #pkts not compressed: 3, #pkts comp failed: 0, #pkts decomp failed: 0\n      #pre-frag successes: 0, #pre-frag failures: 0, #fragments created: 0\n      #PMTUs sent: 0, #PMTUs rcvd: 0, #decapsulated frgs needing reassembly: 0\n      #TFC rcvd: 0, #TFC sent: 0\n      #Valid ICMP Errors rcvd: 0, #Invalid ICMP Errors rcvd: 0\n      #pkts no sa (send): 0, #pkts invalid sa (rcv): 0\n      #pkts encaps failed (send): 0, #pkts decaps failed (rcv): 0\n      #pkts invalid prot (rcv): 0, #pkts verify failed: 0\n      #pkts invalid identity (rcv): 0, #pkts invalid len (rcv): 0\n      #pkts invalid pad (rcv): 0,\n      #pkts invalid ip version (rcv): 0,\n      #pkts replay rollover (send): 0, #pkts replay rollover (rcv): 0\n      #pkts replay failed (rcv): 0\n      #pkts min mtu frag failed (send): 0, #pkts bad frag offset (rcv): 0\n      #pkts internal err (send): 0, #pkts internal err (rcv): 0\n\n      local crypto endpt.: 192.168.1.80\/0, remote crypto endpt.: 192.168.1.51\/0\n      path mtu 1500, ipsec overhead 74(44), media mtu 1500\n      PMTU time remaining (sec): 0, DF policy: copy-df\n      ICMP error validation: disabled, TFC packets: disabled\n      current outbound spi: A1AD74BD\n      current inbound spi : 9F115119\n\n    inbound esp sas:\n      spi: 0x9F115119 (2668712217)\n         transform: esp-aes-256 esp-sha-hmac no compression \n         in use settings ={L2L, Tunnel, PFS Group 2, IKEv1, }\n         slot: 0, conn_id: 81920, crypto-map: NET_LAB_map2\n         sa timing: remaining key lifetime (sec): 28567\n         IV size: 16 bytes\n         replay detection support: Y\n         Anti replay bitmap: \n          0x00000000 0x0000000F\n    outbound esp sas:\n      spi: 0xA1AD74BD (2712499389)\n         transform: esp-aes-256 esp-sha-hmac no compression \n         in use settings ={L2L, Tunnel, PFS Group 2, IKEv1, }\n         slot: 0, conn_id: 81920, crypto-map: NET_LAB_map2\n         sa timing: remaining key lifetime (sec): 28566\n         IV size: 16 bytes\n         replay detection support: Y\n         Anti replay bitmap: \n          0x00000000 0x00000001\n<\/pre>\n<h4>Weryfikacja ze strony Palo<\/h4>\n<p>W <strong>GUI<\/strong> przechodzimy do&nbsp;<strong>monitor &#8211;&gt; logs &#8211;&gt; system<\/strong> gdzie log filtrujemy:&nbsp;<strong>( subtype eq vpn )<\/strong><\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec12.png\" rel=\"attachment wp-att-672\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"672\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/attachment\/palo_ipsec12\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec12.png?fit=1005%2C508&amp;ssl=1\" data-orig-size=\"1005,508\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"palo_ipsec12\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec12.png?fit=770%2C389&amp;ssl=1\" class=\"alignnone size-full wp-image-672\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec12.png?resize=770%2C389\" alt=\"palo_ipsec12\" width=\"770\" height=\"389\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec12.png?w=1005&amp;ssl=1 1005w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec12.png?resize=300%2C152&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/03\/palo_ipsec12.png?resize=768%2C388&amp;ssl=1 768w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/a><\/p>\n<p>mo\u017cemy te\u017c &nbsp;przej\u015b\u0107 do&nbsp;<strong>network &#8211;&gt; ipsec-tunnels&nbsp;<\/strong>i sprawdzi\u0107 czy kontrolki w kolumnach \u015bwiec\u0105 na zielono, mo\u017cna klikn\u0105\u0107 na nie i zobaczy\u0107 wi\u0119cej szczeg\u00f3\u0142\u00f3w:<\/p>\n<p>&nbsp;<\/p>\n<p>CLI<\/p>\n<p>Faza1<\/p>\n<pre class=\"lang:sh decode:true \">&gt; show vpn ike-sa detail gateway VPN-ASA\n\nIKE Gateway VPN-ASA, ID 1 192.168.1.51           =&gt; 192.168.1.80          \n  Current time: Mar.24 04:04:31\n\nIKE Phase1 SA:\n  Cookie:  8EE57EC6DC0BF7C0:E4C239F89F5E3F8F  Resp\n        State:      Established\n        Mode:       Main\n        Authentication:  PSK\n        Proposal:   AES256-CBC\/SHA1\/DH2\n        NAT:        Not detected\n        Message ID: 0, phase 2: 0\n        Phase 2 SA created : 1\n        Created:    Mar.24 03:51:45, 12 minutes 46 seconds ago\n        Expires:    Mar.25 03:51:45<\/pre>\n<p>Faza 2<\/p>\n<pre class=\"lang:sh decode:true\">&gt; show vpn tunnel name tunel-asa \n\nTnID Name(Gateway)                  Local Proxy IP       Ptl:Port   Remote Proxy IP      Ptl:Port   Proposals                                                   \n---- -------------                  --------------       --------   ---------------      --------   ---------                                                   \n1    tunel-asa:asa-palo(VPN-ASA)    10.20.10.0\/24        0:0        172.16.1.0\/24        0:0        ESP tunl [DH2][AES256][SHA1] 28800-sec                       \n\nShow IPSec tunnel config: Total 1 tunnels found.\n\n\n&gt; show vpn ipsec-sa tunnel tunel-asa:asa-palo \n\nGwID\/client IP  TnID   Peer-Address           Tunnel(Gateway)                                Algorithm          SPI(in)  SPI(out) life(Sec\/KB) \n--------------  ----   ------------           ---------------                                ---------          -------  -------- ------------ \n1               1      192.168.1.80           tunel-asa:asa-palo(VPN-ASA)                    ESP\/A256\/SHA1      A1AD74BD 9F115119 27991\/0       \n\nShow IPSec SA: Total 1 tunnels found. 1 ipsec sa found.\n<\/pre>\n<p>Statystki dla po\u0142\u0105czenia:<\/p>\n<pre class=\"lang:sh decode:true \">&gt; show vpn flow name tunel-asa:asa-palo \n\ntunnel  tunel-asa:asa-palo\n        id:                     1\n        type:                   IPSec\n        gateway id:             1\n        local ip:               192.168.1.51\n        peer ip:                192.168.1.80\n        inner interface:        tunnel.1 \n        outer interface:        ethernet1\/1\n        state:                  active\n        session:                212\n        tunnel mtu:             1428\n        lifetime remain:        27906 sec\n        latest rekey:           894 seconds ago\n        monitor:                off\n          monitor packets seen: 0\n          monitor packets reply:0\n        en\/decap context:       5       \n        local spi:              A1AD74BD\n        remote spi:             9F115119\n        key type:               auto key\n        protocol:               ESP\n        auth algorithm:         SHA1\n        enc  algorithm:         AES256\n        proxy-id:\n          local ip:             10.20.10.0\/24\n          remote ip:            172.16.1.0\/24\n          protocol:             0  \n          local port:           0   \n          remote port:          0\n        anti replay check:      no\n        copy tos:               no\n        authentication errors:  0\n        decryption errors:      0\n        inner packet warnings:  0\n        replay packets:         0\n        packets received \n          when lifetime expired:0\n          when lifesize expired:0\n        sending sequence:       3\n        receive sequence:       0\n        encap packets:          116\n        decap packets:          6\n        encap bytes:            13536\n        decap bytes:            624\n        key acquire requests:   63\n        owner state:            0\n        owner cpuid:            s1dp0\n        ownership:              1<\/pre>\n<p>&nbsp;<\/p>\n<p><a href=\"http:\/\/www.safekom.pl\/blog\/palo-alto\/palo-generator-configow-vpn\/\">W innym po\u015bcie udost\u0119pniam generator Configu IPSec dla PALO<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Poni\u017cej pokazuj\u0119 jak zestawia\u0107 po\u0142\u0105czenie IPsec pomi\u0119dzy PaloAlto Networks a Cisco ASA. W mym przypadku oba urz\u0105dzenia s\u0105 w wersji wirtualnej ale konfiguracja ich odpowiada tak jak by\u015bmy konfigurowali urz\u0105dzenia fizyczne. Za\u0142o\u017cenia: Faza 1 aes256 sha-1 pfs g2 86400s Faza 2 aes256 sha-1 pfs g2 28800s Palo Cisco ASA Sieci kt\u00f3re b\u0119d\u0105 podlega\u0142y szyfrowaniu 10.20.10.0\/24 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":304,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[4,84,78],"tags":[158,13,162,172,179,173,174,77,176,79,81,171,82,175,177,178,30],"class_list":["post-647","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cisco","category-lab","category-palo-alto","tag-asdm","tag-cisco","tag-cisco-asav","tag-cypto","tag-flow","tag-ike-crypto","tag-ike-gateways","tag-ipsec","tag-isakmp","tag-palo","tag-palo-alto-networks","tag-pfs","tag-phase","tag-proxy-ids","tag-subtype-eq-vpn","tag-tunnel","tag-vpn"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>LAB - IPSec Palo - Cisco ASA krok po kroku- SafeKom Blog<\/title>\n<meta name=\"description\" content=\"Konfiguracja krok po kroku IPSec pomi\u0119dzy urz\u0105dzeniami Palo - Cisco ASA. Du\u017ca dawka wiedzy w tym temacie LAB - IPSec Palo - Cisco ASA\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/\" \/>\n<meta property=\"og:locale\" content=\"pl_PL\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"LAB - IPSec Palo - Cisco ASA krok po kroku- SafeKom Blog\" \/>\n<meta property=\"og:description\" content=\"Konfiguracja krok po kroku IPSec pomi\u0119dzy urz\u0105dzeniami Palo - Cisco ASA. Du\u017ca dawka wiedzy w tym temacie LAB - IPSec Palo - Cisco ASA\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/\" \/>\n<meta property=\"og:site_name\" content=\"SafeKom Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/safekompl\" \/>\n<meta property=\"article:published_time\" content=\"2016-03-23T19:19:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-03-25T11:24:04+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1\" \/>\n\t<meta property=\"og:image:width\" content=\"566\" \/>\n\t<meta property=\"og:image:height\" content=\"680\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Micha\u0142 Iwa\u0144czuk\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@MIwaczuk\" \/>\n<meta name=\"twitter:site\" content=\"@MIwaczuk\" \/>\n<meta name=\"twitter:label1\" content=\"Napisane przez\" \/>\n\t<meta name=\"twitter:data1\" content=\"Micha\u0142 Iwa\u0144czuk\" \/>\n\t<meta name=\"twitter:label2\" content=\"Szacowany czas czytania\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minut\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/lab\\\/lab_ipsec_palo_ciscoasa\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/lab\\\/lab_ipsec_palo_ciscoasa\\\/\"},\"author\":{\"name\":\"Micha\u0142 Iwa\u0144czuk\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#\\\/schema\\\/person\\\/fd4cc931b624af4b7353d36d92ba7181\"},\"headline\":\"LAB &#8211; IPSec Palo &#8211; Cisco ASA\",\"datePublished\":\"2016-03-23T19:19:00+00:00\",\"dateModified\":\"2020-03-25T11:24:04+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/lab\\\/lab_ipsec_palo_ciscoasa\\\/\"},\"wordCount\":428,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/lab\\\/lab_ipsec_palo_ciscoasa\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/i0.wp.com\\\/www.safekom.pl\\\/blog\\\/wp-content\\\/uploads\\\/2015\\\/08\\\/Paloalto_logo.png?fit=566%2C680&ssl=1\",\"keywords\":[\"asdm\",\"cisco\",\"cisco asav\",\"cypto\",\"flow\",\"ike-crypto\",\"ike-gateways\",\"ipsec\",\"isakmp\",\"Palo\",\"Palo Alto Networks\",\"pfs\",\"phase\",\"proxy ID's\",\"subtype eq vpn\",\"tunnel\",\"vpn\"],\"articleSection\":[\"Cisco\",\"Lab\",\"Palo Alto\"],\"inLanguage\":\"pl-PL\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/lab\\\/lab_ipsec_palo_ciscoasa\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/lab\\\/lab_ipsec_palo_ciscoasa\\\/\",\"url\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/lab\\\/lab_ipsec_palo_ciscoasa\\\/\",\"name\":\"LAB - IPSec Palo - Cisco ASA krok po kroku- SafeKom Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/lab\\\/lab_ipsec_palo_ciscoasa\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/lab\\\/lab_ipsec_palo_ciscoasa\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/i0.wp.com\\\/www.safekom.pl\\\/blog\\\/wp-content\\\/uploads\\\/2015\\\/08\\\/Paloalto_logo.png?fit=566%2C680&ssl=1\",\"datePublished\":\"2016-03-23T19:19:00+00:00\",\"dateModified\":\"2020-03-25T11:24:04+00:00\",\"description\":\"Konfiguracja krok po kroku IPSec pomi\u0119dzy urz\u0105dzeniami Palo - Cisco ASA. Du\u017ca dawka wiedzy w tym temacie LAB - IPSec Palo - Cisco ASA\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/lab\\\/lab_ipsec_palo_ciscoasa\\\/#breadcrumb\"},\"inLanguage\":\"pl-PL\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/lab\\\/lab_ipsec_palo_ciscoasa\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"pl-PL\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/lab\\\/lab_ipsec_palo_ciscoasa\\\/#primaryimage\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/www.safekom.pl\\\/blog\\\/wp-content\\\/uploads\\\/2015\\\/08\\\/Paloalto_logo.png?fit=566%2C680&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/www.safekom.pl\\\/blog\\\/wp-content\\\/uploads\\\/2015\\\/08\\\/Paloalto_logo.png?fit=566%2C680&ssl=1\",\"width\":566,\"height\":680},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/lab\\\/lab_ipsec_palo_ciscoasa\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Strona g\u0142\u00f3wna\",\"item\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"LAB &#8211; IPSec Palo &#8211; Cisco ASA\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/\",\"name\":\"SafeKom Blog\",\"description\":\"Notatki Architekta i in\u017cyniera zwi\u0105zanego rozwi\u0105zaniami on-prem\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"pl-PL\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#organization\",\"name\":\"SafeKom Blog\",\"url\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pl-PL\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/www.safekom.pl\\\/blog\\\/wp-content\\\/uploads\\\/2015\\\/05\\\/cropped-logo.png?fit=512%2C512&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/www.safekom.pl\\\/blog\\\/wp-content\\\/uploads\\\/2015\\\/05\\\/cropped-logo.png?fit=512%2C512&ssl=1\",\"width\":512,\"height\":512,\"caption\":\"SafeKom Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/safekompl\",\"https:\\\/\\\/x.com\\\/MIwaczuk\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/michaliwanczuk\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#\\\/schema\\\/person\\\/fd4cc931b624af4b7353d36d92ba7181\",\"name\":\"Micha\u0142 Iwa\u0144czuk\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pl-PL\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/cc6dda4ee8d21d1f254147e5ee6f5e38881b88a4a12a5774ca42380597e52014?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/cc6dda4ee8d21d1f254147e5ee6f5e38881b88a4a12a5774ca42380597e52014?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/cc6dda4ee8d21d1f254147e5ee6f5e38881b88a4a12a5774ca42380597e52014?s=96&d=mm&r=g\",\"caption\":\"Micha\u0142 Iwa\u0144czuk\"},\"description\":\"Pasjonat komputerowy od zawsze oraz maniak w zakresie sieci, wirtualizacji oraz bezpiecze\u0144stwa IT. Kompetentny in\u017cynier z du\u017cym do\u015bwiadczeniem w realizacji projekt\u00f3w informatycznych i telekomunikacyjnych. Wieloletni administrator IT, kt\u00f3ry utrzymuje systemy informatyczne dostosowuj\u0105c je do wymog\u00f3w biznesowych z zapewnieniem dost\u0119pno\u015bci 24\\\/7\\\/365.\",\"url\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/author\\\/admin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"LAB - IPSec Palo - Cisco ASA krok po kroku- SafeKom Blog","description":"Konfiguracja krok po kroku IPSec pomi\u0119dzy urz\u0105dzeniami Palo - Cisco ASA. Du\u017ca dawka wiedzy w tym temacie LAB - IPSec Palo - Cisco ASA","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/","og_locale":"pl_PL","og_type":"article","og_title":"LAB - IPSec Palo - Cisco ASA krok po kroku- SafeKom Blog","og_description":"Konfiguracja krok po kroku IPSec pomi\u0119dzy urz\u0105dzeniami Palo - Cisco ASA. Du\u017ca dawka wiedzy w tym temacie LAB - IPSec Palo - Cisco ASA","og_url":"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/","og_site_name":"SafeKom Blog","article_publisher":"https:\/\/www.facebook.com\/safekompl","article_published_time":"2016-03-23T19:19:00+00:00","article_modified_time":"2020-03-25T11:24:04+00:00","og_image":[{"width":566,"height":680,"url":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1","type":"image\/png"}],"author":"Micha\u0142 Iwa\u0144czuk","twitter_card":"summary_large_image","twitter_creator":"@MIwaczuk","twitter_site":"@MIwaczuk","twitter_misc":{"Napisane przez":"Micha\u0142 Iwa\u0144czuk","Szacowany czas czytania":"7 minut"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/#article","isPartOf":{"@id":"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/"},"author":{"name":"Micha\u0142 Iwa\u0144czuk","@id":"https:\/\/www.safekom.pl\/blog\/#\/schema\/person\/fd4cc931b624af4b7353d36d92ba7181"},"headline":"LAB &#8211; IPSec Palo &#8211; Cisco ASA","datePublished":"2016-03-23T19:19:00+00:00","dateModified":"2020-03-25T11:24:04+00:00","mainEntityOfPage":{"@id":"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/"},"wordCount":428,"commentCount":0,"publisher":{"@id":"https:\/\/www.safekom.pl\/blog\/#organization"},"image":{"@id":"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1","keywords":["asdm","cisco","cisco asav","cypto","flow","ike-crypto","ike-gateways","ipsec","isakmp","Palo","Palo Alto Networks","pfs","phase","proxy ID's","subtype eq vpn","tunnel","vpn"],"articleSection":["Cisco","Lab","Palo Alto"],"inLanguage":"pl-PL","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/","url":"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/","name":"LAB - IPSec Palo - Cisco ASA krok po kroku- SafeKom Blog","isPartOf":{"@id":"https:\/\/www.safekom.pl\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/#primaryimage"},"image":{"@id":"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1","datePublished":"2016-03-23T19:19:00+00:00","dateModified":"2020-03-25T11:24:04+00:00","description":"Konfiguracja krok po kroku IPSec pomi\u0119dzy urz\u0105dzeniami Palo - Cisco ASA. Du\u017ca dawka wiedzy w tym temacie LAB - IPSec Palo - Cisco ASA","breadcrumb":{"@id":"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/#breadcrumb"},"inLanguage":"pl-PL","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/"]}]},{"@type":"ImageObject","inLanguage":"pl-PL","@id":"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/#primaryimage","url":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1","contentUrl":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1","width":566,"height":680},{"@type":"BreadcrumbList","@id":"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Strona g\u0142\u00f3wna","item":"https:\/\/www.safekom.pl\/blog\/"},{"@type":"ListItem","position":2,"name":"LAB &#8211; IPSec Palo &#8211; Cisco ASA"}]},{"@type":"WebSite","@id":"https:\/\/www.safekom.pl\/blog\/#website","url":"https:\/\/www.safekom.pl\/blog\/","name":"SafeKom Blog","description":"Notatki Architekta i in\u017cyniera zwi\u0105zanego rozwi\u0105zaniami on-prem","publisher":{"@id":"https:\/\/www.safekom.pl\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.safekom.pl\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"pl-PL"},{"@type":"Organization","@id":"https:\/\/www.safekom.pl\/blog\/#organization","name":"SafeKom Blog","url":"https:\/\/www.safekom.pl\/blog\/","logo":{"@type":"ImageObject","inLanguage":"pl-PL","@id":"https:\/\/www.safekom.pl\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/05\/cropped-logo.png?fit=512%2C512&ssl=1","contentUrl":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/05\/cropped-logo.png?fit=512%2C512&ssl=1","width":512,"height":512,"caption":"SafeKom Blog"},"image":{"@id":"https:\/\/www.safekom.pl\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/safekompl","https:\/\/x.com\/MIwaczuk","https:\/\/www.linkedin.com\/in\/michaliwanczuk\/"]},{"@type":"Person","@id":"https:\/\/www.safekom.pl\/blog\/#\/schema\/person\/fd4cc931b624af4b7353d36d92ba7181","name":"Micha\u0142 Iwa\u0144czuk","image":{"@type":"ImageObject","inLanguage":"pl-PL","@id":"https:\/\/secure.gravatar.com\/avatar\/cc6dda4ee8d21d1f254147e5ee6f5e38881b88a4a12a5774ca42380597e52014?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/cc6dda4ee8d21d1f254147e5ee6f5e38881b88a4a12a5774ca42380597e52014?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/cc6dda4ee8d21d1f254147e5ee6f5e38881b88a4a12a5774ca42380597e52014?s=96&d=mm&r=g","caption":"Micha\u0142 Iwa\u0144czuk"},"description":"Pasjonat komputerowy od zawsze oraz maniak w zakresie sieci, wirtualizacji oraz bezpiecze\u0144stwa IT. Kompetentny in\u017cynier z du\u017cym do\u015bwiadczeniem w realizacji projekt\u00f3w informatycznych i telekomunikacyjnych. Wieloletni administrator IT, kt\u00f3ry utrzymuje systemy informatyczne dostosowuj\u0105c je do wymog\u00f3w biznesowych z zapewnieniem dost\u0119pno\u015bci 24\/7\/365.","url":"https:\/\/www.safekom.pl\/blog\/author\/admin\/"}]}},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1","jetpack_shortlink":"https:\/\/wp.me\/p7i9ri-ar","jetpack-related-posts":[{"id":171,"url":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ipsec-juniper-srx-cisco-router\/","url_meta":{"origin":647,"position":0},"title":"Lab &#8211; IPSEC Juniper SRX &#8211; Cisco router","author":"Micha\u0142 Iwa\u0144czuk","date":"21.08.2015","format":false,"excerpt":"Dzi\u015b postanowi\u0142em opisa\u0107 troch\u0119 labowania, temat ostatnio bardzo mocno przerabiany IPSEC. Poni\u017cej opisz\u0119 wariant policy base vpn, kt\u00f3ry jest bardzo elastyczny. Za\u0142o\u017cenia: Faza 1 aes256 sha-1 pfs g2 3600s Faza 2 aes256 sha-1 pfs g2 3600s Cisco Juniper SRX Sieci kt\u00f3re b\u0119d\u0105 podlega\u0142y szyfrowaniu 172.16.10.0\/24 10.10.10.0\/24 Cisco Juniper SRX Interfejs\u2026","rel":"","context":"W \u201eCisco&quot;","block_context":{"text":"Cisco","link":"https:\/\/www.safekom.pl\/blog\/category\/cisco\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/junos_multicolor_burst.png?fit=361%2C393&ssl=1&resize=350%2C200","width":350,"height":200},"classes":[]},{"id":292,"url":"https:\/\/www.safekom.pl\/blog\/juniper\/lab-ipsec-srx-palo\/","url_meta":{"origin":647,"position":1},"title":"LAB &#8211; IPSEC SRX  PALO","author":"Micha\u0142 Iwa\u0144czuk","date":"30.08.2015","format":false,"excerpt":"Dzi\u015b przyszed\u0142 czas na lab z wykorzystaniem urz\u0105dze\u0144 Juniper SRX oraz Palo Alto Networks. Skupi\u0119 si\u0119 w tym wpisie na skonfigurowaniu po\u0142\u0105czenia VPN Ipsec pomi\u0119dzy tymi urz\u0105dzeniami. za\u0142o\u017cenia: Faza 1 aes256 sha-1 pfs g2 3600s Faza 2 aes256 sha-1 pfs g2 3600s Palo SRX Sieci kt\u00f3re b\u0119d\u0105 podlega\u0142y szyfrowaniu 10.20.10.0\/24\u2026","rel":"","context":"W \u201eJuniper&quot;","block_context":{"text":"Juniper","link":"https:\/\/www.safekom.pl\/blog\/category\/juniper\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1&resize=525%2C300 1.5x"},"classes":[]},{"id":2567,"url":"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/","url_meta":{"origin":647,"position":2},"title":"NSX-t IPSec Route base","author":"Micha\u0142 Iwa\u0144czuk","date":"26.03.2020","format":false,"excerpt":"W dzisiejszym wpisie przedstawi\u0119 konfiguracj\u0119 NSX-t IPSec Route base, jest to\u00a0 opis krok po kroku jak skonfigurowa\u0107 IPseca po stronie NSX'a oraz Vyos kt\u00f3ry b\u0119dzie uczestnikiem IPseca.\u00a0 Za\u0142o\u017cenia Poni\u017cej rysunek pogl\u0105dowy jak wygl\u0105da topologia po\u0142\u0105cze\u0144. Pomi\u0119dzy routerem T0 i chmurk\u0105 ju\u017c istnieje po\u0142\u0105czenie oraz jest zestawione s\u0105siedztwo BGP w celu\u2026","rel":"","context":"W \u201eNSX&quot;","block_context":{"text":"NSX","link":"https:\/\/www.safekom.pl\/blog\/category\/vmware\/nsx\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1&resize=700%2C400 2x"},"classes":[]},{"id":457,"url":"https:\/\/www.safekom.pl\/blog\/cisco\/cisco-asa-ograniczenie-dostepu-do-ssl-vpn\/","url_meta":{"origin":647,"position":3},"title":"Cisco ASA &#8211; Ograniczenie dost\u0119pu do SSL VPN oraz IKE","author":"Micha\u0142 Iwa\u0144czuk","date":"30.12.2015","format":false,"excerpt":"Dla szukaj\u0105cych jak ograniczy\u0107 dost\u0119p do us\u0142ug uruchamianych na Cisco ASA, mam na my\u015bli SSL VPN, czy IKE na samy dole jest aktualizacja jak to zrobi\u0107 dla IKE przy podatno\u015bci\u00a0CVE-2016-1287 Poni\u017cej przedstawi\u0119 jak ograniczy\u0107 dost\u0119p do SSL VPN dla okre\u015blonych ip lub sieci. definiujemy Grup\u0119 w kt\u00f3ra b\u0119dzie zawiera\u0107 list\u0119\u2026","rel":"","context":"W \u201eCisco&quot;","block_context":{"text":"Cisco","link":"https:\/\/www.safekom.pl\/blog\/category\/cisco\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/09\/cisco-logo.png?fit=400%2C300&ssl=1&resize=350%2C200","width":350,"height":200},"classes":[]},{"id":610,"url":"https:\/\/www.safekom.pl\/blog\/cisco\/asav-pierwsze-uruchomienie-w-labie\/","url_meta":{"origin":647,"position":4},"title":"ASAv &#8211; pierwsze uruchomienie w labie","author":"Micha\u0142 Iwa\u0144czuk","date":"06.03.2016","format":false,"excerpt":"Pierwsze uruchomienie Cisco ASAv w Labie. Pokazuj\u0119 podstawow\u0105 konfiguracj\u0119 od importu po zalogowanie si\u0119 po ssh lub asdm.","rel":"","context":"W \u201eCisco&quot;","block_context":{"text":"Cisco","link":"https:\/\/www.safekom.pl\/blog\/category\/cisco\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/09\/cisco-logo.png?fit=400%2C300&ssl=1&resize=350%2C200","width":350,"height":200},"classes":[]},{"id":676,"url":"https:\/\/www.safekom.pl\/blog\/palo-alto\/palo-generator-configow-vpn\/","url_meta":{"origin":647,"position":5},"title":"Palo &#8211; Generator config\u00f3w VPN","author":"Micha\u0142 Iwa\u0144czuk","date":"24.03.2016","format":false,"excerpt":"W nap\u0142ywie mocy stworzy\u0142em ma\u0142ego Excela z generatorem konfig\u00f3w po\u0142\u0105cze\u0144 IPSec, jest to na chwil\u0119 wersja uboga ale mam nadziej\u0119 z czasem uda mi si\u0119 doda\u0107 wi\u0119cej funkcji. Na chwil\u0119 obecn\u0105 obs\u0142uguje vpn'y w trybie main z PSK. wersja 0.2 poprawione b\u0142\u0119dy, dodanie opis\u00f3w p\u00f3l, uporz\u0105dkowanie leciutkie. Plik generatora(potrzeba w\u0142\u0105czenia\u2026","rel":"","context":"W \u201ePalo Alto&quot;","block_context":{"text":"Palo Alto","link":"https:\/\/www.safekom.pl\/blog\/category\/palo-alto\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1&resize=525%2C300 1.5x"},"classes":[]}],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/posts\/647","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/comments?post=647"}],"version-history":[{"count":1,"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/posts\/647\/revisions"}],"predecessor-version":[{"id":2577,"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/posts\/647\/revisions\/2577"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/media\/304"}],"wp:attachment":[{"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/media?parent=647"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/categories?post=647"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/tags?post=647"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}