Configure remote access VPN crypto maps

Firewall Threat Defense automatically generates crypto maps for interfaces with IPsec-IKEv2 protocol enabled. The Crypto Maps page lists these interface groups.

To add or remove interface groups of a remote access VPN policy, click the Access Interface tab.

Procedure


Step 1

Choose Secure Connections > Remote Access VPN.

Step 2

Click the edit icon next to the remote access VPN policy.

Step 3

Click the Advanced tab.

Step 4

In the left pane, click IPsec > Crypto Maps.

Step 5

Select a crypto map in the table and click the edit icon to update the crypto map parameters.

Step 6

In the Edit Crypto Maps dialog box, configure these parameters:

  1. In IKEv2 IPsec Proposals, click + and choose the transform sets to define how to secure tunnel traffic with authentication and encryption.

  2. Check the Enable Reverse Route Injection check box to automatically insert static routes into the routing process for networks and hosts protected by a remote endpoint.

  3. Check the Enable Client Services check box and specify the port number.

    The Client Services server provides HTTPS (SSL) access, enabling Secure Client Downloader to receive software upgrades, profiles, localization and customization files, and other required files. If you enable this option, specify the client services port number. If disabled, users cannot download any files required by Secure Client.

    Note

    You can use the same port as SSL VPN running on the same device. Even if SSL VPN is configured, you must enable this option to allow file downloads over SSL for IPsec-IKEv2 clients.

  4. Check the Enable Perfect Forward Secrecy check box.

    Use Perfect Forward Secrecy (PFS) to generate a unique session key for each encrypted exchange, protecting recorded exchanges from decryption even if endpoint keys are compromised. If enabled, choose a Diffie-Hellman key derivation algorithm for generating the PFS session key from the Modulus Group list.

  5. From the Modulus group drop-down list, choose a modulus group.

    The modulus group specifies the Diffie-Hellman group used to derive a shared secret between two IPsec peers without transmitting it. A larger modulus provides stronger security but requires more processing time. Both peers must use a matching modulus group. Choose a modulus group to allow in the remote access VPN configuration:

    • 1—Diffie-Hellman Group 1 (768-bit modulus)

    • 2—Diffie-Hellman Group 2 (1024-bit modulus)

    • 5—Diffie-Hellman Group 5 (1536-bit modulus, considered good protection for 128-bit keys, but group 14 is better). If you are using AES encryption, use this group (or higher)

    • 14—Diffie-Hellman Group 14 (2048-bit modulus, considered good protection for 128-bit keys)

    • 19—Diffie-Hellman Group 19 (256-bit elliptical curve field size)

    • 20—Diffie-Hellman Group 20 (384-bit elliptical curve field size)

    • 21—Diffie-Hellman Group 21 (521-bit elliptical curve field size)

    • 24—Diffie-Hellman Group 24 (2048-bit modulus and 256-bit prime order subgroup)

  6. In the Lifetime Duration field, enter the lifetime of the security association (SA), in seconds.

    The range is 120 to 2147483647 seconds. The default is 28800 seconds.

    When the lifetime is exceeded, the SA expires and must be renegotiated between the two peers. Shorter lifetimes improve IKE negotiation security, while longer lifetimes allow future IPsec SAs to be established more quickly.

  7. In the Lifetime Size (kbytes) field, enter the volume of traffic (in kilobytes) allowed between IPsec peers before the SA expires.

    The range is 10 to 2147483647 kilobytes. The default is 4,608,000 kilobytes. If you do not specify a value, the SA allows unlimited data.

  8. In ESPv3 Settings, configure these parameters:

    • Check the Validate incoming ICMP error messages check box to validate ICMP error messages received through an IPsec tunnel and destined for a host in the private network.

    • Check the Enable 'Do Not Fragment' Policy check box to define how the IPsec subsystem handles large packets with the do-not-fragment (DF) bit set in the IP header. From the Policy drop-down list, choose one of these options:

      • Set—Sets and uses the DF bit.

      • Copy—Maintains the DF bit.

      • Clear—Ignores the DF bit.

    • Check the Enable Traffic Flow Confidentiality (TFC) Packets check box to send dummy TFC packets that mask the traffic profile traversing the tunnel. Configure the Burst, Payload Size, and Timeout parameters to generate random-length packets at random intervals across the specified SA.

      Note

      Enabling TFC packets prevents the VPN tunnel from being idle, which may cause the VPN idle timeout configured in the group policy to not work as expected.

      • In the Burst field, enter the number of dummy packets to send in one burst. The range is 1 to 16 bytes.

      • In the Payload Size field, enter the size of the dummy packet payload. The range is from 64 to 1024 bytes.

      • In the Timeout field, enter the maximum time between bursts. The range is from 10 to 60 seconds.

  9. Click OK.

Step 7

Click Save.