Mikrotik To Cisco ASA IPsec VPN - VION Technology Blog

You might also like

Download as pdf or txt
Download as pdf or txt
You are on page 1of 6

Mikrotik to Cisco ASA IPsec VPN - VION Technology Blog

http://www.vionblog.com/mikrotik-to-cisco-asa-ipsec-vpn/

HOME

ABOUT

CONTACT

DOWNLOADS

PRIVACY

Search this site...

Blogging

Database

Development

General

Networking

Telephony

HOME

NETWORKING

MIKROTIK TO CISCO ASA IPSEC VPN

Mikrotik to Cisco ASA IPsec VPN


269 days ago by Nikola Stojanoski 4

We needed to setup IPsec VPN for a client with a remote location that already had Cisco ASA. So, here is a Mikrotik to Cisco ASA IPsec howto.

Tutorial Scenario
Cisco ASA site
WAN: 1.1.1.2/30 (outside) LAN: 192.168.2.1/24 (inside)
YouTube Twitter Facebook RSS Email

Mikrotik site
WAN: 1.1.1.1/30 (ether1) LAN: 192.168.1.1/24 (ether2)

Popular Posts openerp-server.conf for OpenERP 7 explained Install OpenERP 7.0 from trunk

Cisco ASA to Mikrotik configuration


Launch the VPN configuration wizard on your Cisco ASA router Set VPN Tunnel Type as Site-to-Site Meridian Option 11 Programming Manual skip-name-resolve to speed up MySQL and avoid problems Site-to-Site IPSec VPN using Mikrotik Routers VirtualBox 4.2 and phpVirtualBox on Debian Mikrotik to Cisco ASA IPsec VPN Oracle Instant Client and PHP OCI8 on Debian Squeeze OpenERP 7.0 compared to OpenERP 6.1 Zimbra ActiveSync with Z-Push v2

VION Technology Blog


Like 85 people like VION Technology Blog.

Set the Remote Peer IP Address: 1.1.1.1(Mikrotik WAN) and Pre-shared key. Also Tunnel Group Name should be the Remote Peer IP Address.
Facebook social plugin

1 of 6

6/27/2013 3:46 PM

Mikrotik to Cisco ASA IPsec VPN - VION Technology Blog

http://www.vionblog.com/mikrotik-to-cisco-asa-ipsec-vpn/

Tags
Apache

Aria SOHO ASA Blogging chat Cisco

Debian DHCP Door Phone firewall Full-Text Search

iPECS iPECS-LIK iPECS-MG ipLDK IPSec


Hunt Group IM

LG-Ericsson memcached
Mikrotik Mobile MySQL nginx Nortel NTP
pidgin

Meridian

OpenERP Option 11 PBX PC Admin PHP


Set the IKE Policy Encryption to 3DES, Authentication to MD5 and DH Group to 2
Skype SSL VirtualBox VoiceMail VoIP

PostgreSQL Reverse Proxy SIP skip-name-resolve VPN Webmaster

Zimbra

Set the IPsec Encryption to 3DES and Authentication to MD5

2 of 6

6/27/2013 3:46 PM

Mikrotik to Cisco ASA IPsec VPN - VION Technology Blog

http://www.vionblog.com/mikrotik-to-cisco-asa-ipsec-vpn/

Set the Local and Remote Networks

Dont forget to set the IKE Parameters to Identity: Address to avoid connection problems

3 of 6

6/27/2013 3:46 PM

Mikrotik to Cisco ASA IPsec VPN - VION Technology Blog

http://www.vionblog.com/mikrotik-to-cisco-asa-ipsec-vpn/

Mikrotik to Cisco ASA configuration


Create new policy

Create new Peer

Modify the default proposal to accept MD5 as Authentication

4 of 6

6/27/2013 3:46 PM

Mikrotik to Cisco ASA IPsec VPN - VION Technology Blog

http://www.vionblog.com/mikrotik-to-cisco-asa-ipsec-vpn/

Create NAT rule to bypass the traffic that should to trough the tunnel

Move the rule to the top

Now you can connect your branch offices using Mikrotik Routers even if you have Cisco ASAs installed on the other locations. Links: Cisco ASA, Mikrotik Routerboard

Tags: ASA, Cisco, IPSec, Mikrotik, VPN

Nikola Stojanoski
System Administrator and Developer. Giving back to the community by blogging about my problems, solutions and practical howto's.

Related Articles

Setting Mikrotik as IPSec Concentrator

My Mikrotik Initial Setup

Site-to-Site IPSec VPN using Mikrotik Routers

4 Responses to Mikrotik to Cisco ASA IPsec VPN

Damjan Momirovski
December 18, 2012 at 11:34 am Mnogu dobar blog , povekje od korisen :) , bravo za Mrki.
Reply Reply

5 of 6

6/27/2013 3:46 PM

Mikrotik to Cisco ASA IPsec VPN - VION Technology Blog

http://www.vionblog.com/mikrotik-to-cisco-asa-ipsec-vpn/

patriotmk
February 8, 2013 at 2:29 pm , , :)
Reply Reply

Horst Bursik
April 2, 2013 at 1:19 pm You saved my day thank you! :)
Reply Reply

Configurations Mikrotik
April 10, 2013 at 12:26 pm Good post
Reply Reply

Leave a Reply
Name (Required) Mail (will not be published) (Required) Website

71=

2013 VION Technology Blog. All rights reserved.

Bloggers.com

6 of 6

6/27/2013 3:46 PM

You might also like