How to Configure Site to Site VPN on Cisco Routers (2024)

July 27, 2018CCIE, CCIE Security, CCNA Security, Security1 commentHow to Configure Site to Site VPN on Cisco Routers (1)

BR1:

1) Configure the ISAKMP Tunnel From BR1 to BR2 router ( Phase1).

BR1(config)# crypto isakmp policy 1
BR1(config-isakmp)# encryption 3des
BR1(config-isakmp)# hash md5
BR1(config-isakmp)# authentication pre-share
BR1(config-isakmp)# group 2
BR1(config-isakmp)# lifetime 86400

BR1(config)# crypto isakmp key Cisco123 address 1.1.1.2

2) Configure IPSEC Tunnel From BR1 to BR2 router ( Phase2).

BR1(config)# crypto ipsec transform-set BR1toBR2 esp-3des esp-md5-hmac

3) Configure the traffic that need to be encrypted from BR1 to BR2 router ( Interesting Traffic).

BR1(config)# ip access-list extended BR1toBR2ACL
BR1(config-ext-nacl)# permit ip 10.0.0.0 0.255.255.255 20.0.0.0 0.255.255.255

4) Combine all the parameters ( Phase1, Phase 2 and Interesting traffic) using crypto map.

BR1(config)# crypto map BR1 5 ipsec-isakmp
BR1(config-crypto-map)# set peer 1.1.1.2
BR1(config-crypto-map)# set transform-set BR1toBR2
BR1(config-crypto-map)# match address BR1toBR2ACL

5) Apply on the interface which is connected to the Internet or from which traffic goes to the peer router.

BR1(config)# interface g0/1

BR1(config-if)# crypto map BR1

How to Configure Site to Site VPN on Cisco Routers (2)

BR2:

1) Configure the ISAKMP Tunnel From BR2 to BR1 router ( Phase1).

BR2(config)# crypto isakmp policy 1
BR2(config-isakmp)# encryption 3des
BR2(config-isakmp)# hash md5
BR2(config-isakmp)# authentication pre-share
BR2(config-isakmp)# group 2
BR2(config-isakmp)# lifetime 86400

BR2(config)# crypto isakmp key Cisco123 address 1.1.1.1

2) Configure IPsec Tunnel From BR2 to BR1 router ( Phase2).

BR2(config)# crypto ipsec transform-set BR2toBR1 esp-3des esp-md5-hmac

3) Configure the traffic that needs to be encrypted from BR2 to BR1 router ( Interesting Traffic).

BR2(config)# ip access-list extended BR2toBR1ACL
BR2(config-ext-nacl)# permit ip 20.0.0.0 0.255.255.255 10.0.0.0 0.255.255.255

4) Combine all the parameters ( Phase1, Phase 2 and Interesting traffic) using crypto map.

BR2(config)# crypto map BR2 5 ipsec-isakmp
BR2(config-crypto-map)# set peer 1.1.1.1
BR2(config-crypto-map)# set transform-set BR2toBR1
BR2(config-crypto-map)# match address BR2toBR1ACL

5) Apply on the interface which is connected to the Internet or from which traffic goes to the peer router.

BR2(config)# interface g0/1

BR2(config-if)# crypto map BR2

Verification:

BR1# show crypto session

BR2# show crypto session

Note: We can configure onlyone crypto map on each interface if you want to configure multiple site to site tunnels on the same router then you can use Crypto map with different sequence numbers for each tunnel.

Md.Kareemoddin

CCIE # 54759

Ref: Cisco.com

"+y+""}else{if(A==5){c+='

  • How to Configure Site to Site VPN on Cisco Routers (3)'+w+""+y+"
  • "}else{if(A==6){c+='

  • "+w+'

    How to Configure Site to Site VPN on Cisco Routers (4)'+u+""+y+"

  • "}else{c+='

  • "+w+"
  • "}}}}}s.innerHTML=c+=""+y;d.callBack()};randomRelatedIndex=h;showRelatedPost=g;j(d.homePage.replace(/\/$/,"")+"/feeds/posts/summary"+e+"?alt=json-in-script&orderby=updated&max-results=0&callback=randomRelatedIndex")})(window,document,document.getElementsByTagName("head")[0]);//]]>

    How to Configure Site to Site VPN on Cisco Routers (2024)
    Top Articles
    How to Get Your Coinbase Pro API Key and Use It [Full Guide]
    All Eligible Waitlist Members Now Have a Crypto Wallet - Lightning Network is Coming to Robinhood — Under the Hood
    123Movies Encanto
    Palm Coast Permits Online
    Libiyi Sawsharpener
    Ffxiv Palm Chippings
    Euro (EUR), aktuální kurzy měn
    Boomerang Media Group: Quality Media Solutions
    Coffman Memorial Union | U of M Bookstores
    Es.cvs.com/Otchs/Devoted
    Practical Magic 123Movies
    What Auto Parts Stores Are Open
    Stl Craiglist
    Arrests reported by Yuba County Sheriff
    Teamexpress Login
    Fnv Turbo
    Best Cav Commanders Rok
    Hardly Antonyms
    Bros Movie Wiki
    Palace Pizza Joplin
    Studentvue Columbia Heights
    Lancasterfire Live Incidents
    Invert Clipping Mask Illustrator
    Labby Memorial Funeral Homes Leesville Obituaries
    Zoe Mintz Adam Duritz
    Www Craigslist Com Bakersfield
    Hewn New Bedford
    Babbychula
    Watertown Ford Quick Lane
    Culver's.comsummerofsmiles
    Truvy Back Office Login
    Narragansett Bay Cruising - A Complete Guide: Explore Newport, Providence & More
    Farm Equipment Innovations
    Paradise Point Animal Hospital With Veterinarians On-The-Go
    Page 2383 – Christianity Today
    Deepwoken: Best Attunement Tier List - Item Level Gaming
    Robert A McDougal: XPP Tutorial
    Kacey King Ranch
    Fairwinds Shred Fest 2023
    NIST Special Publication (SP) 800-37 Rev. 2 (Withdrawn), Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy
    Sedano's Supermarkets Expands to Orlando - Sedano's Supermarkets
    Lichen - 1.17.0 - Gemsbok! Antler Windchimes! Shoji Screens!
    Snohomish Hairmasters
    Thanksgiving Point Luminaria Promo Code
    Daly City Building Division
    Noaa Marine Weather Forecast By Zone
    No Boundaries Pants For Men
    Top 40 Minecraft mods to enhance your gaming experience
    Rise Meadville Reviews
    Epower Raley's
    ats: MODIFIED PETERBILT 389 [1.31.X] v update auf 1.48 Trucks Mod für American Truck Simulator
    Latest Posts
    Article information

    Author: Dong Thiel

    Last Updated:

    Views: 5985

    Rating: 4.9 / 5 (59 voted)

    Reviews: 82% of readers found this page helpful

    Author information

    Name: Dong Thiel

    Birthday: 2001-07-14

    Address: 2865 Kasha Unions, West Corrinne, AK 05708-1071

    Phone: +3512198379449

    Job: Design Planner

    Hobby: Graffiti, Foreign language learning, Gambling, Metalworking, Rowing, Sculling, Sewing

    Introduction: My name is Dong Thiel, I am a brainy, happy, tasty, lively, splendid, talented, cooperative person who loves writing and wants to share my knowledge and understanding with you.