Chapter 7 Configuring VPNs Using an IPSec Tunnel and Generic Routing Encapsulation

Configure a GRE Tunnel

BETA DRAFT - CISCO CONFIDENTIAL

 

Command or Action

Purpose

Step 3

 

 

tunnel source interface-type number

Specifies the source endpoint of the router for the

 

 

GRE tunnel.

 

Example:

 

 

Router(config-if)# tunnel source

 

 

fastethernet 2

 

 

Router(config-if)#

 

Step 4

 

 

tunnel destination default-gateway-ip-address

Specifies the destination endpoint of the router for

 

 

the GRE tunnel.

 

Example:

 

 

Router(config-if)# tunnel destination

 

 

192.168.101.1

 

 

Router(config-if)#

 

Step 5

 

 

crypto map map-name

Assigns a crypto map to the tunnel.

 

Example:

Note Dynamic routing or static routes to the

 

tunnel interface must be configured to

 

 

 

Router(config-if)#crypto map static-map

establish connectivity between the sites.

 

Router(config-if)#

See the Cisco IOS Security Configuration

 

 

 

 

Guide for details.

Step 6

 

 

exit

Exits interface configuration mode, and returns to

 

 

global configuration mode.

 

Example:

 

 

Router(config-if)# exit

 

 

Router(config)#

 

Step 7

 

 

ip access-list {standard extended}

Enters ACL configuration mode for the named

 

access-list-name

ACL that is used by the crypto map.

 

Example:

 

 

Router(config)# ip access-list extended

 

 

vpnstatic1

 

 

Router(config-acl)#

 

Step 8

 

 

permit protocol source source-wildcard

Specifies that only GRE traffic is permitted on the

 

destination destination-wildcard

outbound interface.

 

Example:

 

 

Router(config-acl)# permit gre host

 

 

192.168.100.1 host 192.168.101.1

 

 

Router(config-acl)#

 

Step 9

 

 

exit

Returns to global configuration mode.

 

Example:

 

 

Router(config-acl)# exit

 

 

Router(config)#

 

 

 

 

Cisco 1800 Series Integrated Services Routers (Fixed) Software Configuration Guide

 

OL-6426-02

7-9

 

 

 

Page 93
Image 93
Cisco Systems OL-6426-02 Assigns a crypto map to the tunnel, Tunnel interface must be configured to, Guide for details