Site to Site VPN for Beginners.
The two sites are able to access the internet and having static Public IP.
the equation is the sites need to access each other resources securely over the web.
A small example is as below:
Router 1:
Router1#sh running-config
Building configuration...
Current configuration : 1303 bytes
!
version 12.4
no service timestamps log datetime msec
no service timestamps debug datetime msec
no service password-encryption
!
hostname Router1
!
!
!
!
!
!
!
!
ip cef
no ipv6 cef
!
!
!
!
crypto isakmp policy 1
encr aes
authentication pre-share
group 5
lifetime 1800
!
crypto isakmp key nightread3r address 122.1.1.2
!
!
crypto ipsec security-association lifetime seconds 1800
!
crypto ipsec transform-set t-set esp-aes esp-sha-hmac
!
crypto map test 10 ipsec-isakmp
set peer 122.1.1.2
set security-association lifetime seconds 1800
set transform-set t-set
match address 101
!
!
!
!
!
!
spanning-tree mode pvst
!
!
!
!
!
!
interface FastEthernet0/0
ip address 121.1.1.2 255.255.255.252
ip nat outside
duplex auto
speed auto
crypto map test
!
interface FastEthernet0/1
ip address 192.168.10.254 255.255.255.0
ip nat inside
duplex auto
speed auto
!
interface Vlan1
no ip address
shutdown
!
ip nat inside source list natacl interface FastEthernet0/0 overload
ip classless
ip route 0.0.0.0 0.0.0.0 121.1.1.1
!
ip flow-export version 9
!
!
ip access-list extended natacl
deny ip 192.168.10.0 0.0.0.255 192.168.20.0 0.0.0.255
permit ip any any
access-list 101 permit ip 192.168.10.0 0.0.0.255 192.168.20.0 0.0.0.255
!
!
!
!
!
line con 0
!
line aux 0
!
line vty 0 4
login
!
!
!
end
Router1#
Router 2:
Router2#sh running-config
Building configuration...
Current configuration : 1303 bytes
!
version 12.4
no service timestamps log datetime msec
no service timestamps debug datetime msec
no service password-encryption
!
hostname Router2
!
!
!
!
!
!
!
!
ip cef
no ipv6 cef
!
!
!
!
crypto isakmp policy 1
encr aes
authentication pre-share
group 5
lifetime 1800
!
crypto isakmp key nightread3r address 121.1.1.2
!
!
crypto ipsec security-association lifetime seconds 1800
!
crypto ipsec transform-set t-set esp-aes esp-sha-hmac
!
crypto map test 10 ipsec-isakmp
set peer 121.1.1.2
set security-association lifetime seconds 1800
set transform-set t-set
match address 101
!
!
!
!
!
!
spanning-tree mode pvst
!
!
!
!
!
!
interface FastEthernet0/0
ip address 122.1.1.2 255.255.255.252
ip nat outside
duplex auto
speed auto
crypto map test
!
interface FastEthernet0/1
ip address 192.168.20.254 255.255.255.0
ip nat inside
duplex auto
speed auto
!
interface Vlan1
no ip address
shutdown
!
ip nat inside source list natacl interface FastEthernet0/0 overload
ip classless
ip route 0.0.0.0 0.0.0.0 122.1.1.1
!
ip flow-export version 9
!
!
ip access-list extended natacl
deny ip 192.168.20.0 0.0.0.255 192.168.10.0 0.0.0.255
permit ip any any
access-list 101 permit ip 192.168.20.0 0.0.0.255 192.168.10.0 0.0.0.255
!
!
!
!
!
line con 0
!
line aux 0
!
line vty 0 4
login
!
!
!
end
Router2#
Router2 con0 is now available
Press RETURN to get started.
Router2>
Router2>
Router2>
Router2>
Router2 con0 is now available
Press RETURN to get started.
Router2>
Router2>
Router2>
Router2>
Router2>en
Router2>enable
Router2#
Router2#
Router2#sh run
Router2#sh running-config
Building configuration...
Current configuration : 1303 bytes
!
version 12.4
no service timestamps log datetime msec
no service timestamps debug datetime msec
no service password-encryption
!
hostname Router2
!
!
!
!
!
!
!
!
ip cef
no ipv6 cef
!
!
!
!
crypto isakmp policy 1
encr aes
authentication pre-share
group 5
lifetime 1800
!
crypto isakmp key nightread3r address 121.1.1.2
!
!
crypto ipsec security-association lifetime seconds 1800
!
crypto ipsec transform-set t-set esp-aes esp-sha-hmac
!
crypto map test 10 ipsec-isakmp
set peer 121.1.1.2
set security-association lifetime seconds 1800
set transform-set t-set
match address 101
!
!
!
!
!
!
spanning-tree mode pvst
!
!
!
!
!
!
interface FastEthernet0/0
ip address 122.1.1.2 255.255.255.252
ip nat outside
duplex auto
speed auto
crypto map test
!
interface FastEthernet0/1
ip address 192.168.20.254 255.255.255.0
ip nat inside
duplex auto
speed auto
!
interface Vlan1
no ip address
shutdown
!
ip nat inside source list natacl interface FastEthernet0/0 overload
ip classless
ip route 0.0.0.0 0.0.0.0 122.1.1.1
!
ip flow-export version 9
!
!
ip access-list extended natacl
deny ip 192.168.20.0 0.0.0.255 192.168.10.0 0.0.0.255
permit ip any any
access-list 101 permit ip 192.168.20.0 0.0.0.255 192.168.10.0 0.0.0.255
!
!
!
!
!
line con 0
!
line aux 0
!
line vty 0 4
login
!
!
!
end
Router2#
Verification:
ping response from PC1
verification from Router 1:
Presented By: Naresh Mahato
Comments
Post a Comment