Lab 1: Site-to-Site IPSec VPN with NAT

CCIE - Practical Implementation of IPsec VPN - Secure DMVPN CCIE - Practical Implementation of IPSEC VPN - Secure DMVPN
29 minutes
Share the link to this page
Copied
  Completed
You need to have access to the item to view this lesson.
One-time Fee
$69.99
List Price:  $99.99
You save:  $30
€64.96
List Price:  €92.81
You save:  €27.84
£55.77
List Price:  £79.68
You save:  £23.90
CA$95.68
List Price:  CA$136.70
You save:  CA$41.01
A$106.02
List Price:  A$151.47
You save:  A$45.44
S$94.41
List Price:  S$134.88
You save:  S$40.47
HK$546.80
List Price:  HK$781.18
You save:  HK$234.37
CHF 63.34
List Price:  CHF 90.49
You save:  CHF 27.15
NOK kr761.11
List Price:  NOK kr1,087.35
You save:  NOK kr326.23
DKK kr485.02
List Price:  DKK kr692.92
You save:  DKK kr207.89
NZ$116.42
List Price:  NZ$166.33
You save:  NZ$49.90
د.إ257.06
List Price:  د.إ367.25
You save:  د.إ110.18
৳7,660.01
List Price:  ৳10,943.35
You save:  ৳3,283.33
₹5,835.78
List Price:  ₹8,337.18
You save:  ₹2,501.40
RM331.75
List Price:  RM473.95
You save:  RM142.20
₦86,437.65
List Price:  ₦123,487.65
You save:  ₦37,050
₨19,416.31
List Price:  ₨27,738.77
You save:  ₨8,322.46
฿2,572.74
List Price:  ฿3,675.50
You save:  ฿1,102.76
₺2,264.43
List Price:  ₺3,235.04
You save:  ₺970.61
B$356.70
List Price:  B$509.60
You save:  B$152.89
R1,295.44
List Price:  R1,850.72
You save:  R555.27
Лв127.05
List Price:  Лв181.51
You save:  Лв54.46
₩94,909.58
List Price:  ₩135,590.93
You save:  ₩40,681.35
₪259.50
List Price:  ₪370.74
You save:  ₪111.23
₱3,993.87
List Price:  ₱5,705.78
You save:  ₱1,711.90
¥10,712.31
List Price:  ¥15,303.96
You save:  ¥4,591.65
MX$1,187.89
List Price:  MX$1,697.07
You save:  MX$509.17
QR254.57
List Price:  QR363.69
You save:  QR109.12
P950.82
List Price:  P1,358.38
You save:  P407.55
KSh9,247.76
List Price:  KSh13,211.65
You save:  KSh3,963.89
E£3,352.12
List Price:  E£4,788.95
You save:  E£1,436.83
ብር4,006.43
List Price:  ብር5,723.72
You save:  ብር1,717.28
Kz58,511.64
List Price:  Kz83,591.64
You save:  Kz25,080
CLP$65,950.47
List Price:  CLP$94,219
You save:  CLP$28,268.52
CN¥506.53
List Price:  CN¥723.64
You save:  CN¥217.11
RD$4,055.76
List Price:  RD$5,794.19
You save:  RD$1,738.43
DA9,420.16
List Price:  DA13,457.95
You save:  DA4,037.79
FJ$157.70
List Price:  FJ$225.30
You save:  FJ$67.59
Q542.52
List Price:  Q775.06
You save:  Q232.54
GY$14,601.52
List Price:  GY$20,860.22
You save:  GY$6,258.69
ISK kr9,764.23
List Price:  ISK kr13,949.49
You save:  ISK kr4,185.26
DH703.98
List Price:  DH1,005.73
You save:  DH301.75
L1,236.34
List Price:  L1,766.28
You save:  L529.93
ден3,998.59
List Price:  ден5,712.52
You save:  ден1,713.92
MOP$561.77
List Price:  MOP$802.57
You save:  MOP$240.79
N$1,291.99
List Price:  N$1,845.78
You save:  N$553.78
C$2,569.36
List Price:  C$3,670.67
You save:  C$1,101.31
रु9,319.09
List Price:  रु13,313.56
You save:  रु3,994.46
S/260.54
List Price:  S/372.22
You save:  S/111.67
K269.79
List Price:  K385.44
You save:  K115.64
SAR262.50
List Price:  SAR375.02
You save:  SAR112.51
ZK1,882.68
List Price:  ZK2,689.66
You save:  ZK806.98
L323.40
List Price:  L462.03
You save:  L138.62
Kč1,628.77
List Price:  Kč2,326.92
You save:  Kč698.14
Ft25,305.79
List Price:  Ft36,152.68
You save:  Ft10,846.88
SEK kr755.02
List Price:  SEK kr1,078.64
You save:  SEK kr323.62
ARS$61,468.17
List Price:  ARS$87,815.44
You save:  ARS$26,347.26
Bs483.33
List Price:  Bs690.51
You save:  Bs207.17
COP$271,845.87
List Price:  COP$388,367.89
You save:  COP$116,522.02
₡35,672.25
List Price:  ₡50,962.55
You save:  ₡15,290.29
L1,724.16
List Price:  L2,463.20
You save:  L739.03
₲522,510.75
List Price:  ₲746,475.93
You save:  ₲223,965.17
$U2,674.97
List Price:  $U3,821.56
You save:  $U1,146.58
zł281.37
List Price:  zł401.98
You save:  zł120.60
Already have an account? Log In

Transcript

Hello again, this is your host Habib zecharia. And this is our first lap for IPsec VPN with Nat topology. Basically the two sites, site a and site b, r one r two is considered to be a one site location. Our three will be a remote site or branch office perhaps. And basically the link between r two and three I'm showing as a pseudo link. But this could be also an internet cloud.

That means r two r three can only communicate with r two, but it has no reachability to r1. This is basically common scenario at At a lot of organizations, you cannot basically a remote site cannot basically communicate with an internal router, it can only communicate to the edge router. So our two will will be have as our edge router, and our two will have the NAT configuration. So let's start with this task number one, establish connectivity between r one and r three using static routes. Task number two is configure static Nat in r two so that our ones serial interface one slash zero is seen in r two. Right so that's how our tree will communicate with r1 through our To add the third configuration will be the IPsec VPN configuration.

And as I said the IPsec configuration is has a lot of command lines that we will apply. Basically, it's a learning process and anyone who would do this probably two or three times will get to know how to apply IPsec VPN. Now this topology will basically covered the traditional IPsec VPN implementation in our second lab, which is going to be on dmvpn and how to secure the dmvpn tunnels, we're gonna have a much simpler way of doing IPsec VPN by This is basically a very practical lab. And what I will advise my students is really to try it, doing it at home and gaining that comfort level. Okay, so let's start I've started the routers already. And let me bring our one and start configuring it.

Some of the configurations are basically a replica. And it's easier if you use a notepad to do that configuration. But anyway, let's stop doing it. I hope it's clear and the fonts are clear in the video. So first thing is r1. We don't have to give it a host name because it's already showing as r1.

We will start by configuring the loopback interface give it an IP address loopback usually doesn't need the no shut command interface. That's the first interface and the IP address according to the topology is 120 10 dot 10 dot 125525 Let me bring our two now. Give it up to are two has another interface. Let's give it a clock rate even though it's not necessary. The best practice in serial interfaces is to always give the clock rate for the DC. I think we will go back to our one and just give a clock rate as well.

Let me save it. Okay, so let me bring our three Okay, the interfaces are up in r three. The other requirement that we want to provide is a static route between the routers. So let me bring back r1 and apply the static route. So the default route for r1 is going to be IP route and all the traffic will be directed to our tos serial interface one slash one, and that IP is 120 dot 10 dot 10 dot two. Okay, now let me do this Same thing for r three.

All the traffic and r three is directed to our tos serial interface, one slash two, which is dot two. Okay. Now let me bring our two. So our two will have two routes, basically one route to reach the loopback interface inside B and another loopback interface inside a. So let's do that IP I don't know what's happening here IP route. Let me save the configuration.

Now. Basically task two is completed task two was no. Task one is completed with establishing connectivity between r one and r three using static routes. So let me bring our one and we will basically ping our threes. loopback interface. So ping, dirty, dirty, dirty, dirty from source 10 dot 10 dot 10 dot 10.

And yes, we can ping. So that's good. We achieved our first task. Now task number two is configure static Nat. So are two is basically our router here but it could be also a firewall that will do nothing, right. So.

So the configuration of firewall in a router. It's almost the same if you do this if you do it in from Seelye mode. So we have two interfaces in r two. So interface serial one slash one will act as our IP Nat inside and interface one slash s one slash two will be IP Nat outside. Let's exit. Now we will have to basically apply the static Nat.

So IP Nat source, the source is basically static 120 dot 10 dot 10 dot one will be translated to 220 dot 20 dot 20 dot one IP Nat inside There we go. Now if you notice I used one 220 20 dot 20 dot one, where as this interface has got to configure it. Basically if you look at this topology dot one is part of this subnet as well so we could use dot one dot four, because dot three is assigned here, dot five dot six and so on. So we chose dot one okay. So if I do show IP Nat translations, so this tell me the the inside global which is 220 dot 2020 dot one, which is inside global is translated to inside local IP, which is 120 10. dot 10 dot one. So that's what we wanted.

We wanted our three to communicate with r1 using the inside global IP which is 220 20 dot 20 dot one and that's how Nat netting works. Okay. So with this we have actually completed task number two. Now task number three is where we will put all our attention now, which is configuring IPsec VPN. Now if you look at the architecture slide I have said there is IPsec policy that will run first, that's what we will start working on. So let's add the tunnel will be created from r1 all the way to r three, r two has no purpose at this time.

All the work will be done on our work. And our three let me bring our one. So as I said most of the most of the, the commands will be replicated between r one and r three. Let me put both of them here. Let me actually bring r one on top and r three at the bottom. And we will continue applying the same commands into both of the routers, so we don't miss anything.

And I will recommend that you do this at your own pace. The more you practice, the more you will get to know the commands as I mentioned in my previous slides, I say cam is the protocol that drives all other components. And we will add all other components now hash MD five, authentication, pre share, group to encryption will be three deaths. One thing I didn't discuss is about group two group is basically referring to diffie Hellman group and Cisco routers support groups that are from one to 24. For simplicity, I always use group two and it provides 1025 four bits, encryption, okay. Or basically, it can communicate, establish communication using 1064 bits.

That's that's the right way to say it. So that's done. Let me apply the same commands here in our three authentication to encryption three trade So this is all we have to do for ISO camp policy. Now let's add the crypto ISO camp key. Let's use Cisco 123 address. Now this address is the peer IP address in our topology it is going to be 220 dot 20 dot 23.

This IP is the IP of the neighboring device which is our threes interface here. Okay let's do the same thing in our three crypto I can notice I'm missing crypto. I think we said Cisco 123 and the address is 220 20 dot one. If you notice our three is going to establish communication with our tos global inside IP address. Remember that so that's why we are using 220 dot 20 dot 20 dot one as the peer device. Now that is done now we will configure and we will configure something known IPsec transform set to use desk for encryption and Mt five for hashing.

Okay, so let's create the transform set. crypto IPsec transform set, and I'll call it Tran. That's the name I'll give it. We can use ESP does. And e SP, MD five. HMC.

Same thing in our three we have to match all the steps between these two routers. So they can negotiate the authentication and encryption one this time transferring all the interesting traffic Okay, we made a mistake here. I mean that there you go. Now we will create the access list for the interesting traffic. So, access list 101 permit IP host to host same thing here in our three access list 101 permit IP host. So that's how our access list is done.

Now there's a step that we need to do which is the crypto map. Let's do that. crypto map. VPN 10 IPsec. Again, sorry about the typo. It's been a long day.

Said peer Now we know who is our peer that's how our peer match address on a one. Set. Transform set. Tran. Let's apply the same in our three crypto map. VPN 10.

Said peer Don't forget our pier is the global inside IP address. No one. So that is done. Now as you know, we apply crypto map to the interfaces when it comes to VPN. Similarly we do for the access list we apply access group to the interfaces but when it comes to VPN, we apply the crypto map into the interfaces. So in r1 we will apply the crypto map to this interface.

For our three we will apply to this interface which is serial one slash two for r1. It's serial one slash zero. So let's do that interface, serial one slash zero crypto map, v, p n. Let's do the same thing here in our three, interface, one slash two, one slash two. And we said it's crypto map, VPN. Let's save it. Now our configuration is totally complete.

Let's generate interesting traffic that's when the VPN will kick in. So if I do ping 3030 3030 from the source, which is 10 dot 10 dot 10 dot 10 you can see it's going through which is great. Now let's check the policy the policies the security Association. So if I do show crypto I say cam as a I can see that I can see to 20 2023 from the source 120 dot 10 dot 10 dot one and the status is active. The other thing we could do is basically do show crypto IPsec sa, that's another security Association. And we could include number.

And there you go. It tells us how many encapsulations happened, how many decapsulation is happen, and what failed. And what got decompressed. The other command I wanted to show you was the number of connections that are active. So if I do show crypto engine connections active. This tells me that IPsec is active the algorithm is Diaz plus MD five.

So there was a decryption here. Same thing here. So with this, I conclude our first lab, which is basically an implementation of site to site VPN with Nat. This topology could have been simpler. Basically, if you didn't want to introduce Nat in the middle, you could just connect r1 to r three and just follow the same steps but there will be No Nat configurations because there will be no r1 there'll be no r two. So that would have been very simpler lab.

But I introduced this lab to make it a little bit complicated and also to to move to mimic real world topology. I hope you have enjoyed this lab and once again, thank you and we will do the second lab shortly. Thank you

Sign Up

Share

Share with friends, get 20% off
Invite your friends to LearnDesk learning marketplace. For each purchase they make, you get 20% off (upto $10) on your next purchase.