Skip to main content

Configuring Cisco ASA5505 to connect to OPNsense

Minimum version required for IPSECv2 is v8.4 on the Cisco ASA

in v8.4

Available in v8.4

ESP:DES_CBC/HMAC_SHA1_96/NO_EXT_SEQ

from VPN/IPsec/Log from OPNsense

selected08[CFG] proposal:<con2|16> IKE:configured DES_CBC/proposals: HMAC_MD5_96/ESP:AES_CBC_128/HMAC_SHA1_96/NO_EXT_SEQ, PRF_HMAC_MD5/ESP:AES_CBC_128/HMAC_SHA2_256_128/NO_EXT_SEQ, MODP_1024ESP:AES_CBC_128/HMAC_SHA2_384_192/NO_EXT_SEQ, ESP:AES_CBC_128/HMAC_SHA2_512_256/NO_EXT_SEQ, ESP:AES_CBC_128/AES_XCBC_96/NO_EXT_SEQ, ESP:AES_CBC_192/HMAC_SHA1_96/NO_EXT_SEQ, ESP:AES_CBC_192/HMAC_SHA2_256_128/NO_EXT_SEQ, ESP:AES_CBC_192/HMAC_SHA2_384_192/NO_EXT_SEQ, ESP:AES_CBC_192/HMAC_SHA2_512_256/NO_EXT_SEQ, ESP:AES_CBC_192/AES_XCBC_96/NO_EXT_SEQ, ESP:AES_CBC_256/HMAC_SHA1_96/NO_EXT_SEQ, ESP:AES_CBC_256/HMAC_SHA2_256_128/NO_EXT_SEQ, ESP:AES_CBC_256/HMAC_SHA2_384_192/NO_EXT_SEQ, ESP:AES_CBC_256/HMAC_SHA2_512_256/NO_EXT_SEQ, ESP:AES_CBC_256/AES_XCBC_96/NO_EXT_SEQ, ESP:AES_GCM_16_128/NO_EXT_SEQ, ESP:AES_GCM_16_128/NO_EXT_SEQ, ESP:AES_GCM_16_128/NO_EXT_SEQ, ESP:AES_GCM_16_128/NO_EXT_SEQ, ESP:AES_GCM_16_128/NO_EXT_SEQ, ESP:AES_GCM_16_192/NO_EXT_SEQ, ESP:AES_GCM_16_192/NO_EXT_SEQ, ESP:AES_GCM_16_192/NO_EXT_SEQ, ESP:AES_GCM_16_192/NO_EXT_SEQ, ESP:AES_GCM_16_192/NO_EXT_SEQ, ESP:AES_GCM_16_256/NO_EXT_SEQ, ESP:AES_GCM_16_256/NO_EXT_SEQ, ESP:AES_GCM_16_256/NO_EXT_SEQ, ESP:AES_GCM_16_256/NO_EXT_SEQ, ESP:AES_GCM_16_256/NO_EXT_SEQ, ESP:NULL/HMAC_SHA1_96/NO_EXT_SEQ, ESP:NULL/HMAC_SHA2_256_128/NO_EXT_SEQ, ESP:NULL/HMAC_SHA2_384_192/NO_EXT_SEQ, ESP:NULL/HMAC_SHA2_512_256/NO_EXT_SEQ, ESP:NULL/AES_XCBC_96/NO_EXT_SEQ