| [ LiB ] |
The following is a step-by-step discussion of the Practical Exercise solution.
IKE uses UDP port 500. The IPSec ESP and AH protocols use protocol numbers 50 and 51. You must ensure that any existing access lists you might already have configured do not block protocol 50, 51, and UDP port 500 traffic at any interface used by IPSec. In some cases you might need to reconfigure an existing access list to explicitly permit this traffic.
R1(config)#crypto isakmp policy 1 R1(config-isakmp)#authentication pre-share
R1(config)#crypto isakmp key cisco123 address 100.133.123.2 R1(config)#crypto isakmp key cisco123 address 100.133.123.3
R2(config)#crypto isakmp policy 1 R2(config-isakmp)#authentication pre-share
R2(config)#crypto isakmp key cisco123 address 100.133.123.1 R2(config)#crypto isakmp key cisco123 address 100.133.123.3
R3(config)#crypto isakmp policy 1 R3(config-isakmp)#authentication pre-share
R3(config)#crypto isakmp key cisco123 address 100.133.123.1 R3(config)#crypto isakmp key cisco123 address 100.133.123.2
R1(config)#ip route 170.170.170.0 255.255.255.0 100.133.123.2 R1(config)#ip route 180.180.180.0 255.255.255.0 100.133.123.3
R1(config)#access-list 170 permit ip 160.160.160.0 0.0.0.255 170.170.170.0 0.0.0.255 R1(config)#access-list 180 permit ip 160.160.160.0 0.0.0.255 180.180.180.0 0.0.0.255
R1(config)#crypto ipsec transform-set 170cisco esp-des esp-md5-hmac R1(cfg-crypto-trans)#exit R1(config)#crypto ipsec transform-set 180cisco esp-des esp-md5-hmac
R1(config)#crypto map mymap 17 ipsec-isakmp R1(config-crypto-m)#set peer 100.133.123.2 R1(config-crypto-m)#set transform-set 170cisco R1(config-crypto-m)#match address 170 R1(config-crypto-m)#exit R1(config)#crypto map mymap 18 ipsec-isakmp R1(config-crypto-m)#set peer 100.133.123.3 R1(config-crypto-m)#set transform-set 180cisco R1(config-crypto-m)#match address 180
R1(config)#interface ethernet 0 R1(config-if)#crypto map mymap
R2(config)#ip route 160.160.160.0 255.255.255.0 100.133.123.1 R2(config)#ip route 180.180.180.0 255.255.255.0 100.133.123.3
R2(config)#access-list 160 permit ip 170.170.170.0 0.0.0.255 160.160.160.0 0.0.0.255 R2(config)#access-list 180 permit ip 170.170.170.0 0.0.0.255 180.180.180.0 0.0.0.255
R2(config)#crypto ipsec transform-set 160cisco esp-des esp-md5-hmac R2(cfg-crypto-trans)#exit R2(config)#crypto ipsec transform-set 180cisco esp-des esp-md5-hmac
R2(config)#crypto map mymap 16 ipsec-isakmp R2(config-crypto-m)#set peer 100.133.123.1 R2(config-crypto-m)#set transform-set 160cisco R2(config-crypto-m)#match address 160 R2(config-crypto-m)#exit R2(config)#crypto map mymap 18 ipsec-isakmp R2(config-crypto-m)#set peer 100.133.123.3 R2(config-crypto-m)#set transform-set 180cisco R2(config-crypto-m)#match address 180
R2(config)#interface ethernet 0 R2(config-if)#crypto map mymap
R3(config)#ip route 160.160.160.0 255.255.255.0 100.133.123.1 R3(config)#ip route 170.170.170.0 255.255.255.0 100.133.123.2
R3(config)#access-list 160 permit ip 180.180.180.0 0.0.0.255 160.160.160.0 0.0.0.255 R3(config)#access-list 170 permit ip 180.180.180.0 0.0.0.255 170.170.170.0 0.0.0.255
R3(config)#crypto ipsec transform-set 160cisco esp-des esp-md5-hmac R3(cfg-crypto-trans)#exit R3(config)#crypto ipsec transform-set 170cisco esp-des esp-md5-hmac
R3(config)#crypto map mymap 16 ipsec-isakmp R3(config-crypto-m)#set peer 100.133.123.1 R3(config-crypto-m)#set transform-set 160cisco R3(config-crypto-m)#match address 160 R3(config-crypto-m)#exit R3(config)#crypto map mymap 17 ipsec-isakmp R3(config-crypto-m)#set peer 100.133.123.2 R3(config-crypto-m)#set transform-set 170cisco R3(config-crypto-m)#match address 170
R3(config)#interface ethernet 0 R3(config-if)#crypto map mymap
| [ LiB ] |