Chapter 9 Configuring Security Features

Configuring VPN

!

crypto isakmp policy 1 encryption 3des authentication pre-share group 2

lifetime 480

!

crypto isakmp client configuration group rtr-remote key secret-password

dns 10.50.10.1 10.60.10.1 domain company.com

pool dynpool

!

crypto ipsec transform-set vpn1 esp-3des esp-sha-hmac

!

crypto ipsec security-association lifetime seconds 86400

!

crypto dynamic-map dynmap 1 set transform-set vpn1 reverse-route

!

crypto map static-map 1 ipsec-isakmp dynamic dynmap crypto map dynmap isakmp authorization list rtr-remote crypto map dynmap client configuration address respond

crypto ipsec client ezvpn ezvpnclient connect auto

group 2 key secret-password mode client

peer 192.168.100.1

!

interface fastethernet 4

crypto ipsec client ezvpn ezvpnclient outside crypto map static-map

!

interface vlan 1

crypto ipsec client ezvpn ezvpnclient inside

!

Configure a Site-to-Site GRE Tunnel

To configure a GRE tunnel, perform these steps, beginning in global configuration mode:

SUMMARY STEPS

1.interface type number

2.ip address ip-address mask

3.tunnel source interface-type number

4.tunnel destination default-gateway-ip-address

5.crypto map map-name

6.exit

7.ip access-list {standard extended} access-list-name

8.permit protocol source source-wildcard destination destination-wildcard

9.exit

 

 

Cisco 819 Series Integrated Services Routers Software Configuration Guide

 

 

 

 

 

 

OL-23590-02

 

 

9-17

 

 

 

 

 

Page 111
Image 111
Cisco Systems C819HG4GVK9, C819GUK9 manual Configure a Site-to-Site GRE Tunnel